kneo-dash
The backend-for-frontend (BFF) for the Kneo Agent Dashboard — the
operational console for the Kneo Agent Platform.
A thin FastAPI layer over the typed kneo-client
SDK: it answers an operator's five questions — what is running, what is stuck,
what needs human action, what changed, is production healthy — and serves the
dashboard SPA. It never imports kneo-serv and never puts platform API keys in
the browser.
This package runs either as the container image ghcr.io/kneo-agent/kneo-dash
(BFF + built SPA in one unit) or as the PyPI wheel — the published wheel
bundles the built SPA (ADR-011), so pip install kneo-dash && kneo-dash serves
the full app (UI + API) same-origin, no container. (A source/editable build without
the SPA staged runs API-only.)
Install
pip install kneo-dash
Run
The platform connection comes from the kneo-client profile environment
(KNEO_URL + KNEO_API_KEY, or a ~/.config/kneo/client.toml profile):
# Local/trial: KNEO_DASH_DEV_MODE=1 runs a single UNAUTHENTICATED operator (static mode).
# The BFF refuses to start in static mode without it (ADR-009 §5); for a real deployment
# use OIDC instead (KNEO_DASH_AUTH_MODE=oidc + KNEO_DASH_SESSION_SECRET + provider config).
KNEO_URL=https://your-kneo-serv KNEO_API_KEY=… KNEO_DASH_DEV_MODE=1 kneo-dash # BFF on :8090
Dashboard-server settings use the KNEO_DASH_ env prefix (e.g. KNEO_DASH_AUTH_MODE,
KNEO_DASH_SESSION_SECRET, KNEO_DASH_DEFAULT_PROFILE, KNEO_DASH_CORS_ORIGINS,
KNEO_DASH_SPA_DIR).
Scope (0.5.0)
Container-free full install · review-hardening. 0.5.0 bundles the built SPA into the wheel
and the sdist (ADR-011), so a
bare pip install kneo-dash && kneo-dash serves the full UI + API same-origin with no Docker;
it also clears a two-review punch list (workflow deep audit + external review) and lands the
frontend majors (React 19 · router 7). Builds on the 0.4.0 auth · RBAC · dashboard config ·
hardening cut, which itself builds on the 0.2.0 live-debugging core (runs
list + detail: status · trace · run-graph · continuation chain · replay/recovery ·
time-travel diff · live SSE trace tail; run control; the human-in-the-loop queue;
Launch Load → Deploy → Run). 0.3.0 wires the governance surfaces —
audit (search/paginate), policies (view · preview · update), and the
credential-reference inventory (references + scopes; secret values never
surfaced) — adds a per-run policy report, session/thread grouping, an
operator Overview, HITL bulk resume, 2-run compare, error clusters,
recover & continue, and a client-side run-bundle export. It also introduces
the dashboard state store (SQLite by default — stdlib; optional Postgres via the
[postgres] extra + KNEO_DASH_DB_URL) backing operator annotations, saved
Runs filters, and launch history / re-launch. Since 0.4.0 the BFF
authenticates operators (OIDC) and enforces roles server-side, with a live Connections
env-switcher; run KNEO_DASH_AUTH_MODE=oidc (the unauthenticated static mode is dev-only
and refuses to start without KNEO_DASH_DEV_MODE=1).
Links
- Source & docs: https://github.com/kneo-agent/kneo-dash
- License: MIT
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file kneo_dash-0.6.0.tar.gz.
File metadata
- Download URL: kneo_dash-0.6.0.tar.gz
- Upload date:
- Size: 293.1 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b462362ddad2ec55f249c3be67f368de5820abe7b39e2a78a6a011ce174c6ab5
|
|
| MD5 |
8d75e5227af8dcf40e484e90bd62271a
|
|
| BLAKE2b-256 |
27e8bc2167fd090a1260252bf82b84578ae4cda151679bd53383a9f96c98b107
|
Provenance
The following attestation bundles were made for kneo_dash-0.6.0.tar.gz:
Publisher:
release.yml on kneo-agent/kneo-dash
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
kneo_dash-0.6.0.tar.gz -
Subject digest:
b462362ddad2ec55f249c3be67f368de5820abe7b39e2a78a6a011ce174c6ab5 - Sigstore transparency entry: 2181934551
- Sigstore integration time:
-
Permalink:
kneo-agent/kneo-dash@7041321327acd943cebb5b75414a5848334a173b -
Branch / Tag:
refs/tags/v0.6.0 - Owner: https://github.com/kneo-agent
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@7041321327acd943cebb5b75414a5848334a173b -
Trigger Event:
push
-
Statement type:
File details
Details for the file kneo_dash-0.6.0-py3-none-any.whl.
File metadata
- Download URL: kneo_dash-0.6.0-py3-none-any.whl
- Upload date:
- Size: 252.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
65aa930ea28818e4dcf9fa12d671382275bcb1b56a4e60346989ae4098d2b92d
|
|
| MD5 |
a290af6796aaa5939c604bc325ccfbec
|
|
| BLAKE2b-256 |
d17437be036b8b17942435ba9e6574a5fe1d65c33ecedd4643180c06be07d4c9
|
Provenance
The following attestation bundles were made for kneo_dash-0.6.0-py3-none-any.whl:
Publisher:
release.yml on kneo-agent/kneo-dash
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
kneo_dash-0.6.0-py3-none-any.whl -
Subject digest:
65aa930ea28818e4dcf9fa12d671382275bcb1b56a4e60346989ae4098d2b92d - Sigstore transparency entry: 2181934880
- Sigstore integration time:
-
Permalink:
kneo-agent/kneo-dash@7041321327acd943cebb5b75414a5848334a173b -
Branch / Tag:
refs/tags/v0.6.0 - Owner: https://github.com/kneo-agent
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@7041321327acd943cebb5b75414a5848334a173b -
Trigger Event:
push
-
Statement type: