The repository publishes documentation, not the Kuboard server
Kuboard is a browser console for Kubernetes, while kuboard-press is its VitePress documentation site. The root README is written mainly in Chinese and points to Chinese and English guides. Those guides describe multi-cluster management, workload editing, storage and network resources, logs, browser terminals, audit records, MFA, and an MCP server. The distinction matters: cloning this repository lets you inspect and build the manuals, not audit the backend that receives cluster credentials.
The package identifies itself as UNLICENSED, and GitHub reports no repository license despite 25,245 stars. Kuboard's README calls the software free for individuals and small businesses, while the separate licensing guide supplies a concrete limit: up to 3 managed clusters need no license file, and each cluster above that limit needs another file. Anyone with an open-source procurement requirement should stop there and ask for the product's complete terms and source position.
What happened when we ran it
Our fresh Debian sandbox installed commit 6672c05 in 5 seconds. Pnpm added 248 packages, and the finished environment used 319 MB on disk. The checkout had 505 files, about 250,464 lines of source, and occupied 50.3 MB before installation. Npm audit found 0 known vulnerabilities: 0 critical, 0 high, 0 moderate, and 0 low.
The lab found no recognized build script or target, so it skipped the build. It also found no test script or target and skipped tests. The repository scan recorded a pnpm workspace, a Dockerfile, no CI workflow files, and no tests directory. These results say the documentation dependencies installed cleanly. They provide no runtime result for Kuboard, no Kubernetes compatibility proof, and no test count for the server product.
The quick start gives Kuboard a database and cluster access
The English quick start asks for Docker on an amd64 or arm64 host. Its Compose example starts MariaDB 11.3.2 and the Kuboard v4 image, maps host port 8000 to container port 80, and persists database data plus application logs. The first login uses admin and the published default password Kuboard123; the guide immediately tells the operator to change it before creating users and importing a cluster.
A serious deployment is much larger than those 2 containers. The high-availability guide uses at least 2 Kuboard replicas behind Nginx, an external database design, and Redis for state shared across instances. Its full cluster example has 6 Redis nodes, split into 3 masters and 3 replicas. OIDC state, MCP sessions, event delivery, and rate limits depend on shared Redis when requests can land on different Kuboard replicas.
MCP writes require a plan and a 15-minute token
Kuboard v4.1.0 or newer can expose 34 documented MCP tools for clusters, workloads, events, metrics, and Kubernetes resources. Read operations can run directly. Persistent writes enter a 5-phase flow: the agent creates a plan, the user reviews it in Kuboard, the server issues a one-time token, steps execute in order, and the result is stored. A token expires after 15 minutes and is bound to its user and plan.
That approval design is the strongest reason to consider Kuboard over a dashboard with an unrestricted agent credential. It still needs testing. Operators can disable mandatory approval in settings, so policy must prevent that switch from becoming an easy shortcut. Partial execution also stops on the first failed step and cannot resume; the user has to create and approve another plan. The database keeps approval state, while Redis supports the surrounding session behavior in a multi-replica deployment.
English guides exist, while English release notes do not
The repository contains 134 paths under docs/en and 172 under docs/zh, including parallel installation, operations, user, MCP, and reference sections. The English material is substantial enough to install the product and understand the approval model. Yet docs/en/changelog/v4.x.md says the English mirror will be added later. The Chinese changelog lists v4.2.2.0 on September 13, 2026, with agent approval, MCP audit work, terminal changes, and many fixes.
GitHub's latest-release endpoint returned 404 because this repository does not publish its product versions there. Operators have to follow the documentation changelog and image tags instead. That makes upgrades less convenient for an English-only team, especially when the README says Kubernetes 1.15 through 1.34 are supported. Pin the image, preserve the database, and translate the relevant Chinese release entry before changing a production console.
Recent commits coexist with 539 open issues and pull requests
The last push was September 27, 2026, and issue activity continued through September 24. GitHub counted 539 open issues and pull requests. Several current reports are specific enough to reproduce during a trial: issue 664 says v4.2.2 failed to load a PostgreSQL driver class, issue 659 reports incorrect Pod CPU and memory requests on Kubernetes 1.33, and issue 657 reports an authorization error for a read-only user. They are reports, not proof that every deployment is affected.
Kuboard is easier to try than to verify. The 5-second dependency install and detailed bilingual manuals make the documentation pleasant to work with, while the absent server source prevents the same inspection of the product. Put it beside a disposable cluster first. If its visual operations and MCP approval flow solve a real problem, test your database, Kubernetes version, read-only roles, backups, and upgrade path before the console touches production credentials.

