Agent skill

Cloud SaaS Mode

by chmonitor in chmonitor/chmonitor

Work on chmonitor's Cloud (SaaS) vs self-hosted (OSS) behaviour from ONE codebase.

GPL-3.0Auto-check: notesDatabases

Install Cloud SaaS Mode

skills CLI
$ npx skills add chmonitor/chmonitor --skill cloud-saas-mode -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install chmonitor/chmonitor cloud-saas-mode --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/chmonitor/chmonitor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/cloud-saas-mode .claude/skills/cloud-saas-mode && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-saas-mode
GitHub stars
298
Token cost
~2.5k tokens
SKILL.md length
999 words
Files
1
Skills in repo
53
Repo updated
First seen
Licence
GPL-3.0

At a glance

Work on chmonitor's Cloud (SaaS) vs self-hosted (OSS) behaviour from ONE codebase.

  • Changing how dash.chmonitor.dev differs from Docker/K8s/OSS builds: the cloud-mode flag
  • SKILL.md covers Golden rule, The flag, Behaviour and Welcome / setup page, plus 4 more sections
  • Calls pnpm and bun; needs ANYROUTER_API_KEY and CHM_API_KEY_SECRET
  • Public read-only demo hosts

What it does

Cloud SaaS Mode is an agent skill from chmonitor/chmonitor. Work on chmonitor's Cloud (SaaS) vs self-hosted (OSS) behaviour from ONE codebase. Use when changing how dash.chmonitor.dev differs from Docker/K8s/OSS builds: the cloud-mode flag, public read-only demo hosts, the welcome/setup onboarding page, per-user (D1) ClickHouse connections, host visibility for anonymous vs signed-in users, the "Test connection" error classifier and its docs links, or the "Try with sample ClickHouse" onboarding preset. Triggers: "cloud mode", "SaaS", "demo host", "welcome page", "setup…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Data warehousing, Container orchestration and Containers. It works with ClickHouse, Docker and Kubernetes. The repository describes itself as: Open-source operational advisor for ClickHouse — real-time monitoring plus AI-driven index/partition/materialized-view recommendations. The licence is GPL-3.0.

When your agent uses it

  • Changing how dash.chmonitor.dev differs from Docker/K8s/OSS builds: the cloud-mode flag
  • Public read-only demo hosts
  • The welcome/setup onboarding page
  • ClickHouse connections

Example prompts

  • “Test connection”
  • “Try with sample ClickHouse”
  • “cloud mode”
  • “/cloud-saas-mode”

Requirements

  • Docker
  • A credential in ANYROUTER_API_KEY
  • A credential in CHM_API_KEY_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit fc39ef0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANYROUTER_API_KEY
    • CHM_API_KEY_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud SaaS Mode loads about 2.5k tokens when it runs. Until then it costs about 210 tokens; SKILL.md has 999 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~210
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:47
    Single source of truth: `apps/dashboard/.env.production` (+ `.env.preview` overlay).
  • NoteMentions a .env fileSKILL.md:51
    es NO `[vars]` — never re-add one; edit `.env.production`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from chmonitor/chmonitor at commit fc39ef0, republished under its GPL-3.0 licence (© chmonitor). 999 words, ~2,516 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-saas-mode/SKILL.md (or your agent's skills folder).
name
cloud-saas-mode
description
Work on chmonitor's Cloud (SaaS) vs self-hosted (OSS) behaviour from ONE codebase. Use when changing how dash.chmonitor.dev differs from Docker/K8s/OSS builds: the cloud-mode flag, public read-only demo hosts, the welcome/setup onboarding page, per-user (D1) ClickHouse connections, host visibility for anonymous vs signed-in users, the "Test connection" error classifier and its docs links, or the "Try with sample ClickHouse" onboarding preset. Triggers: "cloud mode", "SaaS", "demo host", "welcome page", "setup page", "first-run", "add host error", "connection error", "read-only host", "hide hosts when signed in", "sample cluster", "sample ClickHouse", "try sample", "guest AI", "anonymous agent", "guest credits", "guest quota", "sign-in", "sign-up", "/auth.md", "chm auth", "auth/cli", "CLI login", "device login".
metadata.tags
saas, cloud, oss, self-hosted, onboarding, hosts, clerk, connection-errors, sample-cluster, guest-ai

chmonitor Cloud (SaaS) mode

One codebase, two products. dash.chmonitor.dev = Cloud; Docker/K8s/self-built Worker = self-hosted (OSS). The difference is runtime config behind one flag.

Paid self-host path: operators who already run ClickHouse buy a commercial license (yearly/lifetime, host count, honor system). Do not push them to Polar cloud seats. Do not add a license key to the OSS binary.

This is a project skill kept under .claude/skills/ (NOT .agents/skills/, which the build:skills registry scans for end-user AI-agent skills). Keep dev skills here so they never leak into the agent bundle.

Golden rule

Fail-closed to self-hosted. Unset/junk CHM_CLOUD_MODE / VITE_CLOUD_MODE → NOT cloud → OSS unchanged. Cloud behaviour is ADDITIVE only. Never gate a core monitoring feature behind cloud mode. (Mirrors lib/edition fail-open design.)

The flag

  • Resolver: apps/dashboard/src/lib/cloud/cloud-mode.ts
    • isCloudModeClient() — build-time, React/hooks (reads VITE_CLOUD_MODE).
    • isCloudModeServer(env) — runtime CHM_CLOUD_MODE wins over build-time.
    • parseCloudMode(v) — only 'true'|'1'|'cloud' (trim/case-insensitive) → true.
  • Build inline: vite.config.ts CLIENT_ENV + src/vite-env.d.ts. Each client VITE_* DERIVES from the canonical CHM_* (set the value once).
  • Single source of truth: apps/dashboard/.env.production (+ .env.preview overlay). It feeds BOTH the vite client build (CHM_BUILD_ENV=production|preview → build:production/build:preview) AND the Worker runtime [vars] (apps/dashboard/scripts/patch-wrangler-env.ts injects the non-VITE_ keys). wrangler.toml declares NO [vars] — never re-add one; edit .env.production.
  • Self-hosted uses the same names from apps/dashboard/.env.example (Docker env_file, Helm values.yaml). Secrets only via set-secrets.ts / K8s Secret.

Cloud mode is a BUILD-TIME contract (#2515). The client bundle only sees the baked-in VITE_CLOUD_MODE; it never reads runtime env. Booting a prebuilt OSS image with runtime CHM_DEPLOYMENT_MODE=cloud / CHM_CLOUD_MODE=true splits the product — server enforces cloud (demo guard) while the client renders OSS UI. Enable cloud by setting CHM_CLOUD_MODE before the build (so the VITE derivation runs), not only at runtime. Guard: detectCloudModeMismatch(env) → {server, clientBuild, mismatch}; /api/healthz warns and reports cloudMode on mismatch. The reverse (cloud build, runtime unset) is safe — fail-closed.

Behaviour

Self-hostedCloud
Env hostsreal, full accesssource:'demo', read-only
Anonymousenv hoststhe demo
Signed-inenv hostsdemo HIDDEN → own D1 connections; zero → welcome/setup
Agent (anon)Clerk-gated if access=authenticatedreachable on demo host via authorizeAgentApiRequest guest wrapper (not CHM_FEATURE_AGENT_ACCESS=public); daily cap 3 + RL 5/min; D1 guest:<ip-hash>; deploy ANYROUTER_API_KEY + anyrouter:anyrouter/free
CLI device login (CHM_DEVICE_LOGIN)off by default (auto); set true for device-only tokens when auth=none (trusted LAN)on when CHM_API_KEY_SECRET is set; /device needs Clerk session

Resolver: lib/auth/device-login-config.ts. Store: D1 or in-memory (lib/auth/device-code-store.ts). See docs/knowledge/standalone-cli.md.

CLI auth discovery: GET /api/v1/auth/cli (public) returns method none|device|api_key for chm auth login — no auth_mode in CLI config. Code: lib/auth/cli-auth-discovery.ts.

Welcome / setup page

components/host/first-run-empty-state.tsx renders 3 variants by (cloudMode, isSignedIn): cloud signed-in (Connect-your-host + Add-host dialog), cloud anon (sign-in + value prop), self-hosted (env-var guidance + browser add). Gate ClerkSignInButton behind isClerkEnabled().

Human vs agent auth URLs (#3092). /sign-in and /sign-up are human HTML pages (components/clerk/auth-page.tsx: Clerk modal CTA, or an explicit "use the dashboard Sign in control" fallback when Clerk is off). /login redirects to /sign-in. /auth.md is the agent-facing markdown document. agentDiscoveryHandler in start.ts must never rewrite the human auth paths to text/markdown — a cached markdown HIT is what made dash.chmonitor.dev/sign-in unusable for people.

Demo down (#3592). If the active host is source:'demo' and host-status fails, FirstRunGate shows DemoUnavailableBanner ("Demo temporarily unavailable" + Retry, components/host/demo-unavailable-banner.tsx). Demo-only via isDemoUnavailable; OSS/env hosts never see it. Don't add per-card demo-down handling.

Cloud signed-in welcome: connect a host immediately. There is no Polar plan picker and no dashboard /billing page. Public paid checkout is self-host licenses on chmonitor.dev/pricing → hooks.chmonitor.dev/checkout/license. Host/seat counts are not enforced. OSS fails open.

"Try with sample ClickHouse" preset — a DIFFERENT thing from the demo host above (server env-configured, cloud-only): a one-click preset any user (OSS or cloud signed-in) can add through the NORMAL add-host path, for the "must own a cluster to try it" barrier. Not shown to cloud anon visitors (they already get the automatic demo). components/connections/sample-preset.ts is the single constant (SAMPLE_CLUSTER_PRESET + isSampleClusterHost) — currently the public ClickHouse Playground (play.clickhouse.com/explorer, non-secret, DDL/INSERT rejected server-side); that shared demo also denies several system.* tables chmonitor needs (query_log, parts, merges, processes, replicas, mutations, disks, errors), so operational pages show their normal empty/error states against it — schema browsing, metrics/settings/functions, and SQL/AI chat work. add-host-dialog.tsx's initialPreset?: 'sample' must be set explicitly (incl. undefined) on every open — the dialog is reused, not remounted per-CTA. components/host/sample-cluster-banner.tsx is the dismissible "Connect your own cluster" convert nudge shown once the sample is connected. Full detail: docs/knowledge/cloud-saas-mode.md.

Show full SKILL.md (301 more words)Show less

Guest AI credits (Cloud only)

Anonymous Cloud visitors can chat on the demo host. Reachability is not CHM_FEATURE_AGENT_ACCESS=public (agent is operation: 'write'; Clerk public-read still 401s unsigned POSTs). authorizeAgentApiRequest allows unsigned Cloud + public-read on agent POST / models / config-check / followups only. UI: agent-auth-gate.tsx ensureAuthed() true for Cloud unsigned; OSS Clerk stays gated.

Guests bill the deploy ANYROUTER_API_KEY and default to anyrouter:anyrouter/free (pinned; auto routed guests to BYOK-only / out-of-quota models, #3578). Server strips BYOK apiKey, ignores mcpServers / user MCP, allowlists auto + free, hostId env/demo only. Conversations stay Clerk-only (local thread for unsigned Cloud).

They get a dedicated daily message cap (CHM_GUEST_AI_REQUESTS_PER_DAY, default 3) and a tighter per-identity rate limit (RATE_LIMIT_AGENT_GUEST_PER_MIN, default 5) so they cannot burn the shared AnyRouter key. Usage is stored in the existing D1 ai_usage_daily table under guest:<sha256-ip-prefix> — never the literal owner id guest. GET /api/v1/billing/usage returns a slim Guest payload for unsigned Cloud callers so the quota chip can render. OSS skips this (IP RL only, no daily gate). Helpers: lib/billing/guest-ai.ts. Gate: applyAiUsageGate in routes/api/v1/-agent/billing.ts. 402 reason: guest_daily_limit (sign in for more — no Polar jargon).

Connection-error help

lib/connection-errors.ts:

  • classifyConnectionError(raw) → {kind,title,explanation,fix,docsSlug,raw}. Kinds: host_not_allowed, invalid_url, auth_failed, access_denied, dns_error, connection_refused, tls_error, timeout, mixed_content, unknown. Add new patterns by extending RULES (first match wins, specific first).
  • extractConnectionErrorMessage(body) handles {error:string} (test route) AND {error:{message}} (shared validation builder).
  • Rendered by ConnectionErrorPanel in connection-form.tsx.
  • Docs page slug: guides/connection-errors (docs/content/guide/guides/connection-errors.mdx).

Build/test gotchas

  • apps/dashboard is NOT a root pnpm workspace member → cd apps/dashboard && pnpm install.
  • Build inside apps/dashboard: pnpm run build (vite + tsc --noEmit).
  • Tests: bun test src/lib/cloud src/lib/connection-errors.test.ts.
  • Full reference: docs/knowledge/cloud-saas-mode.md.

Keep this skill current

When you change cloud-mode behaviour, demo-host visibility, the welcome/setup page, human /sign-in vs agent /auth.md, per-user connections, the connection-error classifier, or guest-agent credits/rate-limits, UPDATE this file and docs/knowledge/cloud-saas-mode.md in the same change. See the "Auto-improve project skills" note in the root CLAUDE.md.

© chmonitor, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/cloud-saas-mode of chmonitor/chmonitor.

Open the folder on GitHubat commit fc39ef0

Compare with similar skills

Cloud SaaS Mode next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud SaaS Mode compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud SaaS Mode this skillchmonitor/chmonitor298—~2.5kAutomated safety check: NotesGPL-3.0
Funnelcake Deployment Workflowdivinevideo/divine-mobile265—~3.6kAutomated safety check: PassMPL-2.0
Tgf Server Devthkhxm/tgf128—~1.3kAutomated safety check: NotesMIT
Local Platform E2Ecomputesdk/benchmarks126—~3kAutomated safety check: NotesMIT
Multi Cluster API Data Mismatchdivinevideo/divine-mobile265—~1.3kAutomated safety check: PassMPL-2.0
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Funnelcake Deployment Workflow

    divinevideo/divine-mobile

    Deploy funnelcake (api + relay) to ANY environment (production, staging, poc) on GKE via ArgoCD.

    265 GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tgf Server Dev

    thkhxm/tgf

    基于 tgf v2(github.com/thkhxm/tgf/v2)用确定性的 tgfctl 工作流创建、验证和维护 Go 游戏服务器项目。

    128 GitHub stars~1.3k tokensUpdated 2 mo ago
    DatabasesAuto-check: notes
  • Local Platform E2E

    computesdk/benchmarks

    Stand up benchmarks-platform locally (Postgres + MinIO + ClickHouse in docker) and run a real @benchsdk/runner benchmark against it, with no cloud or provider credentials.

    126 GitHub stars~3k tokensUpdated today
    DatabasesAuto-check: notes
  • Multi Cluster API Data Mismatch

    divinevideo/divine-mobile

    Debug "API returns data that doesn't exist in database" when multiple Kubernetes clusters exist (production, staging, POC).

    265 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed

More from chmonitor/chmonitor

All 53 skills in this repo
  • Hyperframes Creative

    chmonitor/chmonitor

    Non-animation creative direction for HyperFrames videos. An agent skill from chmonitor/chmonitor.

    298 GitHub starsUsed in 5 repos~1.3k tokens
    Auto-check passed
  • Hyperframes Media

    chmonitor/chmonitor

    Audio and media assets for HyperFrames compositions, produced by one shared audio engine (scripts/audio.mjs) — multi-provider TTS (HeyGen / ElevenLabs / Kokoro local), background music + sound…

    298 GitHub starsUsed in 1 repo~2.8k tokens
    Auto-check: notes
  • Remotion To Hyperframes

    chmonitor/chmonitor

    Port an existing Remotion (React) composition to HyperFrames HTML.

    298 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Music To Video

    chmonitor/chmonitor

    A skill your agent uses when the user has a music track (an audio file, or a video to pull audio from) and wants a beat-synced HyperFrames video, calm to hard-hitting.

    298 GitHub starsUsed in 1 repo~4k tokens
    Auto-check: notes
  • Hyperframes Animation

    chmonitor/chmonitor

    All animation knowledge for HyperFrames — atomic motion rules, multi-phase scene blueprints, scene transitions, broader motion-design techniques, AND the seven runtime adapters (GSAP default, plus…

    298 GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • Faceless Explainer

    chmonitor/chmonitor

    turn arbitrary text — an article, notes, a topic, a brief — into a faceless explainer video, up to ~3 min (sweet spot 30-90s), where every visual is invented (typography, abstract graphics…

    298 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check: notes

Questions about Cloud SaaS Mode

What does Cloud SaaS Mode do?

Work on chmonitor's Cloud (SaaS) vs self-hosted (OSS) behaviour from ONE codebase. Cloud SaaS Mode is an agent skill from chmonitor/chmonitor. Work on chmonitor's Cloud (SaaS) vs self-hosted (OSS) behaviour from ONE codebase.

When should I use Cloud SaaS Mode?

Cloud SaaS Mode fits situations like: changing how dash.chmonitor.dev differs from Docker/K8s/OSS builds: the cloud-mode flag; public read-only demo hosts; the welcome/setup onboarding page; clickHouse connections.

How do I install Cloud SaaS Mode in Claude Code?

Run `npx skills add chmonitor/chmonitor --skill cloud-saas-mode -a claude-code`. Or copy the skill folder (.claude/skills/cloud-saas-mode in chmonitor/chmonitor) into .claude/skills/cloud-saas-mode in your project. Claude Code loads it when a task matches its description.

How do I install Cloud SaaS Mode in Codex?

Run `npx skills add chmonitor/chmonitor --skill cloud-saas-mode -a codex`. Or copy the skill folder (.claude/skills/cloud-saas-mode in chmonitor/chmonitor) into .agents/skills/cloud-saas-mode in your project. Codex loads it when a task matches its description.

Can I use Cloud SaaS Mode in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add chmonitor/chmonitor --skill cloud-saas-mode -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-saas-mode, .gemini/skills/cloud-saas-mode, .github/skills/cloud-saas-mode and .opencode/skills/cloud-saas-mode in your project.

What does Cloud SaaS Mode need to run?

Going by SKILL.md and its folder, Cloud SaaS Mode needs the command-line tools its instructions call (pnpm and bun) and credentials named ANYROUTER_API_KEY and CHM_API_KEY_SECRET. Our summary lists: Docker; A credential in ANYROUTER_API_KEY; A credential in CHM_API_KEY_SECRET.

Does Cloud SaaS Mode access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cloud SaaS Mode safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cloud SaaS Mode use?

Cloud SaaS Mode is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud SaaS Mode use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloud SaaS Mode?

Skills that share tags, products or a category with Cloud SaaS Mode: Funnelcake Deployment Workflow (divinevideo/divine-mobile, 265 stars), Tgf Server Dev (thkhxm/tgf, 128 stars), Local Platform E2E (computesdk/benchmarks, 126 stars) and Multi Cluster API Data Mismatch (divinevideo/divine-mobile, 265 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud SaaS Mode?

chmonitor (a GitHub organization) maintains it in chmonitor/chmonitor, which has 298 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 5, 2026.

Source: chmonitor/chmonitor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.