A browser can be a full client for a training workstation
The participant opens an HTTPS address, authenticates and receives the picture of a desktop running on a remote machine. The programs, working files and computing power are all on the VM side. The local computer is mainly responsible for displaying the picture, handling the keyboard and mouse, and the network connection.
This model is especially useful on managed laptops on which the user cannot install a VPN client or a remote desktop program. An up-to-date version of Chrome, Firefox or Edge and access to the given address over HTTPS are often enough to get started. The final requirements, however, depend on the company's network policy and the settings of the particular browser.
The access test must take place on the target network
A connection checked in the instructor's office does not confirm that it will work behind a corporate proxy or from a participant's home connection. The test should use the same type of device, browser and network that will be used during the sessions. You should confirm that the page opens, that signing in works, that the session stays alive for a quarter of an hour or so, and that you can reconnect after a short break.
On a company network, address filtering, TLS inspection, timeouts and the handling of long-lived connections all matter. The security team should receive the specific address and the information that the traffic uses port 443. If the organisation requires a list of allowed domains, agreeing it on the day of the training is usually too late.
Keyboard, clipboard and files make the difference to comfort
Simply displaying the desktop is not enough. A programming workshop requires smooth entry of special characters, keyboard shortcuts and non-ASCII characters (e.g. Polish diacritics). Before the start, you need to check the keyboard layout on both ends of the connection. Differences are particularly easy to miss with characters used in the terminal, such as the slash, tilde, brackets and the pipe symbol.
The clipboard and file transfer should follow the security rules. Sometimes copying text is needed for working with commands, while file transfer is to be disabled. In another scenario, the participant has to download the result of an exercise. These decisions should be part of the environment specification, rather than being left to the default settings.
A desktop and SSH serve different ways of working
A graphical desktop works well for IDEs, administration tools with a user interface, a browser running inside the lab and desktop applications. SSH is the natural choice for the terminal, automation, file transfer and port tunnelling. Both methods can lead to the same machine, so there is no need to prepare two different configurations.
The participant can use the desktop during the main part of the training, while the instructor or a more advanced person connects over SSH for diagnostics. The choice should follow from the course programme. Adding a graphical interface to a training course on terminal tools increases data transfer and the number of components to support, without any clear benefit.
A remote session needs clear security rules
Each participant should receive their own account, and sign-in details should not be posted in a shared chat. The session must have a defined validity period and the option of being revoked. For workstations that contain confidential materials, you need to decide whether the clipboard, file downloads, printing and screenshots are allowed.
A virtual desktop does not stop data being visible on the user's device. A participant can copy information by hand or take a photo of the screen. That is why the lab should use training data and the minimum amount of information needed to complete the exercises.
A contingency plan should not create a second lab
If the connection drops briefly, the user should be able to return to the same session without losing files. Contingency instructions can be limited to reopening the address, checking the network status and giving the instructor the workstation identifier. A long list of alternative clients and configurations only adds to the confusion.
If the participant's connection is too weak for the desktop picture, SSH can be a lighter route. Not every training course can be moved to the terminal, however. A programme that uses graphical applications requires a connection of suitable quality, which is why a technical test before the sessions remains the best way to detect the problem.
Short instructions should answer specific questions
The participant needs the address, the account name, how they will receive the password, the supported browser and information on what they will see after signing in. It is worth adding how to change the keyboard layout, the rules for using the clipboard and a contact for support. Everything else in the configuration should already be ready on the machine.
The site also includes instructions for connecting to a virtual machine, and a description of the available models is part of the training environments offer. The browser is a convenient way into the lab when the path has been checked all the way from the participant's device to the application running on the VM.