13 ms·
Show HN: Kvass, a personal key-value store
- raydiatian 4y agoI hope this feeling is me catching onto the joke in the name rather than being a first responder
- nathell 4y agoThe name can be read as an acronym of ‘Key-Value ASSociative store’, but also alludes to the beverage: https://en.wikipedia.org/wiki/Kvass https://en.wikipedia.org/wiki/Kvass
- jve 4y agoPicture in README.MD really tells you that author is aware of kvass (the drink). This repo actually made me google up that wiki page to get an answer: "Is this drink really called kvass elsewhere, not only in my country?". Yes it does it seems.
- raydiatian 4y agothe original, personal key value store
- deleted 4y ago[deleted]
- tkindy 4y agoI’m wondering what sorts of use-cases people would use a personal key-value store for. Maybe it’s just a useful foundation for building other tools on top of, like a password manager.
- apavlo 4y agoBut it's just a wrapper around SQLite. Skip the middleman and just use SQLite.
- mosselman 4y agoBut you can’t access Sqlite over the web.
- goodpoint 4y ago...and you shouldn't.
- jonnycomputer 4y agoSeems to me that for a personal tool like this, sqlite3 is non-problematic. https://www.sqlite.org/whentouse.html https://www.sqlite.org/whentouse.html "Generally speaking, any site that gets fewer than 100K hits/day should work fine with SQLite. The 100K hits/day figure is a conservative estimate, not a hard upper bound. SQLite has been demonstrated to work with 10 times that amount of traffic."
- gkbrk 4y agoAny concrete reasons? SQLite is probably good enough for 99% of websites / apps.
- goodpoint 4y agoIt's not designed to be straight exposed as a web service. It's not hardened to handled malicious traffic.
- pdpi 4y agoOr don't skip the middleman and get a simple k/v interface instead of having to deal with a whole sqlite database.
- capableweb 4y agoIt's clearly not "just a wrapper around SQLite", read through the README and it'll be evident why.
- tjpnz 4y agoI already use my password manager for the problem this tool is trying to solve.
- maxmunzel 4y agoThe primary use case is for shuffling around files or clipboards between different computers. I also regularly use the url-sharing capability. Prior, I had to deal with ephemeral http servers, which I didn't like from an ergonomic perspective. Ergonomically, I find redis nice. The problem is, that it is in-memory and that encryption is cumbersome. Also, kvass is able to be used offline, as the kv-store is implemented as a CRDT.
- cyberge99 4y agoI use a KV, Hashi vault, so my shell scripts get api keys, secrets, etc and they’re not stored plaintext or in SCM.
- resoluteteeth 4y agoI use skate to store secrets used by some personal programs. I have scripts that pull out the secrets and set them as environment variables that are used by the programs. This way I don't have them sitting around in a configuration file in the source directory and can't accidentally commit them to git but they're easy to sync between computers.
- nextaccountic 4y agoFor passwords specifically there's a similar tool, https://www.passwordstore.org/ https://www.passwordstore.org/ - but it stores GPG-encrypted plain text files versioned with git, instead of managing a sqlite db More importantly, it has Firefox and Chrome extensions for auto-filling passwords on the web https://github.com/passff/passff https://github.com/passff/passff https://github.com/browserpass/browserpass-extension https://github.com/browserpass/browserpass-extension
- traviscj 4y agoI use a similar setup to store code snippets (certain Java annotations for integration/unit tests, various things like that), vehicle license plate/vins, internal (but nonsensitive) ids for test accounts, tons of things like that. Honestly a password manager would probably be technically better—or a bunch of flat files lol—but there was a certain charm to having it displayed / function exactly as I like it, and lightning quick with nothing I didn’t need. IDE would be another natural place for a lot of my usages, but I kept finding I needed to leave it in a pull request review or slack conversation or similar, not necessarily programming myself.
- VMG 4y agonow all that is missing is a FUSE driver
- deleted 4y ago[deleted]
- greatNespresso 4y agoCool project! Congrats on launching ! What is the benefit compared to reddit or CF workers KV?
- maxmunzel 4y agoMainly self-hosting and generating share-able urls. If your key's end in ".html" the mime type is even set accordingly and you can use it for toy-websites ;) This is by no means meant to replace the backend of your app. It's more of an alternative to usb-sticks and google drive.
- kklisura 4y ago
- tuxie_ 4y agoIsn't that the whole point of "Show HN"? Or what do you expect when you click on a "Show HN" story?
- kklisura 4y agoI expected to learn something from it - especially when it's popped on the front page of HN. Am I expecting too much of HN? My train of thought when I saw the link "a key-value store": what data-structure are they using? A hashmap? How are they resolving conflicts? Is it in memory? How are they persisting data? Do they support multiple instances? What about concurrency? etc. Of course I might be a bit disappointed when the project is just 4 web APIs on top of sqlite table.
- svnpenn 4y agoIt's not HN job to entertain you. Someone wrote some software they thought was useful, so they are sharing it. If you don't like it down vote and move on. Get off your high horse.
- tuxie_ 4y agoThat's a bit harsh, while I don't agree with OP I don't think that your language helps in promoting a healthy discussion about what is reasonable to expect from a HN front-page post. Also you say that "it's not HN job to entertain you". What is HN's job then? Because honestly I do come here to read things that entertain me.
- deleted 4y ago[deleted]
- svnpenn 4y agoTo be news. I can understand if you missed that, it's not very obvious from visiting the home page.
- markstos 4y agoFor personal use, I’ve had good luck storing things in files. Then when I need those those things, I read the files.
- christophilus 4y agoHeh. Snarky but true. I store just about everything in a “notes” folder which is mostly markdown files. Easily searchable / editable with any tool you like.
- chrisseaton 4y agoThis seems unnecessarily snarky. You can make anything sound silly by reducing its functionality to the most basic level possible, ignoring all aspects of ergonomics and packaging. And you could make this comment about any storage engine. Like the infamous Dropbox comment here.
- pydry 4y agoDropbox explained itself pretty well. A simple one paragraph why at the top of this project's README wouldnt be amiss.
- chrisseaton 4y agoFor example > Its trivial to set up and operate kvass across multiple devices > remember the file we stored earlier? Let's get a shareable url for it!
- pydry 4y agoI read it. Im pretty clear on what it does. Im still not feeling the why (or the differentiator from other things that store files and give you URLs). Remember when Dropbox explained itself by telling you you didnt need to carry around USB sticks in your jean pockets that get washed or lost? I thought that was pretty neat.
- amelius 4y ago
- losfair 4y agoNice project! I'm wondering why you choose to implement your own cryptography routines instead of using something standard like TLS. Apparently your `DecryptData` and `Encrypt` methods are vulnerable to replay attacks due to a lack of (EC)DH-style key exchange.
- maxmunzel 4y agoThanks for the critique! I wanted to use symmetric crypto as its trivial to use without domains and certificates. The possibility of replays is a non-issue, as the key-value store is implemented as a CRDT and therefore all operations are idempotent. On the other hand, I didn't anticipate replay attacks in the design and thanks to your comment, I'll keep them in mind should I ever find myself in a scenario where they are undesirable...
- losfair 4y agoTLS is available in pre-shared key (PSK) mode. Looks like there is ongoing work to add TLS-PSK to Go's standard library: https://github.com/golang/go/issues/6379#issuecomment-1170067019 https://github.com/golang/go/issues/6379#issuecomment-117006...
- maxmunzel 4y agoCool! If this gets implemented, I'll definitely use is instead of raw AES.
- randomhodler84 4y agoYeaaah don’t use ECB. AEAD or gtfo
- makeworld 4y agoIt doesn't matter if the operations are idempotent. The point is that an eavesdropper can replay a message that sets a key, for example, overwriting whatever was there previously. It would be better to use an established cryptography system. You could do self-signed certs with TLS, like Syncthing does. Or just use SSH.
- vander_elst 4y agoWhat's the use case for this (besides being a nice learning project)? I didn't see this on the readme.
- deleted 4y ago[deleted]
- prezjordan 4y agoThe built-in server and remote support is pretty nice! API seems solid, and I dig the QR codes.
- vorticalbox 4y agoQr codes are pretty cool just a shame it never really took off.
- ponyous 4y agoWhat do you mean it didn't take off? QR code detection is implemented in native iOS camera and IIRC most android implementations too. Almost everyone can use it. In that sense it took off more than bitcoin.
- vorticalbox 4y agoThat is true, its just not as widely used as I would have hoped.
- rscrawfo 4y agoI feel like that has changed over the past few years. Many restaurants in my area started using them for menus, and I recently saw them used to setup wifi while on vacation.
- Skunkleton 4y agoI just paid my lunch tab by scanning a QR code on a receipt, and then tapping Apple Pay. It was rad.
- swah 4y agoIn my country (BR) this transfer method (Pix) that can be iniatiated with a QR code has really picked up - I'm surprised a simple "scam" - replacing printed QR codes that are glued to resturant tables - hasn't caught on yet.
- d1l 4y agoWait, this is just a toy project.
- tuxie_ 4y agoWhat do you mean? It's a project. It has a purpose and it achieves that purpose. If you don't need a lot of code to achieve it, what's the problem? What makes it "toy"?
- Sujeto 4y agoWhat does it do better than Skate? Or what additional things does it do, url and qr codes?
- maxmunzel 4y agoI think it's fair to say that skate is the more mature tool. Kvass on the other hand is more focused and simpler. Especially self-hosting kvass is even simpler than skate, and I had issues linking/syncing skate in the past. It would probably be a nice weekend project to port the url/qr features to skate.
- vlan121 4y agoWhat is the benefit compared to the private use of Redis? Redis is under BSD licence and continues to be very actively maintained and used.
- jbverschoor 4y agoI thought it’s a password store. Also bc of the name “v” pronounced Spanish = b, so key-bass, sounds like pass
- drdaeman 4y agoIt's not Spanish, though, and in quite a few languages there's "w" instead of "v". https://en.wikipedia.org/wiki/Kvass https://en.wikipedia.org/wiki/Kvass
- maxmunzel 4y agoRedis is in-memory so it's prohibitive for big files. Also kvass still works if its disconnected from the server. This is important, if you want to use it for config files. On the other hand, using redis (/skate) for storing files was the inspiration for creating kvass.
- asdfagrgh 4y ago
- izhak 4y agoNot trolling or trying to downplay anybody here, but honestly - how “kvass” (readed as “k-v-ass” given it is a “key-value” storage) is a good name?..
- yreg 4y agoAbout as good a name as the password manager which I'm unable to read in any other way than keep ass. (Just in case you are unaware, kvas/kvass is a traditional north-eastern europe drink.)
- t0astbread 4y ago> the password manager which I'm unable to read in any other way than keep ass I've never read it this way but now I can't unsee it.
- brontosaurusrex 4y agoKvas means yeast, could be also a drink name.
- yreg 4y agoSince this is on top of the readme they refer to the drink: https://user-images.githubusercontent.com/5411096/179968508-5fe1e390-3136-46a6-bb1e-8d329ad231c3.jpeg https://user-images.githubusercontent.com/5411096/179968508-... You could call yeast kvas, but in slavic languages there are usually other nouns used. (drozdze, drozdie, kvasok, kvasnice, закваска , дрожжи). Kvas (the drink) is kvas everywhere.
- nkrisc 4y agohttps://en.m.wikipedia.org/wiki/Kvass https://en.m.wikipedia.org/wiki/Kvass
- Sardtok 4y agoIn Norwegian kvass means sharp.
- mordae 4y agoI like the idea. What surprised me was the custom network protocol. I expected it using ssh to work with the remote instance.
- sigmonsays 4y agoi just have a directory in git and store everything in files can anyone help explain what i'd use this for?
- staindk 4y agoI'm late to reply here but I only now got around to setting Kvass up and testing it out. I got it running on a free GCP Compute VM and linked it through to my PC so that the VM hosts the Kvass server and my PC (and in future laptop) set/get stuff on there. I plan on using Kvass to pass things between my laptop and PC - links, files, images... etc. Will see how that goes - perhaps I don't end up using it at all. If it seems useful I'll try hook my web domain in so that I have a more static domain to use it with.
- jamesbfb 4y agoYou stole my idea! I love it. As a dev who spends a big chunk of their day in the shell, this is the kind of tool that I was destined to create myself, but never did thanks to lack of time, laziness, life, etc.
- dheera 4y agoIn case anyone is wondering about the name, it's a Slavic fermented bread drink that's much less alcoholic than beer (and commercially canned versions are near zero alcohol). It's one of my favorite chilled summer drinks, and you should be able to find it in Slavic stores in the US as well.
- Skunkleton 4y agoThere is a cold cucumber soup that uses kvass as its base. I would recommend giving that a try as well.
- dheera 4y agoOkroshka? Yeah I love that stuff. I'm vegetarian, replacing the sausage with a vegetarian one (or leaving it out) works well. I followed this recipe: https://www.youtube.com/watch?v=ifE7gDiLDbE https://www.youtube.com/watch?v=ifE7gDiLDbE The Life of Boris also has a great video on making Kvass: https://www.youtube.com/watch?v=k1UTJKBMvgc https://www.youtube.com/watch?v=k1UTJKBMvgc though I haven't gotten around to trying it, I've only had commercial bottled and canned ones. I imagine if you make it yourself you'll have a slightly more alcoholic outcome.
- mkoryak 4y agoSomewhat unrelated: Can one buy kvass starter in the United States, and if so, what is it called? I'm not interested in bottled kvass, it never tastes like the real thing and you don't get to watch kvass explosions in the bottle as it is being made
- deleted 4y ago[deleted]
- nibbleshifter 4y agoYou don't need a starter? You can just make one trivially. There's a pretty amusing "Life of Boris" video that shows how on YT.
- richiebful1 4y agoKvass starter? I typically just use yeast, old rye bread, raisins, and sugar. Maybe added lemon for taste at the end. This recipe is similar to how I make mine (in Russian): https://www.gastronom.ru/recipe/55100/domashnij-kvas-iz-hleba-bez-drozhzhej https://www.gastronom.ru/recipe/55100/domashnij-kvas-iz-hleb...
- mkoryak 4y agoTIL.. When I saw kvass being made I was too young to know how it works.
- mbreese 4y agoI have so many questions about this. Much of the architecture seems off to me. I like the concept, but it doesn't seem as secure as it could be. For the README, I'd hope to find a bit more information about the way data is stored and transmitted. For example, this seems to just be a SQLite database with values in fields? Is there a separate encryption key for the database itself? Otherwise anyone with access to the file would be able to see all data stored? The encryption key is only used to encrypt data in transit, but not at rest? And then you're encrypting the full JSON blob instead of only the values? This seems risky to me. What is the purpose of the ProcessID? It is randomly generated and stored in the database (thus used by all clients too). So, I'm not sure what this is for? I see it's used to resolve conflicts, but these should probably be given out by the server? Do the clients cache data locally? It looks like you're basically syncing from the server for every request. You're already making a round trip to the server for a request anyway, so why not keep state only on the server? I can understand an offline-only mode, but this would require a significantly more robust sync mechanism. If this was the goal, I'd love to see this discussed more in the README too. Finally, I don't understand why you're using plain HTTP (no TLS) for communication b/w client and server. I didn't see any authn/authz in the requests. You're also unmarshalling random data from the request w/o confirming that it is valid first. This seems risky to me and could potentially crash the server if I were to send it random data. This would have been a great use-case for a simple (non-HTTP/JSON) TCP server: >>> AUTHTOKEN xxx >>> SET $KEY $LEN $SHA1 >>> <bytes> <<< OK >>> AUTHTOKEN xxx >>> GET $KEY <<< $LEN $SHA1 <<< <bytes> Custom protocols have their own security issues, but it can also be easier to see where there are potential issues (like unmarshalling unvalidated blobs). If you wrap something like the above in TLS-PSK, you're set. If you want to use encryption for a session (after you authenticate), that's possible too, but you're at risk of effectively re-creating TLS.
- deleted 4y ago[deleted]
- koheripbal 4y agoI just use WinSCP with remote file encryption turned on and have VeraCrypt for the local temp storage. That way my entire working file system is encrypted at rest, in transit, and while stored remotely - entirely with heavily mature off the shelf open source tools.
- prussian 4y agoCool. Curious why you chose sqlite instead of something like badger [https://github.com/dgraph-io/badger https://github.com/dgraph-io/badger] given you expose it as a key value database, which badger is.
- maxmunzel 4y agoSQLite allows me to keep multiple versions of the same entry, which is convenient for state merging. Half the sync logic is actually implemented in SQL. Other than that, I’m already familiar with it and the storage backend is not very performance critical for the intended use case.
- mattmerc 4y agoI don't know much about the other solutions that people are mentioning in the comments, but I have to say... this looks elegant! Great job!
- deltasepsilon 4y agohow about: echo "value" > ${home}/.db/key cat ${home}/.db/key > value scp -r ...
- deleted 4y ago[deleted]
- uwagar 4y agouh oh leave that drink alone mate.
- NonNefarious 4y ago
- mahebub 4y agoHack Mama
- mike_hock 4y agoCan you also drink it?