KubeBolt docs
GitHub

Installation Methods

Multiple ways to install KubeBolt, from Docker Compose to in-cluster Helm deployment.

Production deployment inside your cluster. OCI-based chart on GitHub Container Registry. Also listed on Artifact Hub.

helm install kubebolt oci://ghcr.io/clm-cloud-solutions/kubebolt/helm/kubebolt \
  --namespace kubebolt --create-namespace

kubectl -n kubebolt port-forward svc/kubebolt 3000:80

# With an Ingress and your own admin password
helm install kubebolt \
  oci://ghcr.io/clm-cloud-solutions/kubebolt/helm/kubebolt \
  --namespace kubebolt --create-namespace \
  --set auth.adminPassword=YourSecurePassword \
  --set ingress.enabled=true \
  --set ingress.className=nginx \
  --set ingress.hosts[0].host=kubebolt.example.com \
  --set ingress.hosts[0].paths[0].path=/ \
  --set ingress.hosts[0].paths[0].pathType=Prefix

The chart deploys the API, the web UI and a single-node VictoriaMetrics for history (10 GiB PVC, 30-day retention; a second 1 GiB PVC holds KubeBolt’s own data — both on the cluster’s default StorageClass), plus a ServiceAccount and a ClusterRole. The ClusterRole grants read access to every resource type KubeBolt shows and the write verbs its actions need (exec, port-forward, evict, scale, restart, edit, create, delete) — set rbac.create=false and bind your own role if you want a narrower one. KubeBolt probes what its credentials may do and hides the rest. Configurable values include image tags, resources, Ingress, auth, metrics storage and RBAC; the full list is in the chart README. Where ingress-nginx isn’t an option, the chart can expose KubeBolt through the Gateway API instead — set gatewayAPI.enabled=true (use one or the other, not both).

The agent chart

Historical metrics, network flows and cost come from the optional agent, shipped as its own OCI chart with an independent release cadence:

helm install kubebolt-agent \
  oci://ghcr.io/clm-cloud-solutions/kubebolt/helm/kubebolt-agent \
  --namespace kubebolt-system --create-namespace \
  --set backendUrl=kubebolt-agent-ingest.kubebolt.svc.cluster.local:9090

That backendUrl is the in-cluster Service of a release named kubebolt in the kubebolt namespace (<release>-agent-ingest.<namespace>). Remote clusters dial a public address instead; see Connecting clusters.

In practice you rarely write this command by hand — the Add cluster wizard generates it with the right values for your setup (Prometheus mode, OpenCost, mTLS).

Upgrading: upgrade the two charts independently. For the agent, prefer passing your values explicitly (or a values file) over --reuse-values, so chart defaults added in new versions aren’t silently pinned to old ones.

Docker Compose

Full stack with separate API, web and VictoriaMetrics containers. Compose builds the API and web images from the checkout, so the first up takes a few minutes.

deploy/docker-compose.yml and deploy/docker-kubeconfig.sh are files in the git repository, not published artifacts, so Compose starts with a clone:

git clone https://github.com/clm-cloud-solutions/kubebolt.git
cd kubebolt

# The compose file mounts /tmp/docker-kubeconfig, so every install runs the
# helper first. On remote clusters the rewrite is a no-op; it just copies.
./deploy/docker-kubeconfig.sh
cd deploy && docker compose up -d

Frontend at http://localhost:3000. Compose publishes four ports on the host: 3000 (web UI), 8080 (Go API, HTTP and WebSocket), 9090 (gRPC agent ingest) and 8428 (VictoriaMetrics). The generated admin password is printed once to the API log on first boot (docker compose logs api).

EKS note: The compose file mounts ~/.aws, but the API image it builds does not include the AWS CLI, so kubeconfigs that run aws eks get-token fail inside the container. For EKS, prefer the binary, Homebrew or the single-container image (which ships aws-cli) — see the EKS guide.

Single Binary (macOS, Linux, Windows)

One executable with embedded frontend. API + UI in a single process on one port. Download from GitHub Releases.

# macOS Apple Silicon
curl -LO https://github.com/clm-cloud-solutions/kubebolt/releases/latest/download/kubebolt-darwin-arm64
chmod +x kubebolt-darwin-arm64 && mv kubebolt-darwin-arm64 /usr/local/bin/kubebolt

# Linux amd64
curl -LO https://github.com/clm-cloud-solutions/kubebolt/releases/latest/download/kubebolt-linux-amd64
chmod +x kubebolt-linux-amd64 && sudo mv kubebolt-linux-amd64 /usr/local/bin/kubebolt

# Run (reads every context in the kubeconfig; admin password printed once to the log)
kubebolt --kubeconfig ~/.kube/config

Available for darwin-arm64, darwin-amd64, linux-arm64, linux-amd64, and windows-amd64 (kubebolt-windows-amd64.exe), plus .tar.gz / .zip archives and the kubebolt-mcp stdio server for each platform. Verify with sha256sum -c CHECKSUMS.txt.

The single binary (like Homebrew, krew and the single-container image) does not bundle a time-series store. Live views work without one; for history, point KUBEBOLT_METRICS_STORAGE_URL at a VictoriaMetrics, or use the Compose stack or the Helm chart.

.env support: The binary auto-loads a .env file from the current directory. Put KUBEBOLT_ADMIN_PASSWORD, KUBEBOLT_AI_API_KEY, etc. in a .env file next to the binary. System env vars and CLI flags take precedence.

To build your own binary from a checkout instead of downloading a release:

make build-binary
# Produces apps/api/kubebolt (embedded frontend)

Running from source for development is documented once, in Contributing.

Homebrew (macOS, Linux)

Install and update via Homebrew. Automatic version management via brew upgrade. Available for macOS and Linux (amd64 + arm64).

# Add the CLM tap (one-time setup)
brew tap clm-cloud-solutions/tap

# Install
brew install kubebolt

# Run
kubebolt --kubeconfig ~/.kube/config

# Update to the latest version
brew upgrade kubebolt

Docker (single container)

Single image with embedded frontend. No nginx, no compose. Multi-arch (amd64/arm64).

docker run -p 3000:3000 \
  -v ~/.kube/config:/kubeconfig:ro -e KUBECONFIG=/kubeconfig \
  ghcr.io/clm-cloud-solutions/kubebolt:latest

The image runs as a non-root user (kubebolt), so mounting ~/.kube onto /root/.kube does not work — the process can’t read /root. Mount the file and point KUBECONFIG at it, as above. On Linux the kubeconfig file must be readable by that user. The embedded database lives in the /data volume; mount one (-v kubebolt-data:/data) if you want users and settings to survive a container restart.

The image is signed with Cosign. Verify with:

cosign verify ghcr.io/clm-cloud-solutions/kubebolt:latest \
  --certificate-identity-regexp 'https://github.com/clm-cloud-solutions/kubebolt/.*' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

EKS note: The image includes aws-cli. For EKS clusters, mount your AWS config into the non-root user’s home (-v ~/.aws:/home/kubebolt/.aws:ro) and set AWS_PROFILE if you use one, so the kubeconfig’s aws eks get-token exec can obtain tokens.

kubectl Plugin (krew)

Run KubeBolt as a kubectl subcommand. Available via CLM’s custom krew index.

# Prerequisite: install krew (one-time)
# https://krew.sigs.k8s.io/docs/user-guide/setup/install/

# Add the CLM custom index
kubectl krew index add clm https://github.com/clm-cloud-solutions/krew-index.git

# Install
kubectl krew install clm/kubebolt

# Run (uses current kubectl context)
kubectl kubebolt

# Update
kubectl krew upgrade clm/kubebolt

Not built yet

Three more distribution methods are designed but not shipped. There is no URL to give you for any of them yet — when one lands it gets a section above, not a placeholder here.

Track these on the public roadmap.

Next

Once KubeBolt is up, connect your clusters — kubeconfig, the outbound-only agent, or metrics-only.