Introduction
Kaio is a Docker management dashboard, CLI and TUI. It gives you container observability and Compose stack management from one Rust binary, for the host it runs on, and servers can join one another into a cluster, so one of them lists the others, knows whether they answer, and drives them.
What it manages
Section titled “What it manages”| Domain | Capabilities |
|---|---|
| Stacks | Deploy Compose files, edit them in Monaco, manage per-stack environment variables, version every change, roll back, update, restart, delete |
| Containers | Start, stop, restart, pause, delete, individually or in bulk. Live CPU / RAM / network metrics, streamed logs, interactive sh shell |
| Images | List, delete, prune, and scan for CVEs with Trivy |
| Volumes & networks | List, delete, prune |
| System | Global prune, event history, aggregated health |
| Agents | An MCP endpoint at /mcp that hands an AI client the state of the host, and the tools to act on it, as far up the off / read / write / admin ladder as you allow |
Three interfaces, one core
Section titled “Three interfaces, one core”All business logic lives in the shared core crate. The Axum server is a thin
HTTP layer on top of it, and the CLI is a thin client over that API.
- Web UI: React 19 + Tailwind 4, with
prefers-reduced-motionsupport so its animations follow the OS setting. See the Web dashboard. - TUI: a fully event-driven terminal interface at feature parity with the web app. See the TUI shortcuts.
- CLI: every server capability, with
--jsonfor scripting. See the CLI reference.
The practical consequence: aggregation (stack status, vulnerability counts,
metrics) is computed once in core, so the web UI, the TUI and the CLI can
never disagree.
A fourth client: an AI agent
Section titled “A fourth client: an AI agent”The same core answers a fourth kind of caller. With KAIO_MCP set, Kaio serves
the Model Context Protocol at /mcp, so an agent reads
stacks, logs and CVE counts as tools rather than by scraping a UI, and acts on
them only as far as the rung you granted. It is off until you turn it on, and
read is a rung where nothing an agent is talked into calling can change the
host.
What it is not
Section titled “What it is not”Kaio manages the daemon of the host it runs on. Servers join into a cluster, but that is a registry, not an orchestrator: nothing schedules a workload across hosts, and acting on a node means aiming at it. Kaio has no authentication: whatever reaches its port controls the Docker daemon, which is root-equivalent on that host. It expects a layer in front of it, and Security says what that layer has to cover.
Next steps
Section titled “Next steps”Working on the code rather than running it: Development setup.
Kaio, built by Régis Gaidot