Sandstorm, Tempest, and the Future
sandstorm.org
sandstorm.org
For my part, I am no longer heavily involved in the community project -- mostly because I just don't have any free time. :/ But I trust Jake and co.
> Unfortunately, as we hope to continue to support Sandstorm long-term, we’ve had an increasingly challenging problem with the legacy MongoDB database underneath, as Meteor has dropped support for the version we use. Ensuring a seamless migration on end-user servers has proven to be a challenging problem. Dependency upgrades are not fun and this has become a fairly unpleasant project to undertake for unpaid open source contributors.
> Over the past few weeks, we have spoken to a number of potential outside parties about taking on this project and building a migration so that we can update the databases of existing Sandstorm servers and allow us to continue moving forward.
> We are looking to raise the funding for this project through our OpenCollective.
Please take a look at the long list of supported apps [1], which are basically one click install.
Sandstorm is an excellent project. I sort of consider it the platonic ideal of self-hosting software. It does everything the "right" way, especially with respect to security, but ultimately isn't compatible enough with the broader ecosystem for general adoption.
I've been wondering if a lot of self-hosting platforms are targeting the wrong level of scale. On one extreme you have single user instances (SUI hosting). The other extreme is centralized platforms like Google. I used to think the ideal for most people is the "nerdy cousin" approach, where each family has someone capable of running something like Sandstorm or Nextcloud. The problem is that I would much rather trust Google with my private data than anyone close to me. There's so much more incentive for them to go looking through my stuff. This makes me think SUI might be the way to go. Or maybe large federated providers, similar to what we have for email.
Mailinabox [1] almost does it. They target Ubuntu stable, and upgrades are mostly silent. But they needed user intervention when Ubuntu had to be upgraded from 18.10 to 22.04, which was quite challenging.
If sandstorm can get there, then putting it into a RPi box is simple. What's difficult is helping the general public understand the importance of protecting their data, so such a product has a reasonable market.
There are probably a couple interesting approaches. One might be to have users point some other domain at a Sandstorm API endpoint, end-running around Sandstorm's own domain, which might work in scenarios remote servers are only fetching. But another idea would be to sort of "special-case" an ActivityPub server deeply integrated into Tempest, and instead of letting a user install "Mastodon", they are installing a custom frontend that creates a user account on the server's ActivityPub.
Because Sandstorm was intended to work as a large scale hosting service, it avoided pretty much any design which could let one user know about another user on the server, but Tempest may end up making choices more suited to smaller deployments where we assume a Tempest server hosts either one organization or one family or one group of friends, etc.
One idea I think is really neat though is decentralized backup solutions, where an e2e scheme would work really well: Your home server could have a key to store encrypted versions on someone else's server (and vice versa for theirs). Losing a key would still be problematic, but only in the case you also have lost your primary server.
I think Sandstorm as a startup was, if anything, just too early. (I remember people questioning why anyone wouldn't trust Google back when it started!) I suspect in several years everything comparable that isn't Sandstorm will look a lot more like Sandstorm than Docker and such.
IMO we need a nice simple OAuth2-based protocol for setting up something like Cloudflare tunnels.
With the support from a business case, things could get easier for the hobbyists. This is just constructive criticism. I sincerely think this is the coolest open source project around.
The Collections app is currently the best way to share "a group of permissions", which you can in-turn share with a bunch of users, but there's definitely a missing feature there in terms of being able to share to groups of users or especially share some grains by default to new users.
For Tempest, Ian and I had discussed doing a lot more with "keyrings" of capabilities, and I absolutely would like to be able to do that someday.
Sandstorm is a self-hostable web productivity suite.But I really don't understand what the sandstorm runtime is bringing over just having a docker container. It's trying to reinvent docker, which seems weirdly out of scope for the problems it's trying to solve. Or even if docker isn't suitable you can still use OCI-compatible container images instead of a custom format?
https://sandstorm.io/news/2014-08-19-why-not-run-docker-apps
It sounds like "we do use OCI-compatible images, but we wrap them in our own filetype". Which I suppose is fine.
Source: https://sandstorm.org/
MongoDB is perfectly fine at what it's designed for: Enterprise data infrastructure. But while needing a sysadmin or a support call may be no big deal for an enterprise platform, for an open source project without a customer support team or any product telemetry, the risk of shipping a less than perfect database upgrade is extreme.
Tempest, or course, uses SQLite, which is far more suited to the role here with ten years of hindsight.
This old: https://github.com/sandstorm-io/sandstorm-website/pull/19
In all seriousness, I just learned about Sandstorm and think it could be a great fit for a local co-op I’m building. It’s a shame about the startup, but I hope we’ll get a chance to support the open collective.