Privacy & safety

What kabanos stores, where secrets live, what counts as a read, and how production and read-only connections protect your clusters.

No account, no telemetry

kabanos has no account, no analytics, no crash reporting and no update check. The only network traffic is the requests you send to your clusters — directly, or through the SSH tunnel or proxy you configure. (AWS SigV4 connections use the standard AWS credential chain, which may contact AWS for SSO or instance roles.)

What is stored, and where

Everything lives in ~/Library/Application Support/kabanos/:

  • kabanos.db — a local SQLite database with your connections, query library, workspace tabs, request history, environments, routines and their runs.
  • Small settings files for the theme and window state.

Secrets — connection passwords, API keys, SSH passwords and key passphrases, and secret environment variables — are encrypted with a key that lives in the macOS Keychain (the kabanos Safe Storage item). If the Keychain isn’t available, kabanos refuses to store them rather than store them in plain text. Secrets never reach the app’s window: the interface only knows whether a password is stored.

Never stored at all:

  • AWS credentials — they come from your AWS configuration each time.
  • Passwords typed inside a connection URL — they’re split out into the Keychain.
  • Credentials in imported cURL commands.
  • The values of {{variables}} — history keeps the placeholders.

Credentials are also never included in Copy as cURL, connection exports or document exports.

History keeps the newest 20,000 requests. Responses are kept only for saved workspace blocks — the last five per block, up to 512 KB each. Clear it any time in Settings → Request history.

What counts as a read

Every request is classified before it is sent:

  • Read — every GET and HEAD, plus searches and other read-only calls sent with POST: _search, _msearch, _count, _mget, _field_caps, _validate/query, _explain, _analyze, _termvectors, _terms_enum, _knn_search, _async_search, point-in-time and scroll calls, SQL, ES|QL (_query), PPL, _has_privileges, template and ingest simulate calls. Closing a point in time or a scroll is a read too.
  • Dangerous — any other DELETE (with an extra warning for wildcards and _all), _delete_by_query, _update_by_query, closing indices, shrink / split / clone, force merge, cluster settings, security changes, alias changes, snapshot restores, and _bulk requests that contain deletes.
  • Write — everything else. Unknown endpoints are treated as writes.

Production connections

Mark a connection Production and every request that isn’t a read shows a native macOS dialog before anything is sent: the method and path, the connection name and what the request does. Dangerous requests get a Run anyway button; Cancel is the default. Declined requests are never sent.

This check happens in the app’s main process, so it covers everything: the workspace, the Index view, the explorer’s actions, stack management and every step of a routine. Deleting or emptying an index additionally asks you to type its name.

Read-only connections

Turn on Read-only mode and kabanos blocks every request that isn’t a read — it never reaches the cluster. The tab shows an RO badge.

Combine them: a read-only production connection is a safe way to give yourself a look-but-don’t-touch view of a live cluster.

Built safely

The app’s window runs sandboxed and can only reach the cluster through a small, validated interface; it loads no remote code, fonts or scripts. Routine expressions run in a JSONata sandbox, and kabanos never evaluates code you type.