Installation Methods
Multiple ways to install KubeBolt, from Docker Compose to in-cluster Helm deployment.
Helm Chart (recommended for Kubernetes)
Production deployment inside your cluster. OCI-based chart on GitHub Container Registry. Also listed on Artifact Hub.
helm install kubebolt oci://ghcr.io/clm-cloud-solutions/kubebolt/helm/kubebolt \
--namespace kubebolt --create-namespace
kubectl -n kubebolt port-forward svc/kubebolt 3000:80
# With an Ingress and your own admin password
helm install kubebolt \
oci://ghcr.io/clm-cloud-solutions/kubebolt/helm/kubebolt \
--namespace kubebolt --create-namespace \
--set auth.adminPassword=YourSecurePassword \
--set ingress.enabled=true \
--set ingress.className=nginx \
--set ingress.hosts[0].host=kubebolt.example.com \
--set ingress.hosts[0].paths[0].path=/ \
--set ingress.hosts[0].paths[0].pathType=Prefix
The chart deploys the API, the web UI and a single-node VictoriaMetrics for
history (10 GiB PVC, 30-day retention; a second 1 GiB PVC holds KubeBolt’s own
data — both on the cluster’s default StorageClass), plus a ServiceAccount and a
ClusterRole. The ClusterRole grants read access to every resource type
KubeBolt shows and the write verbs its actions need (exec, port-forward,
evict, scale, restart, edit, create, delete) — set rbac.create=false and
bind your own role if you want a narrower one. KubeBolt probes what its
credentials may do and hides the rest. Configurable values include image
tags, resources, Ingress, auth, metrics storage and RBAC; the full list is in
the chart README. Where ingress-nginx isn’t an option,
the chart can expose KubeBolt through the Gateway API instead — set
gatewayAPI.enabled=true (use one or the other, not both).
The agent chart
Historical metrics, network flows and cost come from the optional agent, shipped as its own OCI chart with an independent release cadence:
helm install kubebolt-agent \
oci://ghcr.io/clm-cloud-solutions/kubebolt/helm/kubebolt-agent \
--namespace kubebolt-system --create-namespace \
--set backendUrl=kubebolt-agent-ingest.kubebolt.svc.cluster.local:9090
That backendUrl is the in-cluster Service of a release named kubebolt in
the kubebolt namespace (<release>-agent-ingest.<namespace>). Remote
clusters dial a public address instead; see Connecting clusters.
In practice you rarely write this command by hand — the Add cluster wizard generates it with the right values for your setup (Prometheus mode, OpenCost, mTLS).
Upgrading: upgrade the two charts independently. For the agent, prefer
passing your values explicitly (or a values file) over --reuse-values, so
chart defaults added in new versions aren’t silently pinned to old ones.
Docker Compose
Full stack with separate API, web and VictoriaMetrics containers. Compose
builds the API and web images from the checkout, so the first up takes a few
minutes.
deploy/docker-compose.yml and deploy/docker-kubeconfig.sh are files in the
git repository, not published artifacts, so Compose starts with a clone:
git clone https://github.com/clm-cloud-solutions/kubebolt.git
cd kubebolt
# The compose file mounts /tmp/docker-kubeconfig, so every install runs the
# helper first. On remote clusters the rewrite is a no-op; it just copies.
./deploy/docker-kubeconfig.sh
cd deploy && docker compose up -d
Frontend at http://localhost:3000. Compose publishes four ports on the host:
3000 (web UI), 8080 (Go API, HTTP and WebSocket), 9090 (gRPC agent ingest) and
8428 (VictoriaMetrics). The generated admin password is printed once to the
API log on first boot (docker compose logs api).
EKS note: The compose file mounts ~/.aws, but the API image it builds
does not include the AWS CLI, so kubeconfigs that run aws eks get-token
fail inside the container. For EKS, prefer the binary, Homebrew or the
single-container image (which ships aws-cli) — see the EKS guide.
Single Binary (macOS, Linux, Windows)
One executable with embedded frontend. API + UI in a single process on one port. Download from GitHub Releases.
# macOS Apple Silicon
curl -LO https://github.com/clm-cloud-solutions/kubebolt/releases/latest/download/kubebolt-darwin-arm64
chmod +x kubebolt-darwin-arm64 && mv kubebolt-darwin-arm64 /usr/local/bin/kubebolt
# Linux amd64
curl -LO https://github.com/clm-cloud-solutions/kubebolt/releases/latest/download/kubebolt-linux-amd64
chmod +x kubebolt-linux-amd64 && sudo mv kubebolt-linux-amd64 /usr/local/bin/kubebolt
# Run (reads every context in the kubeconfig; admin password printed once to the log)
kubebolt --kubeconfig ~/.kube/config
Available for darwin-arm64, darwin-amd64, linux-arm64, linux-amd64, and windows-amd64 (kubebolt-windows-amd64.exe), plus .tar.gz / .zip archives and the kubebolt-mcp stdio server for each platform. Verify with sha256sum -c CHECKSUMS.txt.
The single binary (like Homebrew, krew and the single-container image) does
not bundle a time-series store. Live views work without one; for history,
point KUBEBOLT_METRICS_STORAGE_URL at a VictoriaMetrics, or use the
Compose stack or the Helm chart.
.env support: The binary auto-loads a .env file from the current directory. Put KUBEBOLT_ADMIN_PASSWORD, KUBEBOLT_AI_API_KEY, etc. in a .env file next to the binary. System env vars and CLI flags take precedence.
To build your own binary from a checkout instead of downloading a release:
make build-binary
# Produces apps/api/kubebolt (embedded frontend)
Running from source for development is documented once, in Contributing.
Homebrew (macOS, Linux)
Install and update via Homebrew. Automatic version management via brew upgrade. Available for macOS and Linux (amd64 + arm64).
# Add the CLM tap (one-time setup)
brew tap clm-cloud-solutions/tap
# Install
brew install kubebolt
# Run
kubebolt --kubeconfig ~/.kube/config
# Update to the latest version
brew upgrade kubebolt
Docker (single container)
Single image with embedded frontend. No nginx, no compose. Multi-arch (amd64/arm64).
docker run -p 3000:3000 \
-v ~/.kube/config:/kubeconfig:ro -e KUBECONFIG=/kubeconfig \
ghcr.io/clm-cloud-solutions/kubebolt:latest
The image runs as a non-root user (kubebolt), so mounting ~/.kube onto
/root/.kube does not work — the process can’t read /root. Mount the file
and point KUBECONFIG at it, as above. On Linux the kubeconfig file must be
readable by that user. The embedded database lives in the /data volume;
mount one (-v kubebolt-data:/data) if you want users and settings to survive
a container restart.
The image is signed with Cosign. Verify with:
cosign verify ghcr.io/clm-cloud-solutions/kubebolt:latest \
--certificate-identity-regexp 'https://github.com/clm-cloud-solutions/kubebolt/.*' \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
EKS note: The image includes aws-cli. For EKS clusters, mount your AWS config into the non-root user’s home (-v ~/.aws:/home/kubebolt/.aws:ro) and set AWS_PROFILE if you use one, so the kubeconfig’s aws eks get-token exec can obtain tokens.
kubectl Plugin (krew)
Run KubeBolt as a kubectl subcommand. Available via CLM’s custom krew index.
# Prerequisite: install krew (one-time)
# https://krew.sigs.k8s.io/docs/user-guide/setup/install/
# Add the CLM custom index
kubectl krew index add clm https://github.com/clm-cloud-solutions/krew-index.git
# Install
kubectl krew install clm/kubebolt
# Run (uses current kubectl context)
kubectl kubebolt
# Update
kubectl krew upgrade clm/kubebolt
Not built yet
Three more distribution methods are designed but not shipped. There is no URL to give you for any of them yet — when one lands it gets a section above, not a placeholder here.
- One-line install script. A
curl … | shthat detects OS and architecture and drops the binary in place. No such script exists in the repository today; until it does, use the single binary download or Homebrew. - Official krew-index. Once
kubeboltis accepted upstream intokubernetes-sigs/krew-index,kubectl krew install kubeboltwill work without adding the CLM custom index. Until then, use the custom index above. - Kubernetes Operator. Declarative lifecycle management through a
KubeBoltCRD in a separate Kubebuilder controller, handling upgrades and self-healing. Today the Helm chart is the supported in-cluster lifecycle.
Track these on the public roadmap.
Next
Once KubeBolt is up, connect your clusters — kubeconfig, the outbound-only agent, or metrics-only.