Huh, is this tractable?
Huh, is this tractable?
For the syncserver itself, where all the data is synced and stored, you just need tokenserver+syncstorage, plus a database backend of choice. Easy-peasy, you can set it up trivially in minutes if you're used to spin up docker containers and have a database server. Loads of people do this.
However, you still need a way to authenticate. Most people just piggyback on Mozilla's servers for this. This means some metadata (not the synced data itself, mind you, but still) will be shared with Mozilla and a surprising number of third-parties.
To get the last meter and be fully self-reliant you need to go down quite the rabbit hole and set up the fxa stack. It involves several interconnected microservices and a handful of separate mysql databases. I managed to but it took a couple of days to dig through the sources and figure out exactly what is necessary and disable all the third-party integrations. The pieces are all there and it's all done in the open but it's clearly built with the mindset of a cloud-based startup.
https://github.com/mozilla/fxa
Once up and running it has been hands off, not much maintenance at all. Happy I did it but unless you like doing this kind of stuff as a challenge, I'd probably recommend using some alternative extension, until it becomes more approachable.
If you take it on, there are helpful people in the #fxa:mozilla.org Matrix room. More activity there, and self-hosting related discussion/issues/PRs in the fxa github repo, might push them to put in more effort to make it easier to self-host the stack and bring/keep docs up to date.
Hoping to do a proper write-up soon to make it more approachable for others, once things cool down a bit at work.
#fxa is almost a ghost town as of now. The few GH issues relating to this are not getting any interactions.
We can't expect them to prioritize something nobody's asking for or using. I think there're more of us than they realize.
My opinion is "yes" - the source is available and runs as a docker container, the client setup is pretty trivial (on Android you'll need Fennec or another alternate build of Firefox to get at the settings). I'm aware of one user group running a shared instance and it seems to work as advertised.
So I click your link, but the repo says
> Note that this repository is no longer being maintained. Use this at your own risk, and with the understanding that it is not being maintained, work is being done on its replacement, and that no support or assistance will be offered.
So I guess I'll have to wait a little more...
So basically they stopped running the older version themselves but don't consider the newer version production-ready yet. What a mess.
Though when I log in on a mobile device I don't even have to enter the password so I kinda doubt it passes the mud puddle test.
But at least the info is not just stored in the clear ready for datamining like Chrome or Edge do. Though Chrome has very recently added e2e for its passwords but not for the bookmarks.
I didn't look into it personally but a few years ago I tasked an employee with setting up local instance of this for a very privacy conscious small business and after a few days of looking at it he said that it would be too much work to get the released material into a state that end users could make use of.
This could have changed since then however.
Yes. See my comment above. Nothing that a persistent admin can't pull off. I wouldn't blame your coworker for giving up, though.