Skip to content

Introduction

Kaio is a Docker management dashboard, CLI and TUI. It gives you container observability and Compose stack management from one Rust binary, for the host it runs on, and servers can join one another into a cluster, so one of them lists the others, knows whether they answer, and drives them.

Domain Capabilities
Stacks Deploy Compose files, edit them in Monaco, manage per-stack environment variables, version every change, roll back, update, restart, delete
Containers Start, stop, restart, pause, delete, individually or in bulk. Live CPU / RAM / network metrics, streamed logs, interactive sh shell
Images List, delete, prune, and scan for CVEs with Trivy
Volumes & networks List, delete, prune
System Global prune, event history, aggregated health
Agents An MCP endpoint at /mcp that hands an AI client the state of the host, and the tools to act on it, as far up the off / read / write / admin ladder as you allow

All business logic lives in the shared core crate. The Axum server is a thin HTTP layer on top of it, and the CLI is a thin client over that API.

  • Web UI: React 19 + Tailwind 4, with prefers-reduced-motion support so its animations follow the OS setting. See the Web dashboard.
  • TUI: a fully event-driven terminal interface at feature parity with the web app. See the TUI shortcuts.
  • CLI: every server capability, with --json for scripting. See the CLI reference.

The practical consequence: aggregation (stack status, vulnerability counts, metrics) is computed once in core, so the web UI, the TUI and the CLI can never disagree.

The same core answers a fourth kind of caller. With KAIO_MCP set, Kaio serves the Model Context Protocol at /mcp, so an agent reads stacks, logs and CVE counts as tools rather than by scraping a UI, and acts on them only as far as the rung you granted. It is off until you turn it on, and read is a rung where nothing an agent is talked into calling can change the host.

Kaio manages the daemon of the host it runs on. Servers join into a cluster, but that is a registry, not an orchestrator: nothing schedules a workload across hosts, and acting on a node means aiming at it. Kaio has no authentication: whatever reaches its port controls the Docker daemon, which is root-equivalent on that host. It expects a layer in front of it, and Security says what that layer has to cover.

Working on the code rather than running it: Development setup.

Kaio, built by Régis Gaidot