Dakera Dashboard
The Dakera Dashboard is the admin UI for operating a Dakera server. Version 0.4.0 is built for Dakera v0.12.0 and still works against 0.11.x: pages for features an older server lacks leave those parts out. Image: ghcr.io/dakera-ai/dakera-dashboard:0.4.0.
A look inside
Six views that show what you get once the dashboard is running. Swipe, use the arrow keys, or pick a dot, and open any view full screen.






What is in it
One sidebar lists every page in five sections. Features show only when the server has them enabled (for example attachments and records).
| Page | What you do there |
|---|---|
| Overview | See what needs attention: degraded components, configuration warnings, re-embedding, exceeded quotas, failed backups, expiring keys. Also stored vectors, agents, storage, recall latency and cache hit rate. |
| Server health | Degraded components, configuration warnings, background re-embedding with progress, rate and ETA, readiness checks, clock drift and model downloads while the server starts. |
| Capabilities | Models, index kinds, scoring, query languages and the multimodal switches the server reports. |
| Recall lab | Run recall or search for an agent with lang, routing and rerank, and inspect each result's score and the rerank_report. |
| Namespaces | Sizes, quota usage, contents, semantic and keyword search, full-text statistics and reindex, attachments, records, export, delete and maintenance. |
| Agents and memories | Filter, edit, forget and consolidate memories; browse sessions; add a memory with its language. |
| API keys | Create scoped keys pinned to namespaces and agents, with an expiry. Replace a key without downtime (see below). |
| Quotas | Usage against limits and enforcement mode. |
| Backups | Create and restore backups with progress, restore modes, encryption and compression status. |
| Encryption | Keyring status, key rotation and re-seal progress. |
| Cluster | Election, replication, held changes, members, maintenance and background jobs. |
The dashboard also has monitoring pages (analytics, slow queries, live feed, audit log), explore tools (query builder, knowledge graph) and SDK and MCP setup snippets.
Rotating a key without downtime
The Replace action creates a new key with the same scope, namespaces and remaining lifetime and shows it once. The old key keeps working until you confirm your clients have moved and deactivate or revoke it.
How sign-in works
You sign in at /login with your own Dakera API key. The dashboard server checks it against the Dakera API and keeps it in server memory. Your browser gets only an opaque session id in an HttpOnly, SameSite=Strict cookie (Secure and __Host- prefixed over HTTPS). The key is never sent to the browser, and nothing is stored in localStorage, page HTML or URLs. The dashboard adds the Authorization header to API calls itself and ignores any key the browser sends.
Sessions end after DAKERA_SESSION_TTL_HOURS (default 12) or after 2 hours without use.
What each key scope can do
| Key scope | What works |
|---|---|
read | Overview, namespaces, agents, sessions, query tools, knowledge graph, SDK and MCP pages. |
write | Everything read does, plus storing, updating and deleting memories and vectors. |
admin | Everything write does, plus node-wide pages: cluster, storage, analytics, monitoring, backups (list, create, delete) and encryption status. |
super_admin | Everything, including API keys (all keys) and backup download, upload and restore. |
admin pinned to namespaces | Its own namespaces and the API keys for those namespaces. The server refuses it on node-wide routes. |
A page your key cannot use says which scope it needs, and the sidebar marks it. Use the lowest scope that suffices.
Run it
Docker Compose
The dakera-deploy compose file has an optional dashboard service in the dashboard profile. It points at the Dakera service and publishes on 127.0.0.1:3002.
docker compose --profile dashboard up -d
Open http://127.0.0.1:3002 and sign in with a Dakera API key. Set DASHBOARD_PORT to change the port and DASHBOARD_IMAGE to pin another image.
docker run
docker run -d --name dakera-dashboard -p 127.0.0.1:3002:3000 -e DAKERA_API_UPSTREAM=http://dakera:3000 ghcr.io/dakera-ai/dakera-dashboard:0.4.0
DAKERA_API_UPSTREAM is the Dakera API URL as the dashboard container reaches it, so put both on the same Docker network (or use a host address).
| Variable | Default | Description |
|---|---|---|
DAKERA_ | http:// | Dakera API the dashboard proxies to |
DAKERA_ | 12 | Longest a sign-in lasts (15 minutes to 7 days). Idle sessions end after 2 hours. |
The container serves on port 3000. The healthcheck is /_session/healthz:
curl -fs http://localhost:3000/_session/healthz
/health/live and /health/ready stay public for orchestrators; the detailed /health needs a session.
Production notes
- Put TLS in front. The proxy must terminate TLS and forward
X-Forwarded-Protoand the originalHost. The session cookie is markedSecureonly forX-Forwarded-Proto: https, and state-changing requests are accepted only when theirOriginmatches the forwarded host. - Sessions live in memory. A restart signs everyone out. Run one replica, or use sticky sessions, otherwise a request on another replica asks for a new sign-in. No volume is needed.
- Bind to localhost or a private network. Do not expose the plain-HTTP port to the internet, because the API key is typed into the login form.
Upgrading from 0.3.x
Until 0.3.x the container wrote DAKERA_API_KEY into every served page, so anyone who could load the dashboard held that key. 0.4.0 removes it.
- Remove
DAKERA_API_KEYandDAKERA_CLIENT_URLfrom the dashboard container. Both are now ignored with a startup warning. - Rotate the key the old dashboard carried if the dashboard was reachable by people who should not hold it.
- Keep
DAKERA_API_UPSTREAM.DAKERA_SESSION_TTL_HOURSis new and optional. - Update any healthcheck or probe to
/_session/healthz. - Operators now sign in with their own API keys.
Related
- dakera-deploy: compose files and the Dashboard 0.4.0 notes
- Deployment: Docker, Kubernetes and systemd
- Security: API keys, scopes and permissions
- Upgrading from v0.11.108: moving the server to v0.12.0