Skip to content

Configuration

All configuration is environment-based; there is no config file.

Variable Description Default
KAIO_ADDR Address to bind the server (and for the CLI to target) 127.0.0.1:8080
KAIO_ALLOWED_ORIGINS Comma-separated origins allowed to call the API from a browser. Unset keeps the permissive policy (unset)
KAIO_DB SQLite connection string sqlite:./kaio.db
KAIO_STACKS_DIR Directory holding the stacks’ compose.yml files (derived from the DB path)
KAIO_STATIC_DIR Directory holding the built web UI served by the server ./public
KAIO_DOCKER_HOST Custom Docker socket or host local defaults
KAIO_EVENTS_RETENTION_DAYS How many days to keep events before deletion 30
KAIO_LOGS_TAIL Past log lines loaded when opening logs (0 to 10000; per container for stacks). Overridable per request with ?tail= / --tail 100
KAIO_UPDATE_CHECK_INTERVAL_HOURS Interval for the automatic image update check, for every stack (0 disables it) 12
KAIO_NODE_HEALTH_INTERVAL_SECONDS Interval for the automatic probe of every node in the cluster (0 disables it) 60
HOSTNAME Fallback for the name kaio-cli join asks for, when /etc/hostname cannot be read (from the OS)
RUST_LOG Logging level (tracing) info

See MCP server.

Variable Description Default
KAIO_MCP Tools exposed at /mcp: off, read, write or admin. off does not route the endpoint at all off
KAIO_MCP_ALLOWED_HOSTS Comma-separated Host values /mcp answers, on top of the loopback names always accepted. Unset refuses every remote client; * accepts any host (unset)
KAIO_MCP_ALLOWED_ORIGINS Comma-separated browser origins allowed to call /mcp. Unset refuses every request carrying an Origin header, which is what agents and CLIs send (none) (unset)

See Prometheus and Grafana.

Variable Description Default
KAIO_METRICS on serves the Prometheus endpoint at /metrics. off does not route it at all off
KAIO_METRICS_TOKEN Bearer token a scrape must carry. Unset serves /metrics to anyone who can reach the port, and it lists stack names, image names and CVE counts (unset)
Variable Description Default
KAIO_TRIVY_IMAGE Scanner image used for vulnerability scans aquasec/trivy:latest
KAIO_TRANSFER_IMAGE Image of the throwaway container that reads and writes volumes when a stack is moved. Needs tar, du and a shell alpine:3
KAIO_TRIVY_CONCURRENCY Max number of concurrent scans 2
KAIO_TRIVY_SCAN_INTERVAL_HOURS Interval for the automatic rescan of in-use images (0 disables it) 24
DOCKER_HOST Fallback when KAIO_DOCKER_HOST is unset, used to give the scanner container access to the daemon unset

The TUI opens a stack’s compose.yml in an external editor for E, and for the compose draft of a new stack.

Variable Description Default
VISUAL Editor command, tried first. A command with arguments works (code --wait) unset
EDITOR Editor command, tried when VISUAL is unset unset

With neither set, the TUI falls back to vi.

Read when the binaries are compiled, not when they run. They are only needed where .git is absent, which is the case inside the Docker build: the build script falls back to git rev-parse in a checkout, and to dev otherwise.

Variable Description Default
KAIO_GIT_SHA Short SHA stamped into kaio-cli version and kaio-cli --version (read from git, else dev)
  • Binding. KAIO_ADDR defaults to 127.0.0.1:8080, which is not reachable from outside a container. In Docker, set it to 0.0.0.0:8080.
  • The CLI reads the same variable to find its server, so exporting KAIO_ADDR once configures both. Set it per command.
  • Stacks directory. When unset, it is derived from the database path: a DB at /app/data/kaio.db puts stacks under /app/data/stacks/. Both must be on the same persistent volume.
  • Web UI. The server serves everything that is not /api from KAIO_STATIC_DIR. The image keeps it at the default, ./public under /app; the release tarball installs the assets to /usr/share/kaio/public and points the variable there.
  • Docker host. Leave KAIO_DOCKER_HOST unset to use the local defaults; set it to a unix:// path for a rootless Podman socket, as in Podman.

Kaio, built by Régis Gaidot