Standalone browser UI for the self-hosted agent-bom control plane. Requires the agent-bom API image.
8.2K
Explore scan coverage, investigate exposures, and track remediation in the
self-hosted agent-bom control plane. The dashboard connects to the companion
agentbom/agent-bom API image; scan and evidence state stay in your deployment.
This companion image is not a separate product.
curl -fsSL https://raw.githubusercontent.com/msaad00/agent-bom/main/deploy/docker-compose.pilot.yml -o docker-compose.pilot.yml
docker compose -f docker-compose.pilot.yml up -d
docker compose -f docker-compose.pilot.yml ps
Open http://localhost:3000 once both services are healthy. The pilot binds
to loopback, uses the local analyst role without login, and persists evidence
in the agent-bom-pilot-data Docker volume. It is for single-workstation
evaluation; use configured authentication for a shared deployment.
First result: open New Scan and select a public repository, or open Connections, verify a read-only source grant, and run its first scan. A scan creates the inventory and findings; starting the dashboard alone does not collect an estate. Inspect coverage, open a finding, then follow its evidence and remediation action.
Stop with docker compose -f docker-compose.pilot.yml down. The named data
volume remains available for the next run.
Set AGENT_BOM_API_URL on the UI server to the API's HTTP(S) origin, for
example http://api:8422 inside a Compose network. Browser requests remain
same-origin through the UI proxy. NEXT_PUBLIC_API_URL is accepted as a legacy
fallback. See the deployment guide
for authentication, proxy, and production settings.
For Kubernetes, check out the repository and configure the Helm chart and the identity, database, and ingress settings for your environment.
Product scenarios · Documentation · API and scanner image
The API owns authentication (/v1/auth/policy), tenant quotas
(/v1/auth/quota), paginated graph agents (/v1/graph/agents), and fleet state
(/v1/fleet). The UI reflects those facts and role capabilities; it does not
create a separate role, tenant, gateway, or secret lifecycle.
Content type
Image
Digest
sha256:d2933be2a…
Size
111.1 MB
Last updated
about 12 hours ago
docker pull agentbom/agent-bom-ui