Configuration
All configuration is environment-based; there is no config file.
Server & CLI
Section titled “Server & CLI”| Variable | Description | Default |
|---|---|---|
KAIO_ADDR |
Address to bind the server (and for the CLI to target) | 127.0.0.1:8080 |
KAIO_ALLOWED_ORIGINS |
Comma-separated origins allowed to call the API from a browser. Unset keeps the permissive policy | (unset) |
KAIO_DB |
SQLite connection string | sqlite:./kaio.db |
KAIO_STACKS_DIR |
Directory holding the stacks’ compose.yml files |
(derived from the DB path) |
KAIO_STATIC_DIR |
Directory holding the built web UI served by the server | ./public |
KAIO_DOCKER_HOST |
Custom Docker socket or host | local defaults |
KAIO_EVENTS_RETENTION_DAYS |
How many days to keep events before deletion | 30 |
KAIO_LOGS_TAIL |
Past log lines loaded when opening logs (0 to 10000; per container for stacks). Overridable per request with ?tail= / --tail |
100 |
KAIO_UPDATE_CHECK_INTERVAL_HOURS |
Interval for the automatic image update check, for every stack (0 disables it) |
12 |
KAIO_NODE_HEALTH_INTERVAL_SECONDS |
Interval for the automatic probe of every node in the cluster (0 disables it) |
60 |
HOSTNAME |
Fallback for the name kaio-cli join asks for, when /etc/hostname cannot be read |
(from the OS) |
RUST_LOG |
Logging level (tracing) | info |
MCP server
Section titled “MCP server”See MCP server.
| Variable | Description | Default |
|---|---|---|
KAIO_MCP |
Tools exposed at /mcp: off, read, write or admin. off does not route the endpoint at all |
off |
KAIO_MCP_ALLOWED_HOSTS |
Comma-separated Host values /mcp answers, on top of the loopback names always accepted. Unset refuses every remote client; * accepts any host |
(unset) |
KAIO_MCP_ALLOWED_ORIGINS |
Comma-separated browser origins allowed to call /mcp. Unset refuses every request carrying an Origin header, which is what agents and CLIs send (none) |
(unset) |
Prometheus metrics
Section titled “Prometheus metrics”| Variable | Description | Default |
|---|---|---|
KAIO_METRICS |
on serves the Prometheus endpoint at /metrics. off does not route it at all |
off |
KAIO_METRICS_TOKEN |
Bearer token a scrape must carry. Unset serves /metrics to anyone who can reach the port, and it lists stack names, image names and CVE counts |
(unset) |
Vulnerability scanning
Section titled “Vulnerability scanning”| Variable | Description | Default |
|---|---|---|
KAIO_TRIVY_IMAGE |
Scanner image used for vulnerability scans | aquasec/trivy:latest |
KAIO_TRANSFER_IMAGE |
Image of the throwaway container that reads and writes volumes when a stack is moved. Needs tar, du and a shell |
alpine:3 |
KAIO_TRIVY_CONCURRENCY |
Max number of concurrent scans | 2 |
KAIO_TRIVY_SCAN_INTERVAL_HOURS |
Interval for the automatic rescan of in-use images (0 disables it) |
24 |
DOCKER_HOST |
Fallback when KAIO_DOCKER_HOST is unset, used to give the scanner container access to the daemon |
unset |
Editor used by the TUI
Section titled “Editor used by the TUI”The TUI opens a stack’s compose.yml in an external editor for E, and for the
compose draft of a new stack.
| Variable | Description | Default |
|---|---|---|
VISUAL |
Editor command, tried first. A command with arguments works (code --wait) |
unset |
EDITOR |
Editor command, tried when VISUAL is unset |
unset |
With neither set, the TUI falls back to vi.
Build time
Section titled “Build time”Read when the binaries are compiled, not when they run. They are only needed
where .git is absent, which is the case inside the Docker build: the build
script falls back to git rev-parse in a checkout, and to dev otherwise.
| Variable | Description | Default |
|---|---|---|
KAIO_GIT_SHA |
Short SHA stamped into kaio-cli version and kaio-cli --version |
(read from git, else dev) |
- Binding.
KAIO_ADDRdefaults to127.0.0.1:8080, which is not reachable from outside a container. In Docker, set it to0.0.0.0:8080. - The CLI reads the same variable to find its server, so exporting
KAIO_ADDRonce configures both. Set it per command. - Stacks directory. When unset, it is derived from the database path: a DB
at
/app/data/kaio.dbputs stacks under/app/data/stacks/. Both must be on the same persistent volume. - Web UI. The server serves everything that is not
/apifromKAIO_STATIC_DIR. The image keeps it at the default,./publicunder/app; the release tarball installs the assets to/usr/share/kaio/publicand points the variable there. - Docker host. Leave
KAIO_DOCKER_HOSTunset to use the local defaults; set it to aunix://path for a rootless Podman socket, as in Podman.
Kaio, built by Régis Gaidot