I build a lot of local-first apps.
But even local-first apps still need some cloud: backups, sync, collaboration, sandboxed AI agents, and AI inference.
I also don’t want to keep rebuilding the same backend pieces for every app.
So I’m building Cloudoak, a shared cloud layer that apps can build on through the Cloudoak SDK.
I don’t want to run Cloudoak as a traditional SaaS, and I also don’t want users to self-host and maintain another VM just to use it. Both add unnecessary management and friction.
So I’m exploring Cloudoak as a self-installing personal cloud.
The current idea is to have a local Cloudoak app for desktop, Android, and iOS. It acts as both the infrastructure manager and the frontend for your Cloudoak control plane.
Cloudoak App
Desktop / Android / iOS
Manager + Dashboard
│
│ Cloudflare OAuth
▼
Your Cloudflare account
│
▼
Install / upgrade / repair
Cloudoak Control Plane
The Cloudoak app can fetch and verify a versioned release containing the install manifest, control-plane bundle, migrations, and other assets needed to set everything up.
Cloudoak App
│
Fetch + verify release
│
┌────────┼────────┐
▼ ▼ ▼
Manifest Bundle Migrations
│
▼
Cloudflare OAuth
│
▼
Your Cloudflare account
│
├── D1
├── R2
├── Workers
├── Sandboxes
└── Cloudoak Control Plane
Cloudflare OAuth is only for infrastructure management. It is used locally by the Cloudoak app when the control plane needs to be installed, upgraded, repaired, or new Cloudflare resources need to be provisioned.
The Cloudoak control plane has its own auth layer for apps and users.
Apps built on the Cloudoak SDK authenticate to the control plane and use the same shared backend primitives instead of each app rebuilding its own database, storage, sync, auth, sandbox, and AI infrastructure.
App A / App B / App C
│
│ built on
▼
Cloudoak SDK
│
Cloudoak Auth
│
▼
Cloudoak Control Plane
│
┌──────┼───────────┐
▼ ▼ ▼
D1 R2 Workers / Sandboxes
This can also become the common identity and cloud layer across apps, so collaboration, cross-device access, storage, sync, AI services, and sandboxed compute do not need to be reinvented for every project.
I also want to explore making the Cloudoak Manager run as a WebAssembly app directly from the website, with the control-plane frontend hosted there too. If that works well, users could manage their Cloudoak installation without having to install another desktop or mobile app.
So the overall model is:
Your Devices
│
┌────────┴─────────┐
│ Cloudoak App │
│ Desktop / Mobile │
│ Manager + UI │
└────────┬─────────┘
│
Cloudflare OAuth
│
▼
Your Cloudflare
│
▼
Cloudoak Control Plane
Auth + Resource Layer
│
┌─────┼─────┐
▼ ▼ ▼
App A App B App C
│ │ │
└── Cloudoak SDK
No Cloudoak SaaS to depend on. No VM to maintain. No rebuilding the same backend for every app.
Your apps stay local-first, while the shared cloud layer, control plane, and app auth live in your own Cloudflare account.
Note: this is not the final architecture. I’m still exploring the idea through research and writing, so this microblog may change as the architecture research continues.