Development

The capture,packet by packet

Wireshark, on a Void Linux desktop of your own.Open the pcap on the volume and read what is actually on the wire.

Wireshark 4.6.82 cores · 4 GBOpens in a browser tab
hub://wireshark

$ dxflow workflow create --identity wireshark hub://wireshark --start --link

01Pick a machinecores, memory and a rate per hour
02Create the workflowpulled from the hub, once
03Run it, then stopstopped when the work is done
The application

Open the pcap,and dissect it

Thousands of dissectors turn bytes into fields you can filter on.

Display filters

Narrow a million packets to the dozen that matter, by field rather than by eye.

Follow a conversation

Reassemble a TCP stream, or a TLS handshake, and read it in order.

Where the time went

IO graphs, round-trip plots and expert notes on the retransmissions.

How you run it

Every defaultis one override away

The session reads its settings from the environment, so you set them on the start line.

VNC_PASSWORDWhat the tab asks for. It ships as dxflow, and everyone reading this knows that.
PANEL and TASKBARBoth hidden, so the analyzer has the whole screen. Show either one to get the desktop back.
AUDIOOff here. Turn it on and the desktop sound is streamed beside the picture.
start it your way

$ dxflow workflow start wireshark --override env.app.VNC_PASSWORD=something-long

$ dxflow workflow start wireshark --override env.app.TASKBAR=show --link

The session

The analyzerfills the screen

Streamed to your browser, with Wireshark already maximized.

6082Browserin the tab, at /vnc.html
5901VNCin a native client
/volumeStorageyour files, kept between runs
Open it from anywhereStart with --link and the session comes back on an HTTPS address.
Set a password firstVNC_PASSWORD defaults to dxflow, and everyone can read this page.
Good to know

It reads captures,it does not take them

The interface list comes up empty, and that is the design rather than a fault.

No live capture here

Sniffing needs NET_RAW and NET_ADMIN, which a workflow container is not given. Nothing you set will make an interface appear.

Bring the pcap with you

Upload a pcap or pcapng to /volume and open it from there. Analysis is what this entry exists for.

Big captures want memory

Wireshark holds the dissection in RAM. A multi-gigabyte file wants a machine chosen for memory, not cores.

The image

Pulled once,then it stays

Wireshark arrives as one image. This is what comes down the first time, and what the disk should have free for it.

318Mamd64compressed, the way the registry counts it
316Marm64compressed, the way the registry counts it
20GOn diskunpacked, with room to work beside it
ghcr.io/dxflow-ai/wireshark:latestPublished from the hub, pulled on the first start and kept for the ones after it.
Either architectureamd64 and arm64 are both published, and the machine pulls the one it runs.
What it asks for

What it wants,and what it needs

The definition asks for 2 cores and 4 GB. The image comes up on less than that, and a start given --fit trims the ask to whatever the machine actually has.

2 cores · 4 GBAsks forwhat the definition writes down
2 cores · 2 GBRuns onthe least the image comes up on
Not neededGPUit works on the cores alone
The ask is not the floorThe definition writes down what suits the work. The image itself starts on less, which is what the second figure is.
--fit caps it to the hostA start given --fit trims each step to what the machine actually has, for that start alone. The definition is never rewritten.

Machines that fit it

Wireshark asks for 2 cores and 4 GB. Cheapest first.

E2 Medium
$0.042/ hour2 cores · 4 GBStart this machine
T3 Medium
$0.052/ hour2 cores · 4 GBStart this machine
B2s
$0.052/ hour2 cores · 4 GBStart this machine
Run Wireshark on your own machinePick a machine that meets it, and it opens about a minute after you ask.