MVP 1.0 · Local-first desktop

Connect. Capture.
Generate runbooks.

Lorium brings SSH servers, Kubernetes clusters, encrypted secrets, terminal sessions, and AI runbook generation into one private workspace.

MVP scope: SSH, Kubernetes, encrypted vault, session memory, Markdown runbooks.

Lorium
Local workspace
Search your workspace ⌘ K
Local
prod-api-01
production-cluster
Split
Last login: today from 10.0.1.24
ubuntu@prod-api-01:~$ kubectl get pods -n payments
NAME            READY  STATUS   RESTARTS  AGE
payments-api-7d8f  1/1    Running  0         3d
payments-api-8a1c  1/1    Running  0         3d
payments-db-0      1/1    Running  0         12d
ubuntu@prod-api-01:~$
Session capture on
Context savedEncrypted on this device
Runbook ready7 verified steps
Core functionality in the MVP
›_ SSH & local shell Kubernetes contexts # Encrypted vault AI runbooks
MVP workflow

The core loop is simple:
connect, work, keep the knowledge.

Lorium focuses the first release on the path engineers repeat every day: open infrastructure, run commands, capture what happened, and save a useful runbook.

01

Connect to infrastructure

Open local, SSH, and Kubernetes terminal sessions from infrastructure cards with tags, links, and credentials nearby.

Pprod-api-01Production · SSH
Kcore-clusterKubernetes · EKS
Sstaging-dbStaging · SSH
03

Generate and reuse runbooks

Create editable Markdown runbooks and incident notes from selected session steps, then find them offline later.

RUNBOOK

Restart the payments API

Saved to your notes vault
Core workflow

One product path from production access to reusable knowledge.

The MVP keeps the operational loop tight: choose a target, work in the terminal, capture the useful trail, and save the generated document beside your notes.

Infrastructure
Production 3
PPROD

prod-api-01

ubuntu@10.10.10.20

apiprimary
Online
KPROD

core-cluster

Amazon EKS · eu-west-1

kubernetescore
Healthy
DPROD

prod-db-01

ubuntu@10.10.10.40

postgres
Online
Pprod-api-01Infrastructure card
Host
10.10.10.20:22
Secrets
2 linked
Last used
12m ago
Session memory
09:41

Connected to production

SSH · prod-api-01 · ubuntu

09:43

Checked API health

systemctl status payments-api
09:46

Found restart loop in logs

Secret-like values redacted before capture

3 meaningful steps captured
Runbook search

Restart the payments API

Safely restart the service and verify pod health…

runbooks / production · 2 days ago

Payments API latency incident

Diagnosis notes from the May 14 incident…

incidents / payments · 1 month ago

Rotate payments database credentials

Credential rotation procedure and verification…

runbooks / security · 3 months ago
MVP feature set

The first release is built around the daily infra workflow.

Terminal workspace

Local, SSH, and Kubernetes sessions with tabs, split view, search, and quick recovery.

Localprod-api-01 core-cluster +

ubuntu@prod-api-01:~$ docker compose ps

NAME       STATUS      PORTS

api        Up 3 days   0.0.0.0:8080

worker     Up 3 days   —

Encrypted secrets vault

Store credentials locally and link them to the servers or clusters that use them.

DBpostgres-passwordDatabase••••••••
APIgrafana-tokenToken••••••••
SSHproduction-keySSH key••••••••

Universal search

Find servers, clusters, secrets, notes, and generated runbooks instantly with Cmd+K.

prodESC
SERVERS

Pprod-api-01Production

Dprod-db-01Production

Runbooks and notes

Save generated Markdown runbooks into the local notes vault and keep them linked to infrastructure context.

Private by default

Session capture stays under your control.

Lorium is local-first by design. Servers, notes, terminal context, provider keys, and secrets live on your device unless you explicitly choose an AI provider for generation.

  • Local data storageSQLite and Markdown files live on your device.
  • Strong vault encryptionArgon2id key derivation with AES-256-GCM.
  • AI on your termsUse a cloud provider or an OpenAI-compatible local endpoint.
  • Transparent capturePause capture, edit the transcript, or remove steps before generation.
Create your secure account
Encrypted locally AES-256-GCM
Notes vault
Secrets
Session history
Provider keys
Your workspace, your control

Start locally.
Scale when you need it.

Begin with a private local workspace, then connect billing and team features only when they become useful. Your operational data does not become a condition of your subscription.

Lorium workspacePrivate by default

Your terminal memory, runbooks and infrastructure context stay local and available offline.

Local-firstEncryptedOffline-ready
One account for billing and teamsFree · Pro · Team · Corporate
account

Turn real terminal work
into reusable runbooks.

Connect to infrastructure, capture the session, and save the answer in one private workspace.