KubeBolt docs
GitHub

Actions & Governance

The full action surface, RBAC enforcement, dry-run previews, the Kobi governance switches, and the audit trail behind every mutation.

KubeBolt does not only observe — it acts. Actions reach the cluster from two origins: a UI action on a resource page, or a Kobi proposal you approve in chat. Every one of them is RBAC-enforced, most can be previewed before they run, and all of them are recorded in the audit trail. This page covers the action surface and the controls around it.

The action surface

The API and the UI ship more actions than Kobi can propose. Kobi’s propose_* tools are a curated subset — the nine changes that are useful to reason about in a conversation.

ActionEndpointRoleKobi can propose
Rolling restartPOST …/restartEditorpropose_restart_workload
Scale replicasPOST …/scaleEditorpropose_scale_workload
Roll back a DeploymentPOST …/rollbackEditorpropose_rollback_deployment
Set container imagePOST …/set-imageEditorpropose_set_image
Set requests / limitsPOST …/set-resourcesEditorpropose_set_resources
Set environment variablesPOST …/set-envEditorpropose_set_env
HPA min/max replicasPOST /resources/hpas/…/set-boundsEditorpropose_patch_hpa
Ephemeral debug containerPOST …/debugEditorpropose_debug_pod
Delete a resourceDELETE /resources/{type}/{ns}/{name}Adminpropose_delete_resource
Apply edited YAMLPUT …/yamlEditor—
Create from a manifestPOST /resources/{type}/{ns}Editor—
Edit labels and annotationsPOST …/edit-metadataEditor—
Reveal a Secret valuePOST /resources/secrets/…/revealEditor, Admin in production namespaces—
Cordon / uncordon a nodePOST …/cordon · …/uncordonEditor—
Evict a podPOST …/evictEditor—
Pause / resume a rolloutPOST …/rollout-pause · …/rollout-resumeEditor—
CronJob suspend / resume / triggerPOST …/suspend · …/resume · …/triggerEditor—
Drain a nodePOST …/drain (GET tracks, DELETE cancels)Admin—
Open a port-forwardPOST /portforwardEditor—

Drain sits with delete at Admin because evicting every pod on a node can violate PodDisruptionBudgets and degrade cluster capacity. Cordon and uncordon stay at Editor — they only flip a scheduling flag. A single-pod evict is Editor too: it goes through the policy/v1 Eviction API, so a PDB that would be violated returns 429 instead of a disruption.

The origin is stamped on every record via the X-KubeBolt-Action-Source header: ui by default, copilot_proposal when you approved it in chat. An action that started from an insight keeps the originating insight id on the Kobi conversation, so the audit trail can be walked from symptom to fix.

Dry-run preview

Every action Kobi can propose accepts ?dryRun=true — restart, scale, rollback, set-image, set-resources, set-env, set-bounds, debug, and delete. The dry run goes through full admission (dryRun=All), so quota violations, LimitRanges and admission webhooks surface before you approve, with the quota detail parsed out of the apiserver’s error rather than shown raw. Kobi’s action card runs that preview automatically for every proposal except rollback, which the card executes without a preview.

Governance switches

Two toggles bound what Kobi may execute. Both default to on, and both can be changed in Administration → AI (Kobi) → Configuration without a restart:

Env varDefaultEffect when off
KUBEBOLT_AI_ACTIONS_ENABLEDtrueThe propose_* tools are withheld from the model entirely. Kobi still diagnoses and recommends, and offers the equivalent kubectl command instead.
KUBEBOLT_AI_DESTRUCTIVE_ACTIONS_ENABLEDtrueDestructive verbs are withheld from the model and rejected server-side. This also catches scale-to-zero, which shares the non-destructive scale tool and so cannot be filtered out of the tool list.

These two switches govern Kobi-proposed actions only — the server-side gate matches on X-KubeBolt-Action-Source: copilot_proposal. A UI action from a resource page is governed by RBAC, not by these toggles. Turning KUBEBOLT_AI_ACTIONS_ENABLED off makes Kobi advisory; it does not make the install read-only. For that, give people the Viewer role.

Together they let you match the blast radius to the environment: full proposal and execution in dev, diagnosis only in production, for example.

Audit trail

Every mutation is persisted with the operator’s identity, the action source, the parameters applied, and the result. The trail is read through the API — there is no audit page in the open-source UI:

curl -H "Authorization: Bearer $TOKEN" \
  "https://kubebolt.example.com/api/v1/admin/actions?class=mutation&limit=200"

GET /api/v1/admin/actions is admin only and returns the newest records first. class is mutation, access or all (the default); limit defaults to 100 (maximum 1000). Records are pruned after KUBEBOLT_AUDIT_RETENTION_HORIZON (default 2160h, 90 days).

Two action types carry extra audit weight:

Actions always run under the detected RBAC permissions — Kobi can never do more than the cluster grants. See RBAC for how KubeBolt detects and adapts to your kubeconfig’s permissions, and Connecting Clusters for the agent’s three permission tiers.