Kubemoot Dashboard

Overview

The Kubemoot Dashboard is a web UI for looking at a running Kubemoot installation. It lists Kubemoot resources across namespaces, shows GPU node and model state, and streams agent discussions and NATS messages as they happen. It is a SvelteKit application that reads the Kubernetes API and the NATS bus from the server side; the browser never connects to either directly.

Metrics, logs, and traces are not part of the dashboard. For those, see Observability.

Install

The dashboard is an optional part of the kubemoot-operator chart, off by default because it has no login and can purge NATS streams and delete models (see SECURITY.md). Turn it on with one flag when you install the operator:

helm upgrade --install kubemoot-operator \
  oci://ghcr.io/kubemoot/charts/kubemoot-operator \
  --namespace kubemoot --create-namespace \
  --set dashboard.enabled=true

Every dashboard setting lives under dashboard: in the operator chart’s values, with the defaults of the standalone chart. global.imageRegistry and global.imagePullSecrets apply to the dashboard image as they do to the operator’s. The chart exposes the app under the /dashboard path prefix and creates no route. To look at it, port-forward the service (named after the release, kubemoot-operator-dashboard for the release above):

kubectl -n kubemoot port-forward svc/kubemoot-operator-dashboard 8080:80

Then open http://localhost:8080/dashboard.

Standalone chart

The dashboard chart is also published on its own, for a cluster where the operator is installed another way:

helm upgrade --install kubemoot-dashboard \
  oci://ghcr.io/kubemoot/charts/kubemoot-dashboard \
  --namespace kubemoot --create-namespace

Its service is kubemoot-dashboard, so the port-forward target is svc/kubemoot-dashboard. Do not run both the standalone release and dashboard.enabled=true in one namespace unless you want two dashboards.

Publishing on a hostname

To publish it on a hostname, the chart renders a Gateway API HTTPRoute when gateway.enabled is true (dashboard.gateway.enabled in the operator chart; see the chart’s values.yaml for the default) or an Ingress when ingress.enabled is true:

gateway:                      # nest under dashboard: in the operator chart's values
  enabled: true
  name: gateway
  namespace: default
  hostnames:
    - kubemoot.example.com
  pathPrefix: /dashboard

The dashboard has no login of its own, whether or not the chart publishes the route. Put authentication in front of it at the Gateway or Ingress layer (an OAuth2 proxy or your platform’s access policy).

What it shows

The sidebar groups pages by what they cover. The Topology page exists by URL (/topology) without a sidebar entry.

SectionPagesShows
TopOverview, NodesCounts and health for every resource type; Kubernetes nodes with GPU detection and model-loading state
MessagingDiscussions, MessagesMulti-agent discussion threads with a timeline view; a NATS subject explorer with a live message viewer
CrewsCrews, Agents, Prompts, Memory, FitnessCrew and agent configuration, PromptModule contents, crew memory, and fitness suite runs
ModelsProviders, Models, EmbeddingsModelProvider backends, Model state, and EmbeddingModel configuration
MCPsMCP Servers, MCP Gateways, Quality Policies, Catalogs, ReportsMCPServer instances and tools, gateway routing, quality policies, catalog discovery, and quality verdicts
KnowledgeRAG SourcesRAGSource indexing status with document and chunk counts
SystemConfigThe KubemootConfig cluster singleton

Status colors

BadgeMeaning
GreenReady or loaded
YellowPending or pulling
RedError or failed
GrayStatus unavailable

Discussions

A two-panel thread viewer. The left panel lists threads, newest first, each tagged with its crew and channel. The right panel shows the message timeline for the selected thread: the question, each agent’s contribution, and the synthesis. Recent threads are replayed from the JetStream history on page load, and new messages arrive live.

Messages

A general NATS subject explorer. Subscribe to any subject pattern (for example kubemoot.chat.> or kubemoot.operator.>), watch JSON payloads as they arrive, and publish to arbitrary subjects. It is useful for debugging agent communication and operator events.

Reports

MCPServerReport quality verdicts (use, caution, avoid) with the evaluation history. An administrator can pin a verdict to override the automated result; this needs patch on mcpserverreports, which the chart’s ClusterRole does not grant by default.

Fitness

CrewFitnessSuite runs and their scores. A running suite has Pause and Stop buttons, and a paused one has Resume and Stop; they set spec.suspend and spec.cancel (see the CrewFitnessSuite reference). The status badge reads Pausing while a paused suite’s last iteration finishes and Stopping until the operator applies a stop. The Fitness page can also delete a suite run; the owned CrewFitness resources are removed with it.

Access the dashboard needs

The chart creates a ClusterRole (kubemoot-dashboard-reader) with these grants:

ResourcesVerbsWhy
nodes, namespaces, podsget, list, watchNode and namespace views
pods/loggetLog access
configmapsget, listAgent prompt bundles for the Agent detail page
deployments (apps)get, list, watchOperator version in the system-info popover
All kubemoot.ai resourcesget, list, watchEvery Kubemoot page
crewfitnesssuitesdelete, patchThe Fitness page “remove run” action, and its Pause, Resume, and Stop actions

The dashboard never reads or displays Secret values. The container runs as a non-root user with a read-only root filesystem.

HTTP API

The SvelteKit server exposes the JSON and event-stream endpoints the pages use. They carry no authentication, so the same rule applies as for the UI: reach them only through an authenticating proxy. List endpoints accept a namespace query parameter; an empty value lists across all namespaces.

EndpointMethodPurpose
/api/health, /api/versionGETHealth check; dashboard version
/api/namespaces, /api/nodesGETNamespaces; Kubernetes nodes with GPU information
/api/kubemoot/<plural> and /api/kubemoot/<plural>/<name>GETList and detail for agents, crews, models, modelproviders, embeddingmodels, mcpservers, mcpgateways, mcpqualitypolicies, mcpcatalogs, mcpserverreports, ragsources, promptmodules, crewfitnesses
/api/kubemoot/config, /api/kubemoot/system-info, /api/kubemoot/topologyGETConfiguration, system information, agent topology graph
/api/kubemoot/crewfitnesssuitesGETFitness suites; sub-paths under <namespace>/<name>/ serve scores, iterations, transcript, and artifact; DELETE on <namespace>/<name> removes a run; PATCH on <namespace>/<name> with {"action": "pause" | "resume" | "stop"} controls it
/api/kubemoot/mcpserverreports/<name>PATCHPin a verdict
/api/kubemoot/modelproviders/<name>/load, /unload, /deletePOSTModel provider actions
/api/kubemoot/crew-memoryGET, POST, DELETECrew memory facts
/api/kubemoot/watch/<plural>GETKubernetes resource updates as server-sent events
/api/nats/subscribe?subject=GETServer-sent events for a NATS subject
/api/nats/history?stream=&subject=&limit=GETJetStream history replay as a JSON array
/api/nats/publishPOSTPublish { "subject", "data" } to NATS
/api/nats/config, /api/nats/kv, /api/nats/stream, /api/nats/purgeGET, POSTNATS connection status, KV, stream, and purge helpers

The browser talks to the SvelteKit server with server-sent events. Only the server holds a NATS connection (the nats client over TCP), so the browser never connects to NATS directly.