evertap

Limitations

evertap is early: this page lists what it does not do, what has not been tested, how to upgrade and uninstall it, and answers to common questions.

Not in this version

These are planned, but not in v0.1:

  • MCP for agents (evertap mcp) and agent skills (evertap skills install). Agents can use the CLI.
  • evertap connect starting on its own when an app connects, with ev.internal set up by evertap login. For now, run evertap connect in a terminal and add the hosts line yourself.
  • evertap update and evertap repair. Upgrade with the install script (below).
  • Backups, restore, and export. Back up the Docker volumes yourself if you need to. A temporary resource is deleted after 7 days without a connection.
  • Connecting from serverless and preview deployments, which cannot run evertap connect.
  • A short ev command.
  • evertap itself running on Windows, and apps in containers reaching ev.internal.

Never

evertap hands out databases and buckets for development, and stays that small. It does not and will not:

  • Deploy apps, connect to git, or manage domains and certificates
  • Group resources into projects or environments
  • Give you a shell, a terminal, or raw logs on the machine running it
  • Set up Tailscale or WireGuard (you can use Tailscale with it: Tailscale)
  • Read resources from a configuration file
  • Serve production traffic. Use evertap for development, CI, and previews, not as a production database.

Known limits

  • Apps in containers do not reach ev.internal, on a laptop or on the machine running evertap. An app that runs in Docker keeps its database in its own Compose file.
  • Apps on the machine running evertap, in network and cloudflare mode, do not reach ev.internal either: evertap connect is for other machines. Use local mode on a machine that runs both evertap and your apps.
  • Presigned URLs open only where evertap connect runs, or on the machine running evertap in local mode, unless the bucket is reachable from anywhere, which takes network or cloudflare mode and an address of buckets' own (Signed links that work anywhere).
  • Form uploads (a presigned POST) do not work with RustFS buckets, which do not take them. Garage buckets do.
  • PostgreSQL goes through PgBouncer in transaction mode: session state lasts one transaction (Connection pools).
  • A database's version is fixed when it is created. To move to another, create a new database and copy the data.
  • Every client has the same rights. A paired CLI or an API key can use and delete every resource that is not protected. There are no scopes, roles, or expiry dates.
  • The macOS loopback alias that evertap connect asks for lasts until the Mac restarts.
  • Under WSL, Windows apps do not reach ev.internal, and WSL drops the ev.internal line when it starts unless told not to (Windows).
  • Old images stay on disk. When an evertap upgrade brings newer images, the old ones stay until you remove them (Upgrade).

Not tested yet

evertap is tested on Linux. These have not been tried end to end:

  • macOS, as the machine running evertap or as a laptop: setup's sudo steps, the loopback alias after a restart, and Docker Desktop, OrbStack, and Colima
  • WSL, including keeping the ev.internal line with generateHosts = false
  • Traefik and Tailscale Serve in front of evertap, and nginx with a real certificate
  • A proxy run with Docker on a machine whose firewall drops incoming connections by default, such as ufw default deny incoming. Its connections to Docker's bridge address may need allowing, for example with ufw allow in on docker0 to any port 8080, and the same for the br-… interface of its Compose network.
  • Rootless Docker with a proxy run with Docker
  • Cloudflare's Bot Fight Mode in front of evertap login and evertap connect
  • Setup creating a Cloudflare Tunnel against Cloudflare itself: its calls are tested against a stand-in for Cloudflare's API, and its token link's Cloudflare Tunnel permission against none
  • Buckets reached from anywhere through a Cloudflare Tunnel: a HEAD request for a file Cloudflare would cache, such as a .jpg, may arrive as a GET and fail its signature, even with the Cache Rule that setup makes (Cloudflare Tunnel)

If you try one, an issue with what happened helps.

Upgrade

Run the install script again. It keeps your settings, skips setup, and reminds you to restart evertap:

curl -fsSL https://github.com/caru-ini/evertap/releases/latest/download/install.sh | sh
sudo systemctl restart evertap@$USER
  • Upgrade your laptops and CI too. When the CLI and evertap no longer speak the same version of their connection protocol, evertap connect says which machine to upgrade.
  • On start, evertap replaces each of its containers whose image or settings changed, and keeps their data. A database restarts once. The first start after upgrading from an evertap that kept no record of its containers' settings replaces each of them once.
  • The images the old containers ran stay on disk. docker image prune -a removes them, along with every other image no container uses.
  • Before an upgrade changes the format of evertap.db, evertap keeps a copy beside it, named evertap.db.v<version>-<time>.bak. An older evertap refuses to open a file a newer one has changed.

Uninstall

On the machine running evertap, stop it, then remove everything it made, every database's data included:

sudo systemctl disable --now evertap@$USER
evertap uninstall

evertap uninstall lists what it removes and asks you to type uninstall (CLI). Then remove what you installed yourself:

sudo rm /etc/systemd/system/evertap@.service /usr/local/bin/evertap
sudo rm -rf /etc/evertap
sudo systemctl daemon-reload

The images evertap downloaded stay; docker image prune -a removes them with every other unused image.

On a laptop, stop evertap connect, run evertap uninstall to sign out and remove the ev.internal line, and delete the binary. On macOS, the loopback alias goes away at the next restart, or now with sudo ifconfig lo0 -alias 127.77.0.1.

Questions

Why ev.internal?

ICANN reserved .internal for private use in 2024, so it never resolves on the internet, and the name cannot lead anywhere else. .local belongs to mDNS, which can make lookups slow on macOS. localhost would clash with databases you run yourself, and browsers send localhost cookies to every port, so evertap's sign-in would reach your app on localhost:3000.

Why the standard ports?

So a connection URL is the same for every version, in every mode, and wherever evertap runs. Your .env never changes, and tools that assume 5432 or 6379 keep working. evertap tells versions apart by the database's name or user, not by the port.

Why 127.77.0.1?

A loopback address of its own leaves 127.0.0.1 free, so a database you run yourself on 127.0.0.1:5432 and evertap's ev.internal:5432 work side by side.

Does changing the mode touch my data?

No. The mode changes only how evertap is reached. Databases, buckets, and connection details stay as they are.

Can several people share one evertap?

Yes. Each person signs in their own browser and pairs their own laptop, and each appears under Clients. Everyone has the same rights, so share it only with people you trust with every resource.

Edit on GitHub

The evertap name and logo are not licensed with the code (section 6 of the license). You may use them to refer to evertap, but not to name or brand your own product or service, or in a way that suggests evertap made or endorses it, without permission.

evertap is an independent project. It is not affiliated with, endorsed, sponsored, supported, or certified by the owners of the software it runs, and it uses their names only to say which software that is.

  • Postgres, PostgreSQL and the Slonik Logo are trademarks or registered trademarks of the PostgreSQL Community Association of Canada, and used with their permission.
  • MySQL is a registered trademark of Oracle and/or its affiliates.
  • Redis is a registered trademark of Redis Ltd. Any rights therein are reserved to Redis Ltd.
  • RustFS is a trademark of RustFS, Inc.
  • Other names, including Garage, may be trademarks of their respective owners.

On this page