Overview
kimbap is a self-hosted Go application for deploying and managing docker-compose projects on a single host. Think of it as a lean, Go-native alternative to Coolify, Dokploy, or CapRover: point it at a fresh Linux server, and it can install Docker itself, run a web UI for creating and managing projects, optionally front everything with an automatically-SSL'd Traefik reverse proxy, and expose an MCP server so an AI agent — Claude, ChatGPT, or anything else that speaks MCP — can manage the host directly. It also runs on macOS and Windows for local/desktop use — see Install for the platform differences.
What it does
- Project management. Create a project from a
docker-compose.yml(and optional.env), stored directly on the filesystem — not hidden in a database. Deploy, stop, restart, view live container status, and tail logs, all from the web UI, the REST API, or an MCP tool call. - User management. A small built-in login system — username/password
accounts with
admin/memberroles, cookie-based sessions, and per-user API keys for scripted or MCP access. No external identity provider required. - Docker lifecycle. kimbap detects whether Docker is installed and offers
to install or update it via Docker's official
get.docker.comscript — confirmation-gated, never silent. - Reverse proxy + SSL, if you want it. kimbap can provision and manage a
Traefik instance in front of everything, with
automatic Let's Encrypt certificates. Projects register domains through
kimbap's UI/API/MCP tools; kimbap wires up the Traefik routing for you.
Turn it on (
KIMBAP_TRAEFIK_ENABLED=true) if you want that; by default kimbap just runs on its own address, for you to reach directly or front with your own reverse proxy/tunnel instead — see Domains & TLS. - MCP server. A remote, API-key-authenticated MCP endpoint at
/mcplets any MCP-compatible AI agent — Claude Code, claude.ai, ChatGPT, or otherwise — manage the host directly: create and deploy projects, check status, read logs, manage domains, and (with an admin key) install Docker or provision Traefik.
Architecture, in one paragraph
kimbap runs as a native binary — never as a Docker container itself.
This is deliberate: kimbap needs to be able to install Docker onto a host
where Docker doesn't exist yet, and a containerized kimbap couldn't do that
(it would need the very engine it's trying to install). On Linux it
installs itself as a systemd service; on macOS and Windows you run the
binary directly (kimbap run) instead — see Install. By
default kimbap just listens on a plain local port and expects
something else to front it (or nothing at all). Set
KIMBAP_TRAEFIK_ENABLED=true and once Docker exists, kimbap manages a
Traefik container in front of itself and every project it deploys instead:
it reaches kimbap's own UI through a file provider route (since kimbap
isn't a container Traefik's Docker provider can discover), and reaches
project containers through the Docker provider (label-based
auto-discovery). See Domains & TLS for the full mechanism.
Where things live on disk
On Linux this is /var/lib/kimbap/ (the systemd install's default state
dir); on macOS/Windows it's whatever --state-dir you pass kimbap run.
Same layout either way:
/var/lib/kimbap/
├── kimbap.db # sqlite: users, sessions, API keys, project registry, domains, audit log
├── projects/<slug>/
│ ├── docker-compose.yml # yours — kimbap never rewrites this
│ ├── docker-compose.kimbap-labels.yml # auto-generated Traefik routing (only when the project has domains)
│ └── .env
└── traefik/ # only present if KIMBAP_TRAEFIK_ENABLED=true
├── docker-compose.yml # kimbap-managed Traefik service
├── traefik.yml # static config
├── acme.json # Let's Encrypt certificate storage
└── dynamic/kimbap-ui.yml # routes kimbap's own UI
Next steps
- Install kimbap on a host.
- Walk through the quick start to deploy your first project.
- See every setting kimbap has in Configuration — including turning on Traefik.
- Point an AI agent at it via the MCP guide.