Self-hosted FOSS AI companion: orchestrator, tasks on your own PCs, local models taught by a stronger one.
  • TypeScript 43.3%
  • Rust 41.2%
  • CSS 13.7%
  • JavaScript 0.9%
  • HTML 0.5%
  • Other 0.4%
Find a file
Kees Rodriguez 712539ab45 Web: never show demo data on a real server; retry, then say it is unreachable
The app fell back to the mock API whenever the first /api/status call
failed (for example while the server restarted), so signed-in users saw
made-up chats and machine stats. Demo mode is now only for file:// or
?demo, and is labelled.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 06:00:37 +02:00
docs Screenshots, banner and README gallery 2026-10-01 03:32:54 +00:00
server OIDC: allow_new = ["*"] gives every user the provider signs in their own account 2026-10-01 05:55:32 +02:00
web Web: never show demo data on a real server; retry, then say it is unreachable 2026-10-01 06:00:37 +02:00
.dockerignore Milestone 1: Rust server with sign-in, streaming chat and call log; web app uses it 2026-10-01 02:45:30 +00:00
.env.example Milestone 1: Rust server with sign-in, streaming chat and call log; web app uses it 2026-10-01 02:45:30 +00:00
.gitignore Milestone 1: Rust server with sign-in, streaming chat and call log; web app uses it 2026-10-01 02:45:30 +00:00
docker-compose.yml Milestone 1: Rust server with sign-in, streaming chat and call log; web app uses it 2026-10-01 02:45:30 +00:00
Dockerfile Milestone 1: Rust server with sign-in, streaming chat and call log; web app uses it 2026-10-01 02:45:30 +00:00
README.md Screenshots, banner and README gallery 2026-10-01 03:32:54 +00:00

Kreative Kompanion: your AI, your machines

Kreative Kompanion

A self-hosted, FOSS "Claude-like" companion: one orchestrator you talk to per project, tasks that run on your own computers, local models doing the work and a stronger model reviewing and teaching them. See docs/architecture.md.

Screenshots

Sign-in with single sign-on Connect to a server
Sign-in with single sign-on (Keycloak or any OIDC provider) Connect by link or find the server on your network
Dashboard Task timeline with call inspector
Projects, the orchestrator chat and running tasks Every model call: prompt, context, answer, tokens, energy
Machines Models and roles
CPU, RAM, GPU load and wattage of every machine Any model in any role: local, DeepSeek, Claude
Light theme Phone
Kompas Day theme On a phone

Screens other than sign-in show demo data. The banner source is docs/branding/banner.html; docs/branding/render-banner.mjs renders it.

Status

Milestone 1 done, milestone 2 in progress:

  • server/ (Rust, axum, SQLite): sign-in with password or OIDC single sign-on, separate data per user, chats, streaming answers from any OpenAI-compatible or Anthropic model, model roles, a full log of every model call (GET /api/calls), tasks, and kompanion-server import to bring projects and tasks in from another planner.
  • web/ (vanilla TypeScript): talks to the server when served by it, and falls back to a demo with example data when opened on its own.
  • Not yet: runners and machines (milestone 2), task execution (milestone 3).

Run it

cp server/kompanion.example.toml kompanion.toml   # edit providers and roles
cp .env.example .env                              # API keys, if any
docker compose up -d
docker compose logs kompanion   # shows the one-time setup code

Then open the app, enter the setup code and create your account.

For development: cd web && npm run build, then cd server && KOMPANION_CONFIG=../kompanion.toml cargo run (set web_dir = "../web/dist" and, for plain http on localhost only, secure_cookies = false).

Server security

  • No open endpoints except status, setup and sign-in. The first account needs a one-time setup code printed in the server log.
  • Session cookie: random token (stored only as a SHA-256 hash), HttpOnly, Secure, SameSite=Strict. Passwords hashed with Argon2id; sign-in throttled.
  • State-changing requests need an X-Kompanion: 1 header and an allowed Origin.
  • Strict Content-Security-Policy with Trusted Types, nosniff, no-referrer.
  • Provider URLs come only from the admin's config file (no user-supplied URLs, so no SSRF through the API). API keys come from environment variables and are never stored or logged.
  • The container runs as a non-root user with a read-only filesystem and no capabilities.

Web app

Vanilla TypeScript, no framework. Built with esbuild; two small runtime dependencies: marked (markdown) and DOMPurify (sanitising model output).

cd web
npm install
npm run dev        # http://localhost:5173
npm run typecheck
npm run build      # dist/
node build.mjs --single   # dist/preview.html, one self-contained file

Layout of web/src:

  • api/ types shared with the server, the KompanionApi interface, and the mock server
  • core/ small building blocks: escaped templates (html), sanitised markdown, a store that batches updates per animation frame, keyed list updates
  • views/ one file per screen part: connect, sidebar, conversation, tasks, machines, settings

Security rules the code follows: model text is never put into the page as raw HTML (marked + DOMPurify, links forced to http(s) and noopener), templates escape every value, a strict CSP with Trusted Types is set in index.html, and approvals show the exact command, folder, machine and network targets.