Documentation

Kino Cloud

The hosted control plane - what it does for you, what it knows about you, and what it deliberately cannot see.

Kino Cloud is the service running at https://kino.dpdns.org. It is the account system and the credential mint for everything else: it knows which machines are yours, which relays are available, and it issues the short-lived credentials that let your laptop reach your machines.

It is the only piece you do not have to run.

What it does for you#

Machines that install themselves. Add a machine here, run one command on it, and it is reachable. No relay URL to copy, no token to paste, no agent id to keep track of.

Relays, found automatically. Your agents ask which relays exist, latency-race them, and park on the fastest healthy one. When a relay goes down they move on their own. You never pick one.

Credentials that expire on their own. Your machines hold a credential that only ever buys a 24-hour token; your laptop gets one good for an hour at a time. Nothing you install is a permanent password. Delete a machine and its access is gone — see Revocation.

Somewhere to see it all. Machines shows every machine, which relay it is parked on, and whether it is live.

What it knows about you#

Everything Kino Cloud stores about a machine:

It stores It does not store
The name you gave it Its hostname or IP address
An opaque machine id Anything about the hardware or OS
Which relay it last parked on, and when Anything you did while connected
A hash of its credential The credential itself

And about you: your email address, an Argon2 hash of your password, and hashes of any account keys you created.

That is the whole list.

Every credential is shown exactly once

Account keys, enroll keys, agent keys — only a SHA-256 hash is kept. There is no “show me that key again”, because there is nothing to show. Lose one and you create another.

What it cannot see#

Not your SSH credentials. Your passwords and private keys live in Kino SSH Manager’s local encrypted vault and are never uploaded. Kino Cloud has no field to put them in.

Not your sessions. It is not in the data path — no SSH byte ever reaches it. Your session runs between your SSH client and your machine’s own sshd, encrypted end to end, over a relay that is also carrying ciphertext it has no key for. See Who sees what.

Not what you do on the machine. It learns that an agent is parked somewhere. It does not learn that you connected, when, or for how long.

What happens if it goes down#

Not much, immediately. Because it is out of the data path:

  • Agents already parked on a relay stay parked.
  • Tokens already issued keep working until they expire.
  • Sessions already open are untouched.

What stops is adding machines, issuing new credentials, and looking up where an agent is parked. Kino SSH Manager caches the last successful lookup per machine, so a host you have already connected to stays reachable through a short outage.

Agents keep retrying, and pick up where they left off when the service returns. Only after ~24 hours without a refresh does a machine actually lose access.

Limits#

The free tier allows 3 machines per account, and stays free — it is not a trial. Relays are shared, with no cap on how much you move through them while we are in beta.

If you want your traffic over hardware you control, run your own relay — it still works with Kino Cloud, and there is no charge for it on any plan. See Self-hosting.

Paid plans are not priced yet. The shape of them, and a form to tell us which one fits you, is on the plans page.

Deleting things#

To remove Do this Effect
A machine Machines → Remove Its credential stops working immediately. Uninstall the agent too — see kino-agent.
One copy of the app Account keys → Revoke Immediate. Checked on every request.
Your account Email us Everything above goes with it.

Removing a machine here is what actually revokes its access. Uninstalling the agent without deleting the machine leaves a working credential on a box you no longer control.

Relation to the other pieces#

                  ┌────────────────────┐
   account key    │     Kino Cloud     │
   ──────────────►│                    │  issues short-lived
   Kino SSH       │  accounts,         │  credentials, knows
   Manager        │  machines, relays  │  which relays exist
                  └─────┬──────────┬───┘
            refresh     │          │  verify with the public key
            (24h token) │          │  (relays can check, never mint)
                        ▼          ▼
              ┌──────────────┐   ┌──────────────────┐
              │  kino-agent  │──►│    kino-relay    │◄── Kino SSH Manager
              └──────────────┘   └──────────────────┘
                    parks              splices

A relay never asks Kino Cloud for permission — it verifies credentials offline with a public key it was handed once. An agent talks to Kino Cloud only to refresh its token, list relays, and say where it parked.

Open source#

The three pieces that touch your traffic are open, and auditable: Kino SSH Manager (GPL-3.0), kino-agent (GPL-3.0), and kino-relay (AGPL-3.0).

kino-control — the control plane itself — is the one proprietary piece. Normally it is the service you use rather than software you install, but it can be licensed to run on your own infrastructure if nothing may leave your network: see the plans page.