Skip to content

Daemon API

A Unix socket. Never a port.

Controlling microVMs is equivalent to root on their host. That is why the daemon only listens on /run/kling.sock (Linux) or ~/Library/Application Support/kindling/kling.sock (macOS). Remotely, over SSH.

Terminal window
curl --unix-socket /run/kling.sock http://kling/info

GET /info returns the version, the backend, the architecture, the disk copy mode and the capabilities. An extension looks there for what it needs instead of guessing from the version.

Route What it does
POST /machines creates and boots (an image, or from a snapshot)
POST /machines/{ref}/freeze · /thaw lifecycle
POST /machines/{ref}/exec run inside (with allow_exec)
POST /machines/{ref}/credentials keys for the credential proxy
POST /machines/{ref}/guest forwards an HTTP request to the guest
POST /graphs creates a graph
GET /events NDJSON event stream
GET /metrics Prometheus

Errors come back as {"message": "..."}. 507 means “does not fit in memory”: the scheduler uses it to evict and retry.

A kling-<name> executable that answers --kling-manifest and talks to the daemon only through this API. In Go: pkg/plugin, pkg/api, pkg/config.