Show HN: Skadi – self-hosted Trello alternative with a 10 second installation
getskadi.com
getskadi.com
However I chose not run this because it's a compiled binary and the source is nowhere to be seen. I choose not to trust a binary that I found on a forum from the internets. :)
I'm much more likely to try something like Wekan and evaluate it seriously just because I know that me and my team can build whatever features we need and we can trust the code because we can read it.
So does the business model work in the environment you're in? Eg giving the source to people who pay for it? Maybe it would be better to do something like eg nginx or cassandra or gitlab - have an OSS version and some premium version or at least some support contract with gold support or similar. It's a tough space to be fighting in with mature products and free products. How can you separate yourself from these other guys in a way that will still make you money? If it's just a self hosted trello alternative, that space may already be cloudy with Wekan. You need some differentiating quality to sit beside trello and wekan I think.
You are right, asking people to run the binary on their servers is not a good idea.
I guess I have no other choice but to provide the source code to the clients, just like Atlassian does.
I just did some research, and it looks like GitHub are protecting their source code:
http://stackoverflow.com/questions/13185814/how-github-enter...
How do they get away with this?
Trust is critical. Almost all of us Linux users run at least a few prepackaged binaries on our systems. But they come from trustworthy sources such as big companies like Github. These proprietary binaries are usually vetted by security researchers as well to detect any malicious behaviour.
Additionally, I'd recommend posting SHA checksums and offering a more traditional "Download" button as an alternative to the one-liner.
TLDR: You're asking people to take a risk on a new project, without any indiciation of who's behind it or why they should trust you.
Speak for yourself. I explicitly have removed all proprietary software from my machine. The whole "vetted by security researchers" is such a vague metric with mixed results. One researcher will find 30 bugs while another will find 5 in the same time.
> Additionally, I'd recommend posting SHA checksums and offering a more traditional "Download" button as an alternative to the one-liner.
> TLDR: You're asking people to take a risk on a new project, without any indiciation of who's behind it or why they should trust you.
Which is why he should just release the source. Then trust isn't a factor. I don't trust random people on the internet. And no, I don't trust GitHub or whoever you want to pick.
Video drivers?
BIOS?
These are possible, but every individual's weighting of the difficult trade-offs may be different.
I wish RISC-V and free hardware design FPGAs would be a thing soon so I can get rid of the proprietary Intel microcode. Not sure what I'll do about video then though.
So you don't use a desktop operating system? Or smartphone?
But you might have different views, and that's fine. I just wanted to make clear that trusting a proprietary software vendor is something that I find to be extremely foolish (they will always screw you over eventually).
From the webpage:
Skadi is free for projects with less than 3 users, public projects hosted on our servers, and non-profit organizations. For everyone else it's only $1/month per user.
Some companies have information security policies that certain types of data cannot be stored on (or sent through) servers in other countries. It's not about nationalism. It's about having it all under one legal jurisdiction (or limited set of jurisdictions). Having something like this self-hosted would be a great way to solve that problem vs using cloud services, (if it was verified not to phone home, leak data, update itself without permission, or allow remote access - hence why people want to see the source).
Is there a reason you don't want to do that? It clearly works. Release your code under the BSD or GPL licenses and provide it to your customers. If you did that, I'd be happy to pay for software like that. But for me, free (as in freedom) software is a requirement for anything I'm going to run on my machine.
They have a unique offering and they are a trusted brand. If you have neither, you are relying on blind faith. For the vast majority of business to consumer products, this isn't a problem. However, in your case, you have a product that requires the installer to be somewhat knowledgeable, hence the scrutiny.
The easiest way to gain credibility is to have an incumbent vouch for you. For example, if Trello were to say, if you want to host your own Trello like solution, there is no better option than X, then most people wouldn't really care about installing a binary.
Since your solution isn't novel enough for people to take that leap of faith, you really have no other choice but to make the source available or try to align yourself with an established incumbent.
For example, create your product so it has tight integration with an Atlassian product and sell your solution through Atlasisan's marketplace. Or create a tight integration with GitHub and try to get it listed as an integration partner. And so forth.
I'd like to get your opinion on this project. It's still in beta and under heavy development. Some of the basic features like voting and checklists are missing, but they will be implemented by the end of February.
There are so many Kanban boards out there. Why create another?
They key advantage of Skadi is easy installation on your own server. You can literally do it in 10 seconds. It's a binary file with zero dependencies. It uses a built in web server and a LevelDB database. Even the static files are embedded in the binary, which allows easier updates.
So the primary audience is companies who would like to use Trello but can't store sensitive data on outside servers or simply prefer a self-hosted solution.
It also does some things better than Trello. For example, it is extremely light and fast and can handle a lot more cards without freezing. Search is always instant, unlike in Trello.
Of course, it supports JSON imports from Trello.
Thanks for your time.
By the way, the entire "sensitive data" argument is not valid, since you're distributing a compiled binary. Do you really trust compiled binaries for sensitive data? I won't until I'll be able to review the source code.
As a hosting co we'd rather have self-hosted than SaaS, but we'll use (& pay for) free software over both of those options if at all possible.
However the set of features will grow. I plan to implement functionality similar to Hackpad/Confluence, time management, and even source code management, so that companies have everything in one place for a very affordable price.
It's not clear if the limit of 3 users apply to the self hosted server. Maybe you should clarify this point on your site.
I agree with you, running closed source software does not give the company any guarantees.
It looks like GitHub Enterprise is protected:
http://stackoverflow.com/questions/13185814/how-github-enter...
How do they get away with this?
I’m also not certain about the canonical way to update Docker containers. I feel like we miss a standard “pod” (ie set of containers) orchestration tool (as docker-compose doesn’t really matches production requirements).
https://www.rosehosting.com/blog/install-wekan-on-an-ubuntu-...
Are there plans to release the source code, or is there a documented API somewhere?
The source will be released to companies running Skadi on their own servers, just like JIRA.
I've been using this in a professional context for the last four months or so. It's been pretty good. As well as a kanboard it supports a calendar view, task list view (similar to ToDoist) and a very basic Gantt view (no dependency tracking).
[1] http://kanboard.net/documentation/ldap-authentication
At least Skadi doesn't require root access.
I will definitely be adding more information and researching other ways of distributing executables safely.
* show a shadow under the card when dragging that snaps to the list, this means I can accurately see where the card is dropped because sometimes it doesn't go where I want it.
* making a list would be nicer if it didn't have to refresh the page
* also there are some glitches with moving the cards where it indents them or overlaps them, it's hard to explain (I appreciate that this is beta though so you are probably aware of this)
But that's my 2 pence, I'll definitely consider using this once it's more polished on my server :)
Backups are run automatically and saved in the "bkups" directory (next to the executable).
Try Brightpod for project management - recurring tasks, focus mode, cal, time tracking & more - bit.ly/17GZqhe