Show HN: Kloudi – Locally-hosted universal CLI
kloudi.tech
kloudi.tech
Plus, what's up with only supporting running the containers on MacOS? That's really, really bizarre.
Basically, there are a number of signals here that prevent me from trusting you enough to even consider trying this out, even though it's quite possibly solving an interesting problem.
Answering some of the questions you have asked.
- We are a small 2 people team so our approach has been to first get Kloudi out in the open and then figure out what parts of the code we want to open source and what licensing we need to have around that. But irrespectively if you find any security concerns, please feel free to reach out on nitish@kloudi.tech and we'll try to get it sorted as soon as we can. Also keep an eye out on https://www.github.com/kloudi-tech/ for more updates on this.
- Adding to your point on security, we keep all the keys to the tools that you connect with on your local system stored in Mongo hence a container for that. We use a Redis cache to speed up the response time for API requests hence another container for that.
- Documentation are WIP but meanwhile you can read some of the stuff that we have written on https://kloudi.substack.com/ It's more around our journey of building Kloudi, the problem and how we are planning to solve for it. Like I said before we are a very small team and documentations are WIP.
- Finally, we are only supporting macOS as of now because our electron based app currently runs only on this platform. We plan to gradually release support for other platforms eventually but till then we it is macOS.
jart's finding (in another comment below) that you're using fullstory in your electron app is probably the most damning; at this point I wouldn't ever consider even trying your product. Putting a keylogger in an app like this is evidence of careless engineering at best, and malicious intent at worst. Either one is disqualifying for a tool that would have access to so much of my critical infrastructure.
We have built it for developers and understand the criticality of the data handled by the tools used by developers. We in no way want to give off an impression of mistrust or carelessness at the very least, but this sentiment seems to be resonating through out the comments section and as an immediate fix we have updated our app to have no fullstory in it .
Would it be possible for you help us pioneer these concerns. We are here to listen and work on it and would love to chat on our discord channel or over email. Thank you in advance!
That's exactly the point. You don't want to give off that impression. Nobody does. That's not some noble goal.
I wrote an article telling how you can do that for Mac, Windows, and Linux almost a year ago: https://henvic.dev/posts/cs-security/
Kloudi was born as a solution to the problems faced by us while running our previous startup which was a managed freelancer marketplace. While freelancing and handling development for a lot of startups at a given time we realised that any other engineering team uses on an avg 10-15 tools to monitor various aspects of a developers workflow however there is still a lot of staggered information that any developer spends time knitting together. This continued problem was what became the trigger point for building Kloudi. We currently support tools like Sentry, Rollbar, Datadog, Github Issues and our planning to provide support for a bunch of dev-tools in the future.
Some of the key things about Kloudi is that it is locally hosted on your systems. Which means all the keys and data reside on your system. Making it 100% secure and extremely fast!
We are still in our early days of building the product and would love for you all to take it out for a spin and give your feedback. Cheers!
Your docker image (kloudi/api) has a whole bunch of credentials in plaintext inside it. I am not going to check whether they're valid or not, but they certainly look real.
It should be clear from looking at your website that you are not free software. It's not clear at all.
(Also: There seems to be some sort of scroll hijacking which makes the performance of the website rather slow)
In our upcoming release tonight we plan to provide this is an optional feature in case you want to opt out of it.
https://www.fastcompany.com/90152433/the-popular-web-design-...
When your entire workflow is CLI based, having access to your tools from the CLI is really valuable. Unforutunately, I'd wager that the people that this applies to are the first to write their own wrappers for their tools to fit their exact workflows.
This would have been interesting for me, if I hadn't already gone through the effort of writing a bunch of jira/confluence/bitbucket/jenkins CLI wrappers.
Removing 'background-attachment: fixed' from .homepage-module--homePage--XP-yA fixes it