6 ms·
Thumbsup for sandstorm - my conpany is extensivly using it with a small team and external clients. For those who dont know what it is: Single Sing On with an
by chrisMyzel 7y ago
Thumbsup for sandstorm - my conpany is extensivly using it with a small team and external clients.
For those who dont know what it is:
Single Sing On with an App Store. Better explained:
You create one account and then can create/edit/share/copy projects of completely unrelated software
. So lets say you create a gitlab installation, 3 etherpad projects, 5 wekan (trello clone) boards and then share them with your team/client/family by just adding their email adresses - awesome tool!
- reagent_finder 7y agoWas somewhat disappointed it wasn't a 2020 version of the Darude song, but this is nice as well.
- davidjgraph 7y ago"Single Sing On" sounds very close to what you want.
- blauditore 7y agoSee also: https://darude.io/ https://darude.io/
- acl777 7y agothe original will never die! :-)
- tclancy 7y agoYeah, my mind immediately jumped to a hockey team having just scored a goal.
- blowski 7y agoI imagine I've completely misunderstood it, but to me that sounds like pulling Docker images and running them on something like a Kubernetes cluster. The Docker images have to meet a contract, with a type of UI, authentication endpoints, etc. Does that make sense as a comparison?
- andybak 7y agoRoughly yes. All wrapped in a nice UI.
- sciurus 7y agoA key difference is that an app can run in Docker unmodified, but can require significant changes to run in Sandstorm.
- amalcon 7y agoI think the biggest cause of this is just how Sandstorm really wants you to use it for authorization, which means that authorization needs to be scoped at the app instance level. There are good reasons for this. However, for standalone use, app instances need broader scope than what you usually want for authorization. If not for that mismatch, one could just wrap most existing apps that support pubcookie authentication in a layer that translates Sandstorm APIs into HTTP.
- ash 7y agoYes and no. https://sandstorm.io/news/2014-08-19-why-not-run-docker-apps https://sandstorm.io/news/2014-08-19-why-not-run-docker-apps
- ckocagil 7y agoSandstorm is also an extremely security-oriented way of running packaged apps. It uses an advanced sandbox that has defeated many kernel zero-day vulnerabilities. It utilizes the Cap'n Proto serialization + RPC protocol, another security-oriented project of Kenton. Security is critical for a platform for self-hosted apps. One vulnerable or malicious app shouldn't be able to compromise your entire platform. Docker-based solutions don't provide this.