FAQ
Before you connect an account
What CloudDesk connects to, what it keeps where, and what it costs to run, including where it falls short.
Which clouds does CloudDesk work with?
AWS, DigitalOcean and Hetzner Cloud. On AWS it reads EC2 instances, RDS databases, load balancers and S3 buckets; on DigitalOcean, droplets, managed databases and load balancers; and on Hetzner, servers and load balancers. Each cloud is an adapter behind one interface, so a server behaves the same on screen whichever cloud it’s on.
What does it connect to?
Your clouds’ APIs, with your own credentials; the servers you open an SSH session to; and GitHub, to check for an update a minute after it launches and every six hours after that. There’s no account to create, no analytics and no telemetry.
Where are my credentials kept?
For AWS, where they already are: CloudDesk reads the profiles in ~/.aws, and the AWS SDK resolves each one when a call is made, so IAM Identity Center and assumed roles work as they do in your terminal.
DigitalOcean and Hetzner tokens go to your system’s credential store, the Keychain on a Mac. CloudDesk’s own database holds a reference to each, never the secret, and its log scrubs keys and tokens as it’s written.
What permissions does it need on AWS?
Less than an administrator’s key. One published policy lets it read everything it shows and change nothing; another adds the actions that change things. The AWS permissions page lists every action in both, with what each is for.
Will it change anything without asking?
Starting a server doesn’t ask, because nothing breaks. Stopping and restarting ask, and say what will happen to that server; from ⌘K, where the target was matched from a few letters, they ask twice. Destroying a server needs its name typed. Deleting files says what the bucket’s versioning will do with them, and an upload that would replace a file asks first.
Does it cost anything to run?
Listing your resources costs nothing. Reading the AWS bill does: Cost Explorer charges a cent for each request. CloudDesk reads it only for a screen that shows costs, or for an alert about money you’ve switched on, and keeps what it read for six hours.
How accurate are its costs?
Its estimates are on-demand list prices, from a catalog bundled with the app, so they work offline. A rate the catalog doesn’t have is reported missing, which makes a total a floor, rather than guessed. They won’t match an invoice involving Reserved Instances, Savings Plans, Spot or negotiated discounts.
Where your provider publishes the bill, CloudDesk shows it above the estimate — AWS’s from Cost Explorer, DigitalOcean’s from its invoices — and never adds the two together. Nor does it add dollars to euros: Hetzner bills in euros, and its costs stay in them.
Does it work offline?
Your fleet, search and everything CloudDesk has synced are in a database on your machine, so they open without a network. Acting on a server, fresh metrics and the next sync need one.
What does it run on?
macOS 11 or later, on Apple silicon and Intel, as one notarized download. It builds for Linux, as a .deb, an .rpm and an AppImage, but nobody has tried those on a desktop yet, so they aren’t offered here. Windows isn’t built at the moment.
How does it update?
It looks for an update a minute after launch and every six hours, and shows a dot beside Settings when there is one. A button there downloads it, replaces the app and restarts it, after waiting for any transfer a restart would stop. Nothing installs on its own. Every update is signed, and one that’s been tampered with, or that passes an old version off as new, is refused.
See it with your own fleet
It reads the AWS profiles you already have, so connecting one takes a click.
Download for macOS