Local management
Local management. Reviewed changes. Recoverable operations.
Qubicl 0.5 brings your computers into a local management dashboard. Create and configure computers, review updates and backups, and follow operations through completion or recovery. Your agents keep their durable Linux computers, and management stays on hardware you control.
Your computers, together
A dashboard for the owner.
Manage setup, resources, lifecycle, tools, skills, network policy, and scoped credentials in your browser. Open a desktop viewer or published preview in a separate tab. The interface adapts to phones and supports light and dark appearance.
Review before applying
Changes start with an expiring plan showing their effects. Disruptive operations require interruption approval; sensitive changes require your password again. Plans are rechecked against the current computer state before execution.
Keep a record
Operation history survives helper restarts. Closing the browser does not cancel an accepted operation. Return to see its result or review the recovery it needs.
Manage durable homes
Create manual backups, checkpoints, and clones. Backups can capture a stopped computer or temporarily pause a running one. Restore a backup into a new computer and review exact archives before pruning.
Recover locally
The native host helper provides an authenticated recovery page even when Docker, the gateway, or the dashboard frontend is unavailable. It resumes recorded work only after validating the affected resources.
Open the dashboard
On native Linux x64 or Apple Silicon macOS, install the CLI and run these commands as your normal user. Enable prompts for an administrator password in the terminal. New installations can complete setup in the dashboard; existing installations must review the migration below.
$ qubicl dashboard enable $ qubicl dashboard open
The optional login service uses systemd on Linux or a LaunchAgent on macOS. A foreground mode is also available. Qubicl does not start Docker or provide pre-login service operation. Read the dashboard setup guide.
Private administration
Management authority stays on the host.
The native helper holds administrative authority. The dashboard frontend serves verified static assets; it receives no Docker socket, host mounts, passwords, credential values, or TLS private keys.
Protected sessions
Passwords use bounded scrypt hashing. Sessions expire, sensitive changes require reauthentication, and requests enforce Host, Origin, CSRF, and rate checks. Local authorization stays in browser memory; private HTTPS uses Secure, HttpOnly cookies.
Separate access paths
Private dashboard administration has its own identity and access policy. Remote agent, desktop-viewer, and workload-preview traffic use separately configured gateway TLS. Administrative secrets stay out of workloads.
Manage over private HTTPS.
Enable remote administration only on a private network interface with a trusted certificate, a distinct administrator hostname, and permitted client networks. You provide DNS, certificates, routing, and firewall policy. There is no public dashboard mode or automatic tunnel. Invalid certificates or unavailable trusted frontend assets close remote administration.
A computer and its connected clients still share one identity and state. The dashboard is for one owner, without multi-user roles. Use separate computers for separate trust, and supervise workloads: Docker containers are not VM isolation for deliberately hostile code.
Lifecycle and recovery
Interrupted work gets an explicit next step.
Start, stop, restart, backup, configuration, and upgrade operations retain the identities and progress needed for recovery. Qubicl checks the exact affected containers before continuing and leaves ambiguous results for review.
Safer backups
Captures track the containers they pause and publish only complete, verified archives. Recovery retains its journal if unpausing leaves an unsafe state. Retention follows the original computer identity, even after a rename.
Resumable upgrades
Upgrade-all records approved image targets and completed checkpoints. Recovery requires matching catalog, platform, state, and runtime identities instead of replaying arbitrary requests.
Correct resource handling
Diagnostics and orphan cleanup recognize the dashboard and its asset network. Network policy changes detach the gateway before replacing disposable networks, and lifecycle actions reject inconsistent runtime groups.
More reliable daily work
Preview handoffs use isolated origins, completed-process cleanup preserves unrelated requests, and freshly installed skills correctly report unchanged catalog integrity.
Review recorded recovery
Use the dashboard recovery action or inspect the host recovery workflow. Keep pending journals and resolve the reported prerequisite before continuing.
$ qubicl recoverBefore upgrading
Back up, migrate, then update the computers.
State format 4 requires your approval.
Protect a complete copy of the Qubicl state root and durable computer homes before continuing. A home-only backup does not preserve all installation settings, credentials, or dashboard state.
Install the current 0.5 CLI, run setup to review the state migration, then review the coordinated runtime upgrade. Updating the CLI alone does not update existing computer images.
Upgrade to the 0.5 release line
Run as the installation owner. Setup requests explicit migration confirmation and saves a protected, checksummed copy of the prior state. Review the images, resource estimates, interruptions, and preserved settings before approving upgrade-all.
$ npm install -g qubicl-cli@0.5 $ qubicl setup $ qubicl upgrade --all
What stays
Computer identities, durable homes, Chromium profiles, tokens, resources, policies, and prior running or stopped intent are preserved. Migration itself does not start containers. The runtime upgrade replaces verified disposable components.
Before considering a downgrade
Older CLIs refuse state format 4. Downgrading requires a compatible CLI and restoration of the complete protected pre-migration state. Restoring only one computer home is insufficient.
Refresh clients that cache tool discovery. The dashboard does not update the host CLI itself; install the newer CLI before reviewing its bundled image catalog. Security maintenance follows the latest stable minor release line. Read the persistence and recovery guide.
Clients and platforms
The same connections. Clear platform boundaries.
Existing MCP, OpenAPI, Open Terminal, and Open WebUI connection methods remain available. Client paths cover Codex, Claude Code, Claude Desktop, OpenCode, OpenClaw, Hermes Agent, Open WebUI, Cursor, and VS Code.
| Host | Core Qubicl | Dashboard |
|---|---|---|
| Native Linux x64 | Supported | Available |
| Apple Silicon macOS with Docker Desktop | Supported | Available |
| Windows 11 x64, Ubuntu 24.04 on WSL 2, Docker Desktop | Supported | Not available |
| Linux ARM64, Intel macOS, Windows on ARM, other WSL 2 distributions | Best effort | Not available |
| Native Windows or WSL 1 | Unsupported | Not available |
Directly tested host classifications record the v0.1 baseline. The initial 0.5 release uses Linux x64 for general candidate testing, with separate dashboard evidence for native Linux x64, Apple Silicon macOS, and physical iPhone Safari. That does not imply a complete new general macOS or Windows/WSL test run. Physical reboot evidence belongs to the broader supported release tier. See the platform policy.
Requirements remain Node.js 22.14+ or 24.x, Docker Engine 24+ or Docker Desktop 4.29+, and Compose 2.24+. On Windows, run the CLI inside Ubuntu and keep state and homes under the WSL Linux /home filesystem. All computer presets run Linux.
Know the scope
What to expect before enabling it.
- Manual home backups. Dashboard archives are unencrypted and can contain cookies, sessions, credentials, and personal files. Encrypted backups remain CLI-only. Scheduled backups and complete-installation exports are not included.
- Management, not a terminal. Process views show bounded identifiers and lifecycle metadata, not commands, working directories, output, or file contents. Credential values and computer tokens cannot be retrieved from the dashboard.
- Local services need the host. Login services require a logged-in owner and an available Docker engine for computer workloads. Windows/WSL dashboard installation and pre-login operation are outside this release.
- Private remote access needs configuration. You manage certificates, DNS, routing, and firewall rules. Administrator and gateway access need distinct identities and separate configuration.
- One owner, shared computers. There is no multi-user RBAC or automatic isolation between chats and clients sharing a computer. Open Terminal continues to provide bounded non-PTY processes rather than a full interactive terminal or notebook.
- Dashboard host support is narrower. Core Qubicl supports its documented Windows 11 WSL 2 path, but the dashboard is available only on native Linux x64 and Apple Silicon macOS in this release.
Release resources
Install, explore, and verify.
The four computer presets remain available. The release also includes an isolated dashboard image with verified assets. Published candidate records, signatures, and scan evidence identify the shipped artifacts and the checks retained for them.