Privacy & safety
What kabanos stores, where secrets live, what counts as a read, and how production and read-only connections protect your clusters.
No account, no telemetry
kabanos has no account, no analytics, no crash reporting and no update check. The only network traffic is the requests you send to your clusters — directly, or through the SSH tunnel or proxy you configure. (AWS SigV4 connections use the standard AWS credential chain, which may contact AWS for SSO or instance roles.)
What is stored, and where
Everything lives in ~/Library/Application Support/kabanos/:
kabanos.db— a local SQLite database with your connections, query library, workspace tabs, request history, environments, routines and their runs.- Small settings files for the theme and window state.
Secrets — connection passwords, API keys, SSH passwords and key passphrases, and secret environment variables — are encrypted with a key that lives in the macOS Keychain (the kabanos Safe Storage item). If the Keychain isn’t available, kabanos refuses to store them rather than store them in plain text. Secrets never reach the app’s window: the interface only knows whether a password is stored.
Never stored at all:
- AWS credentials — they come from your AWS configuration each time.
- Passwords typed inside a connection URL — they’re split out into the Keychain.
- Credentials in imported cURL commands.
- The values of
{{variables}}— history keeps the placeholders.
Credentials are also never included in Copy as cURL, connection exports or document exports.
History keeps the newest 20,000 requests. Responses are kept only for saved workspace blocks — the last five per block, up to 512 KB each. Clear it any time in Settings → Request history.
What counts as a read
Every request is classified before it is sent:
- Read — every
GETandHEAD, plus searches and other read-only calls sent withPOST:_search,_msearch,_count,_mget,_field_caps,_validate/query,_explain,_analyze,_termvectors,_terms_enum,_knn_search,_async_search, point-in-time and scroll calls, SQL, ES|QL (_query), PPL,_has_privileges, template and ingest simulate calls. Closing a point in time or a scroll is a read too. - Dangerous — any other
DELETE(with an extra warning for wildcards and_all),_delete_by_query,_update_by_query, closing indices, shrink / split / clone, force merge, cluster settings, security changes, alias changes, snapshot restores, and_bulkrequests that contain deletes. - Write — everything else. Unknown endpoints are treated as writes.
Production connections
Mark a connection Production and every request that isn’t a read shows a native macOS dialog before anything is sent: the method and path, the connection name and what the request does. Dangerous requests get a Run anyway button; Cancel is the default. Declined requests are never sent.
This check happens in the app’s main process, so it covers everything: the workspace, the Index view, the explorer’s actions, stack management and every step of a routine. Deleting or emptying an index additionally asks you to type its name.
Read-only connections
Turn on Read-only mode and kabanos blocks every request that isn’t a read — it never reaches the cluster. The tab shows an RO badge.
Combine them: a read-only production connection is a safe way to give yourself a look-but-don’t-touch view of a live cluster.
Built safely
The app’s window runs sandboxed and can only reach the cluster through a small, validated interface; it loads no remote code, fonts or scripts. Routine expressions run in a JSONata sandbox, and kabanos never evaluates code you type.