Dashboard
StealthVault live status · App config · Quick actions
| Environment | URL | Branch | Status |
|---|---|---|---|
| Production | vaults.codes | main |
● Live |
| Staging | dev.vaults.codes | dev |
● Staging |
| GitHub | Mohan454522/stealthvault | main, dev |
● Public |
App Settings
These are synced to localStorage on the same domain. Changing them here changes them in StealthVault too.
Deploy / Release
How to get code from dev to production. No terminal needed once you set this up.
CI — Validate on every push
Runs automatically when you push to dev or main. Checks file existence, JS syntax, critical functions. Takes ~10 seconds.
Promote dev → main (Release)
Manually triggered. You fill in the version number and release notes, choose dry_run=no, and it merges dev into main + creates a GitHub Release. Cloudflare then auto-deploys to vaults.codes.
Cloudflare Pages — Auto deploy
Every push to dev → dev.vaults.codes (within 30s). Every push to main → vaults.codes (within 30s). No action required.
git push origin dev
Fill in: version (e.g. v1.2.0), release notes, dry_run=no
| What | How companies do it | StealthVault version |
|---|---|---|
| Branches | main (prod), staging, feature/* branches | main + dev |
| Code review | Pull Request reviewed by 2 engineers before merge | You are the engineer — just test on staging |
| CI | Lint, unit tests, integration tests, build, security scan | File check + JS syntax check |
| Deploy | Jenkins/GitLab CI/AWS CodeDeploy builds Docker, pushes to Kubernetes | Cloudflare Pages (zero config, free) |
| Versioning | Semantic versioning: v1.0.0, v1.1.0, v2.0.0 | Same — tracked in GitHub Releases |
| Rollback | Re-deploy previous container image | Cloudflare Pages → Deployments → click previous build → Rollback |
| Monitoring | Datadog, Sentry, PagerDuty | Cloudflare Analytics (free, auto) |
| Secrets | AWS Secrets Manager, Vault by HashiCorp | No server = no secrets needed |
Branches & Git Workflow
How StealthVault is structured in git and what each branch means.
| Version | When to use | Examples |
|---|---|---|
| v1.0.0 → v1.0.1 | Patch — bug fix only | Fix progress bar sticking, fix crash on large files |
| v1.0.0 → v1.1.0 | Minor — new feature, backward compatible | Add gallery type filter, add swipe gestures |
| v1.0.0 → v2.0.0 | Major — breaking change | Vault format change, encryption algorithm change |
53564C540006) are always compatible.
Vault Format v6
Complete specification of the StealthVault v6 binary format. Use this to manually recover files if the app is ever unavailable.
| Parameter | Value |
|---|---|
| Algorithm | PBKDF2-SHA-256 |
| Iterations | 310,000 rounds |
| Salt | 16 bytes random per vault file |
| Output | 256-bit AES key |
| Encryption | AES-256-GCM (authenticated) |
| IV per chunk | 12 bytes random |
| Auth tag | 16 bytes (included in CHUNK_ENC) |
| Standard | Web Crypto API (SubtleCrypto) — browser-native, no dependencies |
The file looks like a normal JPEG. To verify it's a StealthVault v6 file:
- Open the file in a hex editor
- Read the last 8 bytes → must be
DE AD 56 36 00 00 DE AD - Read bytes at
[fileSize - 20]for 8 bytes → COVER_SIZE - Read bytes at
[fileSize - 12]for 4 bytes → HEADER_SIZE - Jump to
[COVER_SIZE]and read 8 bytes → must be53 56 4C 54 00 06 00 00
If all checks pass: it's a StealthVault v6 file. The cover image is bytes 0 to COVER_SIZE-1.
Recovery Guide
How to recover your files even if StealthVault.codes is down and you only have your vault images.
→ Download ZIP → Extract → Open index.html in browser
- Your vault images (the encrypted JPEG files)
- Your passphrase(s) — written down or in a password manager
- This URL: github.com/Mohan454522/stealthvault
- Note: "Open index.html in Chrome. File picker → select vault image → enter passphrase → Unlock."