Skip to content

Services

kabactl server starts several services in one process. This page lists them, then shows how to keep the server running in the background.

ServiceListens onPurpose
HTTPS API0.0.0.0:28832Everything the client asks the engine to do.
SOCKS5 proxy0.0.0.0:28833Browsing and terminal traffic, with ad blocking, Safe Browsing and exit routing.
Tor SOCKS5127.0.0.1:28834The same proxy with every connection forced through Tor.
Cluster endpointQUIC, no fixed portThe encrypted mesh between your devices. See cluster & mesh.

The API and proxy ports are fixed in kabactl 0.87; --bind, --port and the port keys in config.toml are not applied. Both listen on all interfaces, so on a machine with a public address, restrict them with your firewall:

Terminal window
# example: allow only loopback to reach the API and proxy
sudo ufw deny 28832/tcp
sudo ufw deny 28833/tcp

The cluster does not need either port open. Peers reach each other through the mesh endpoint, which makes outbound connections and uses a relay when a direct path is not possible.

The API is served with the certificate in certs/. It answers GET /health without authentication; everything else needs a session token (issued at sign-in and valid for jwt_exp_time seconds) or an API key. API keys start with kaba_ and are stored hashed.

Areas of the API:

AreaRoutes underUsed for
Accounts and sessionsusers, session, auth, api-keysSign-in, profile, API keys
Devices and groupsdevices, groups, clusterPeers, invites, eviction
Policies and settingspolicies, settingsModel policies and preferences
Browsing dataframes, visits, sitedataSaved frames, history, per-site data
Memorymemories, trajectories, ontologyMemories, learning data, the tool-loop knowledge graph
Modelsengine, loras, training, vision, voiceInference, adapters, training, image description, speech
Toolssandbox, tool, term, files, folderContainers, tool runs, terminals, file access and sync
Networktor, exposed-services, mediaTor control, service exposure, media controls
Securitysecurity, vaultSafe Browsing database, password vault
Systemhealth, sys/gpu, wsLiveness, GPU information, the event WebSocket

This is an internal API for the client and may change between releases. A stable public API reference is not published yet.

The client sends browsing traffic through the proxy so that one place can apply blocking and routing.

  • Local connections (from 127.0.0.1) need no credentials.
  • Remote connections must authenticate with username kaba and a signed token as the password. A username of kaba:<pane-id> ties the connection to one pane, which is how per-pane Tor works.
  • Requests are checked against the ad-block lists and the Safe Browsing database.
  • If an exit node is selected (Settings → Devices → Use as exit), traffic is tunneled to that peer over kaba/exit/v1 and leaves from its network.
Terminal window
curl --socks5-hostname localhost:28833 https://example.com

Tor support is built in (no separate Tor install). It can be turned on for all browsing, for one pane, or automatically for chosen domains. Exposed services can also be published as onion services. In the client: Settings → Security & Privacy → Tor routing, or the pane menu.

A node can publish a local host:port to the mesh under a name, either private (reachable with an access token) or public (announced to the public directory and searchable). Protocols are http, https and tcp. In the client this is Hippocampus → Services → Expose. See protocols.

  • Terminals. Spawns shells for terminal panes, locally or for a peer, and records sessions as memories with secrets redacted.
  • Sandbox. Runs tool-loop commands in containers. See security.
  • Vault. Stores saved logins and passkeys, or delegates to pass or 1Password.
  • Voice. Speech-to-text and text-to-speech models, provisioned at start when built with voice support.
  • Media. Reads and controls media players on the machine for the header media controls.

There are two ways to keep the server running. Use one, not both.

Terminal window
kabactl service start
kabactl service status
kabactl service stop

start detaches the server and writes kabactl-service.pid and kabactl-service.log in the storage directory. stop sends SIGTERM and waits before forcing the process down.

Terminal window
kabactl service install --systemd # per-user unit
sudo kabactl service install --system --systemd # system-wide unit
Per-userSystem-wide
Binary<storage>/bin/kabactl, symlinked into ~/.local/bin/usr/local/bin/kabactl
Unit~/.config/systemd/user/kabactl.service/etc/systemd/system/kabactl.service
Runs asyoua dedicated kaba user, created if missing
Datayour storage directory/var/lib/kaba
Logsjournalctl --user -u kabactljournalctl -u kabactl

Both units run kabactl server in the foreground so systemd supervises the process, restart on failure with a 5 second delay, and give up after 10 restarts in 5 minutes.

The system unit is hardened: no new privileges, read-only system directories, private /tmp and devices, no access to home directories, only IPv4, IPv6 and Unix sockets, and write access only to /var/lib/kaba.

Terminal window
systemctl --user status kabactl
systemctl --user restart kabactl

To remove everything install created:

Terminal window
kabactl service uninstall # per-user
sudo kabactl service uninstall --system

service install copies the binary to the managed location and prints the line to add to your PATH. There is no launchd or Windows service integration in kabactl 0.87; use kabactl service start, or let the client manage the engine (Settings → Run In Background).

WhatWhere
Server log<storage>/kabactl-server.log (rotating)
Daemon output<storage>/kabactl-service.log
More network detailstart with KABA_DEBUG=1
Crash and memory bundlestart with --trace or KABA_TRACE=1; see <storage>/perf/CURRENT
Health checkkabactl doctor

A --trace bundle contains the environment, allocator statistics, memory samples, an event log and any panics. It is packed into perf/<run>.tgz on shutdown so you can attach one file to a bug report.