I know this is beginning to become off-topic, but why? Presumably, if you're using a flag that has to be run from the command-line, you're either doing it on purpose or using hardware you don't own (and a keylogger is a much greater risk than anything else at that point)
In practice, it's not a problem for me, because the presence or absence of my usual row of extension icons and profile photo is enough of a clue.
But I could see where someone who doesn't normally sign into Chrome, or who doesn't have very many extensions in their normal Chrome profile, could have trouble distinguishing it from their a profile. The windows will tend to look pretty similar.
The problem I see is that not everyone takes the same precautions. And plenty of developers accumulate these sort of tweaks and hacks in their daily driver without realizing or remembering that they've crippled their own security posture.
From a UX perspective, my preference is to make it clear when normal security mechanisms are disabled.
If you're not a lone wolf, or working in the SV bubble, the IT and security departments are going to tell you to go pound sand.
CORS is allowed while running locally and then set while running in development and finally production.
I don't buy your comment at all.
I agree with you that fixing the headers (via a proxy in this case) is the right solution. I'm just not able to prioritize right now.
Beyond that, there are always going to be occasions where developers, security analysts, and testers need to bypass default security enforcement. I'd like to see every browser provide a way to make these adjustments for a one-off session (e.g., via a command-line switch). It's an efficient solution that I can offer when I come across a nasty hack living permanently in a developer's web configuration.
The cleanest solution is to extend the dev pipeline with a proxy for localstack. It won't take me long to knock that out, but it's not something I can prioritize at the moment.
This is what we do while running docker for local development with node.
Then you can change the theme for that profile which makes it obvious which instance you're using.