frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Scalple – Structured production DB access with an immutable audit trail

https://www.scalple.com
2•S3RBVN•1h ago

Comments

S3RBVN•1h ago
Hello, I’m Alexandru Șerban, and I’m building Scalple. Happy to go deep on any part of it.

The problem we kept running into:

Across startups and even some mid-sized companies we saw the same three ways of handling production database access:

1. a shared .env in 1Password 2. an SSH tunnel through a bastion 3. just giving engineers the database password

All three break down the same way: when something goes wrong, you don’t know who ran which query, on what data, or when.

That works until it doesn’t. A GDPR data subject request comes in. An auditor asks for access logs. Enterprise procurement wants proof of controlled production access. You go digging and realize there’s nothing solid—just Slack messages and guesswork.

What we built:

Instead of handing out connection strings, Scalple gives engineers a full database client and a script editor. They write a function, and it runs server side inside a V8 isolate—with a 1 MB memory cap, a 500 ms execution limit, and no outbound network access.

Database credentials never leave control plane. Engineers get the query results—nothing more.

Every operation is written to an append only audit log. There’s no UPDATE or DELETE path in the schema—even for us as admins. Each entry hashes the previous one, creating a verifiable chain. You can export the entire log as a signed, timestamped PDF for compliance and audits.

What it’s not:

Tools like Teleport or Boundary control whether a connection can be established. Scalple operates at a different layer—it controls what happens after the connection: the queries themselves, which fields are returned, and the conditions applied at the record level.

There’s a free self hosted tier (no credit card required): https://scalple.com/install

I’d genuinely love your take on a few things:

* the tradeoffs of using a V8 isolate sandbox * the append only schema design * and whether using TypeScript as a query language would work for your team

Show HN submissions tripled and are now mostly vibe-coded

https://www.adriankrebs.ch/blog/design-slop/
1•hubraumhugo•20s ago•0 comments

China Makes an Island

https://www.nytimes.com/interactive/2026/04/22/world/asia/south-china-sea-island.html
1•tcp_handshaker•2m ago•0 comments

An AI‑enabled device code phishing campaign

https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign...
1•mooreds•2m ago•0 comments

AI Index Report

https://hai.stanford.edu/ai-index/2026-ai-index-report
1•mmaia•2m ago•0 comments

Inside Prime Video

https://insidetechandmedia.substack.com/p/inside-launching-ads-on-prime-video
1•NeedMoreCowbell•3m ago•0 comments

How I've Actually Been Using AI

https://www.indiehackers.com/post/how-ive-actually-been-using-ai-39109e2c59
1•TimLeland•4m ago•0 comments

Ask HN: How are you handling domain registration in agentic workflows?

1•AgentNews•4m ago•0 comments

Built a tool to turn any data into dashboards instantly – looking for feedback

1•dashbee•4m ago•0 comments

The PR you would have opened yourself

https://huggingface.co/blog/transformers-to-mlx
1•gmays•4m ago•0 comments

The Foreman Problem: Managing Teams When Your Best Worker Isn't Human

https://businessasusual.io/p/the-foreman-problem-managing-teams
1•mooreds•7m ago•0 comments

DNS reconnaissance and what it reveals about domains

https://www.whoisxmlapi.com/blog/dns-reconnaissance
1•mennylevinski•9m ago•0 comments

Welcome to Google Cloud Next '26

https://cloud.google.com/blog/topics/google-cloud-next/welcome-to-google-cloud-next26
1•Nic0•9m ago•0 comments

Design is not a moat. It's a generous gift

https://metedata.substack.com/p/008-design-is-a-generous-gift
1•young_mete•10m ago•0 comments

Delta Battlefield Management System

https://en.wikipedia.org/wiki/Delta_(situational_awareness_system)
1•e12e•16m ago•1 comments

Monkey Linux (1997)

https://jenda.hrach.eu/f2/monkeylinux/english.htm
2•alfiedotwtf•18m ago•1 comments

Lufthansa cuts 20k summer flights as fuel prices surge

https://www.bbc.co.uk/news/articles/cre1r4n5j5wo
2•vinni2•19m ago•0 comments

Geoviz JavaScript Library

https://riatelab.github.io/geoviz/
3•mariuz•24m ago•0 comments

Anthropic tests how devs react to yanking Claude Code from Pro plan

https://www.theregister.com/2026/04/22/anthropic_removes_claude_code_pro/
1•marcofloriano•24m ago•1 comments

Smile v6.0 Was Released

https://github.com/haifengl/smile
1•pdsminer•26m ago•1 comments

Iliad fragment found in Roman-era mummy

https://www.thehistoryblog.com/archives/75877
1•wise_blood•26m ago•0 comments

How to Open Source and Not Starve

https://hajo.me/blog/2026/04/22/how-to-open-source-and-not-starve/
2•fxtentacle•27m ago•1 comments

The handmade beauty of Machine Age data visualizations

https://resobscura.substack.com/p/the-handmade-beauty-of-machine-age
1•benbreen•29m ago•0 comments

You lose words on the tip of your tongue (2020)

https://www.bbc.com/future/article/20201125-on-the-tip-of-your-tongue-is-it-a-sign-of-a-bad-memory
1•stephen-hill•29m ago•1 comments

Reverse-engineering a supply chain attack delivered via fake Web3 job interview

https://www.reymom.xyz/blog/security/2026-04-15-supply-chain-attack
1•reymon-dev•29m ago•2 comments

Everything I know about floppy disks (2023)

https://thejpster.org.uk/blog/blog-2023-08-28/
1•stephen-hill•30m ago•0 comments

Build It Yourself (2025)

https://lucumr.pocoo.org/2025/1/24/build-it-yourself/
2•stephen-hill•30m ago•0 comments

AI fact-checker with guardrail classifier and MCP server

https://fact-check-analyzer.vercel.app/
1•amahadeven•31m ago•1 comments

How Skopx Learns Your Business While You Work

https://skopx.com/resources/live-platform-business-context
1•skopx•31m ago•0 comments

Open Benchmark: Text Normalization in Commercial Streaming TTS Models

https://async-vocie-ai-text-to-speech-normalization-benchmark.static.hf.space/index.html
1•baghdasaryana•32m ago•0 comments

Push Notifications Can Betray Your Privacy (and What to Do About It)

https://www.eff.org/deeplinks/2026/04/how-push-notifications-can-betray-your-privacy-and-what-do-...
1•u1hcw9nx•33m ago•0 comments