Kanea
v0.36.0 GITHUB ↗
ONE STATIC BINARY · FULL ORCHESTRATION PLATFORM

From nothing
to orchestration in
two commands.

No cluster to bootstrap, no CNI to choose, no cert-manager to install, no metrics stack to stand up first. Install, kanea init, and the dashboard on the right is already serving.

$ curl -fsSL https://m18h.github.io/kanea/install.sh | sudo bash

Piping a script into a root shell deserves a look first - read it, or install it by hand. Checksum verification is mandatory, with no flag to skip it.

https://127.0.0.1:8600 WEBSOCKET CONNECTED
The Kanea dashboard, served by the daemon
{{ s.k }}
{{ s.v }}
NO CNI·NO KVSTORE·NO SIDECAR·NO OPERATOR·NO AGENT PER NODE·NO METRICS STACK·NO YAML
01 / INSTALL

Two steps, and none of them are hidden

The installer fetches the binary, verifies it, and stops. It generates no keys and starts nothing - those are decisions with consequences, and a script that made them for you would make them at the moment you understand the node least.

01

Install the binary

Checksum verification is mandatory. If cosign is on PATH, the Sigstore signature is verified too.

$ curl -fsSL https://m18h.github.io/kanea/install.sh | sudo bash
02

Run the ceremony

Checks the node, installs containerd, runc and rootless buildkitd at pinned versions, runs the master-key ceremony, writes the units, starts the control plane. The key is shown once.

$ sudo kanea init
03

Deploy something

No spec file required to start. kanea ui opens the dashboard the daemon already serves.

$ kanea run --image nginx --name web --project demo
$ kanea ui

Requirements

{{ r.k }}
{{ r.v }}

That is the whole list. The runtime is installed by kanea init at pinned versions - Kanea supplies it, not you.

Other ways in

Homebrew - the CLI
macOS is the authoring half: kanea plan validates specs with file-and-line diagnostics, no daemon needed.
$ brew tap m18h/kanea
$ brew trust m18h/kanea
$ brew install kanea
Air-gapped nodes
A supported installation, not a workaround. The bundle carries no hashes of its own - a bundle that supplied its own would be a bundle that authenticates itself.
$ kanea bundle create --arch amd64 -o bundle.tar.gz
$ sudo kanea init --bundle bundle.tar.gz
02 / ARCHITECTURE

A control plane you can read in an afternoon

Three processes from one file. The edge is deliberately not a child of the control plane - restarting kanead never drops a request in flight. Pick a piece.

{{ activeKind }}

{{ activeTitle }}

{{ activeBody }}

{{ activeNote }}
03 / SPEC TO RUNNING

One file describes a service completely

HCL - familiar if you have written Nomad job files. Change the spec and watch the platform it produces change with it.

SHOP.HCL
service "web" {
project = "shop"
count = {{ count }}
task "app" {
image = "registry.example.com/shop/web:1.4.0"
env = {
DATABASE_URL = "secret:shop/database-url" # never inlined
DATABASE_HOST = "${service.postgres.host}"
}
resources { cpu = 500 memory = 512 }
}
network {
port "http" { container = 3000 }
policy { allow_from = ["analytics/collector"] } # else: default-deny
}
expose {
domains = ["shop.example.com"]
tls { mode = "{{ tls }}" }
rate_limit { requests = 100 window = "1m" per = "ip" }
}
health_check "http" { path = "/healthz" interval = "10s" }
scaling {
min = 2 max = 10
metric "rps" { target = 500 } # from eBPF, not a sidecar
}
}
WHAT THAT PRODUCES
{{ o.n }}
{{ o.title }}
{{ o.body }}
$ kanea plan shop.hcl
{{ planLine }}
04 / WHAT SHIPS

No agents. No operator to reconcile the operator.

Eight things you would otherwise assemble, already inside.

{{ s.n }}

{{ s.title }}

{{ s.body }}

05 / THE DASHBOARD

Embedded in the binary, served by the daemon

Not a screenshot of a plan - this is kanea ui on a running node, over one multiplexed websocket. Pick a page.

https://127.0.0.1:8600/ WEBSOCKET CONNECTED
Kanea dashboard
{{ f.k }}
{{ f.v }}
06 / WHERE IT SITS

Fewer moving parts than the thing you run now

Kanea is a single-node platform for people who wanted a platform, not a cluster. That is a trade, and this is the trade.

KANEA
K3S
NOMAD
SWARM
{{ row.k }}
{{ row.a }}
{{ row.b }}
{{ row.c }}
{{ row.d }}

Multi-node scheduling is not what Kanea is for. If you need a cluster, the table already told you which column to read.

“Kanea is the Twi word for light. A node should be something you can see all the way into.”

TWI IS AN AKAN LANGUAGE, SPOKEN IN GHANA
07 / DOCUMENTATION

The specification is the product