Shellaro Download

Where Shellaro keeps things

Shellaro separates the application (replaced by every update) from your data (never touched by an update or an uninstall unless you ask for it).

Application files

WhatWhere
Program (installer, per user, no admin rights)%LOCALAPPDATA%\Shellaro (shellaro.exe, uninstall.exe, resources such as the bundled Marketplace)
Start menu shortcut%APPDATA%\Microsoft\Windows\Start Menu\Programs\Shellaro\Shellaro.lnk; a desktop shortcut if chosen on the installer's last page (passive and silent installs always create it)
Uninstall entryHKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Shellaro

An update (Restart to Update or a newer installer) replaces this folder only.

Your data

Everything below is in the data folder, %APPDATA%\com.shellaro.app (for tests and portable use it can be moved with the SHELLARO_CONFIG_DIR environment variable). Settings > Help & About shows the folder in use.

File / folderContentsSecrets?
sessions.jsonSaved sessions and groupsNo (passwords and passphrases are in Credential Manager)
known_hostsHost keys you trusted (OpenSSH format)No
preferences.jsonApp preferences (theme, terminal, safety mode, keybindings, update channel, ...). The WebView keeps a copy; this file is used when that copy is missingNo
app.jsonFirst-run state: whether Getting Started was completed and which version of itNo
workspace.jsonOpen tabs and layout, restored at the next startNo; SSH tabs are restored disconnected
history.json, runbooks.json, safety.json, tunnels.jsonCommand history, runbooks, safety exceptions, tunnel definitionsNo
external.jsonOptional AI settings (provider, endpoint, model, what may be shared)No (API keys are in Credential Manager)
extensions.jsonConsents for extension background commandsNo
labs.jsonThe running lab: target, progress, hints opened, timesNo
extensions\registry.json (installed extensions and the permissions you approved), installed\<id>\<version>\, storage\<id>.json (each extension's own data), inbox\ (packages from the CLI), downloads\, optional trusted-keys.jsonExtension storage is whatever an extension saves
local-cluster\The local Kubernetes cluster: cluster.json, kubectl.bin, and id_ed25519, the SSH key for the cluster's own local containerid_ed25519 is a private key that only opens the local container; it never leaves the computer
logs\shellaro.log and up to three older files (1 MB each), redactedNo
backups\<time>-<reason>\Copies made before an import replaces dataSame as the files copied

Credentials (session passwords and key passphrases, AI API keys) are only in Windows Credential Manager: targets Shellaro/<session id>/<user>/password|passphrase and Shellaro/external/ai/<provider>. They are never written to the data folder, the workspace state, a log, an export or a support bundle.

WebView profile: %LOCALAPPDATA%\com.shellaro.app\EBWebView (WebView2's cache and the page's local storage, which holds the first copy of the preferences). Deleting it loses nothing: preferences come back from preferences.json.

Updates and upgrades

Uninstall

Settings and data stay unless you tick Delete the application data in the uninstaller, which removes %APPDATA%\com.shellaro.app and %LOCALAPPDATA%\com.shellaro.app. Credential Manager entries remain in both cases; remove them in Control Panel > Credential Manager > Windows Credentials (entries starting with Shellaro/), or use Forget saved secrets on a session before uninstalling.

Diagnostics

The log (logs\shellaro.log) records starts, update checks and their results, failed connections, extension failures, lab and cluster failures and uncaught errors. Before a line is written, passwords, passphrases, tokens, API keys, Authorization values and private key blocks are removed and the Windows user folder is shown as %USERPROFILE%. Host and user names that appear in error messages are kept.

Settings > Help & About: