mrkeyoor.com_
Mon 28 Sept 04:39 UTC
Self-Hostedevaluationupdated 28 Sept 2026

kuboard-press review

Kuboard is a self-hosted web console for managing one or more Kubernetes clusters. The repository README is primarily Chinese, English documentation exists, and this particular repository contains the bilingual VitePress documentation site rather than the Kuboard server source.

Verdict

Our Kuboard documentation checkout installed 248 packages in 5 seconds with 0 known npm vulnerabilities, but it did not build or test the Kuboard server because that source is not in this repository. Kuboard deserves a contained trial for a Chinese-speaking team that wants multi-cluster operations and approval-based MCP writes, especially at 3 clusters or fewer. Choose a fully open application repository if source auditability is required, and treat the unfinished English changelog plus the large issue queue as real evaluation costs.

We ran it

Lab card: what happened when we ran kuboard-pressScreenshot of kuboard-press (kuboard.cn)
Install✓ · 5s248 packages · 319 MB
Buildn/ano build script
Testsn/ano test script
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo505 files~250,464 lines of source · 50.3 MB · 0 CI workflows · Dockerfile

Answers from our run

Does kuboard-press build from source?

Dependencies installed in 5 seconds (248 packages), and the project has no separate build step. We cloned commit 6672c05 into a clean Debian container with 3 CPUs and no project-specific setup.

Does kuboard-press have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does kuboard-press have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use kuboard-press?

Buyers who require the application source under an OSI-approved license: this repository contains documentation, its package is marked UNLICENSED, and GitHub reports no repository license.

What are the alternatives to kuboard-press?

Headlamp, Rancher. Our Kuboard documentation checkout installed 248 packages in 5 seconds with 0 known npm vulnerabilities, but it did not build or test the Kuboard server because that source is not in this repository.

Setup3/5Docs install in 5 seconds; the actual server was not built here
Docs4/5Wide bilingual coverage, but the English v4 changelog is empty
Community4/525,245 stars and recent reports, with 539 issues and PRs open
Maturity3/5Current v4 releases, but server source and repository tests are absent

Who it’s for

Chinese-speaking Kubernetes teams that want a visual console for workloads, storage, networking, logs, terminals, and access control.
Small operators managing up to 3 clusters, which the licensing guide says need no license file.
Teams willing to test Kuboard as a packaged container instead of auditing its server implementation here.
MCP users who want cluster reads plus a UI approval step before an agent performs writes.

Who it’s NOT for

Buyers who require the application source under an OSI-approved license: this repository contains documentation, its package is marked UNLICENSED, and GitHub reports no repository license.
English-only operators who need complete release notes: English guides exist, but the English v4 changelog is still a placeholder while the Chinese page carries the releases.
PostgreSQL users who cannot run a version-specific trial: open issue 664 reports that Kuboard v4.2.2 could not load the PostgreSQL driver class.
Teams expecting repository tests to prove the server works: our run found no tests target or tests directory, and it exercised only the documentation checkout.

Setup reality

Our commit 6672c05 checkout installed 248 pnpm packages in 5 seconds and used 319 MB on disk. The lab found no recognized build or test target, so both steps were skipped. Npm audit reported 0 known vulnerabilities across all severity levels.

That result covers the VitePress documentation, not Kuboard itself. The product quick start needs Docker on amd64 or arm64, starts Kuboard with MariaDB, exposes port 8000, and asks you to replace the default administrator password. Importing a cluster then grants the console access to Kubernetes.

The 50.3 MB monorepo held 505 files and about 250,464 source lines. It had a Dockerfile, no CI workflow, and no tests directory. High availability adds multiple Kuboard replicas, a load balancer, a highly available database, and Redis; more than 3 managed clusters need license files.

The repository publishes documentation, not the Kuboard server

Kuboard is a browser console for Kubernetes, while kuboard-press is its VitePress documentation site. The root README is written mainly in Chinese and points to Chinese and English guides. Those guides describe multi-cluster management, workload editing, storage and network resources, logs, browser terminals, audit records, MFA, and an MCP server. The distinction matters: cloning this repository lets you inspect and build the manuals, not audit the backend that receives cluster credentials.

The package identifies itself as UNLICENSED, and GitHub reports no repository license despite 25,245 stars. Kuboard's README calls the software free for individuals and small businesses, while the separate licensing guide supplies a concrete limit: up to 3 managed clusters need no license file, and each cluster above that limit needs another file. Anyone with an open-source procurement requirement should stop there and ask for the product's complete terms and source position.

What happened when we ran it

Our fresh Debian sandbox installed commit 6672c05 in 5 seconds. Pnpm added 248 packages, and the finished environment used 319 MB on disk. The checkout had 505 files, about 250,464 lines of source, and occupied 50.3 MB before installation. Npm audit found 0 known vulnerabilities: 0 critical, 0 high, 0 moderate, and 0 low.

The lab found no recognized build script or target, so it skipped the build. It also found no test script or target and skipped tests. The repository scan recorded a pnpm workspace, a Dockerfile, no CI workflow files, and no tests directory. These results say the documentation dependencies installed cleanly. They provide no runtime result for Kuboard, no Kubernetes compatibility proof, and no test count for the server product.

The quick start gives Kuboard a database and cluster access

The English quick start asks for Docker on an amd64 or arm64 host. Its Compose example starts MariaDB 11.3.2 and the Kuboard v4 image, maps host port 8000 to container port 80, and persists database data plus application logs. The first login uses admin and the published default password Kuboard123; the guide immediately tells the operator to change it before creating users and importing a cluster.

A serious deployment is much larger than those 2 containers. The high-availability guide uses at least 2 Kuboard replicas behind Nginx, an external database design, and Redis for state shared across instances. Its full cluster example has 6 Redis nodes, split into 3 masters and 3 replicas. OIDC state, MCP sessions, event delivery, and rate limits depend on shared Redis when requests can land on different Kuboard replicas.

MCP writes require a plan and a 15-minute token

Kuboard v4.1.0 or newer can expose 34 documented MCP tools for clusters, workloads, events, metrics, and Kubernetes resources. Read operations can run directly. Persistent writes enter a 5-phase flow: the agent creates a plan, the user reviews it in Kuboard, the server issues a one-time token, steps execute in order, and the result is stored. A token expires after 15 minutes and is bound to its user and plan.

That approval design is the strongest reason to consider Kuboard over a dashboard with an unrestricted agent credential. It still needs testing. Operators can disable mandatory approval in settings, so policy must prevent that switch from becoming an easy shortcut. Partial execution also stops on the first failed step and cannot resume; the user has to create and approve another plan. The database keeps approval state, while Redis supports the surrounding session behavior in a multi-replica deployment.

English guides exist, while English release notes do not

The repository contains 134 paths under docs/en and 172 under docs/zh, including parallel installation, operations, user, MCP, and reference sections. The English material is substantial enough to install the product and understand the approval model. Yet docs/en/changelog/v4.x.md says the English mirror will be added later. The Chinese changelog lists v4.2.2.0 on September 13, 2026, with agent approval, MCP audit work, terminal changes, and many fixes.

GitHub's latest-release endpoint returned 404 because this repository does not publish its product versions there. Operators have to follow the documentation changelog and image tags instead. That makes upgrades less convenient for an English-only team, especially when the README says Kubernetes 1.15 through 1.34 are supported. Pin the image, preserve the database, and translate the relevant Chinese release entry before changing a production console.

Recent commits coexist with 539 open issues and pull requests

The last push was September 27, 2026, and issue activity continued through September 24. GitHub counted 539 open issues and pull requests. Several current reports are specific enough to reproduce during a trial: issue 664 says v4.2.2 failed to load a PostgreSQL driver class, issue 659 reports incorrect Pod CPU and memory requests on Kubernetes 1.33, and issue 657 reports an authorization error for a read-only user. They are reports, not proof that every deployment is affected.

Kuboard is easier to try than to verify. The 5-second dependency install and detailed bilingual manuals make the documentation pleasant to work with, while the absent server source prevents the same inspection of the product. Put it beside a disposable cluster first. If its visual operations and MCP approval flow solve a real problem, test your database, Kubernetes version, read-only roles, backups, and upgrade path before the console touches production credentials.

Alternatives

ProjectWhat it isPick it when
HeadlampAn Apache-licensed Kubernetes web UI with a plugin system and desktop option.pick this instead when auditable open-source application code and extensibility matter more than Kuboard's packaged operations suite.
Rancher gh↗An Apache-licensed platform for operating Kubernetes clusters and the resources running on them.pick this instead when cluster provisioning, fleet management, and a larger ecosystem matter more than a compact visual console.

What people are saying

  1. [velocity-scout] eip-work/kuboard-press

Sources

  1. Kuboard repository README
  2. Kuboard repository
  3. Kuboard v4 quick start
  4. Kuboard high-availability guide
  5. Kuboard MCP approval flow
  6. Kuboard license installation guide
  7. Kuboard Chinese v4 changelog
  8. Kuboard PostgreSQL driver report

More self-hosted reviews

taskview-community · dae · yuvomi · mlmvpn_windows · teable · distribution · the whole board →