Certified local mode: managed on-device model with verified setup and egress guard
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- ollama, typescript
- Domain
- ai, cli, documentation, security
Research direction
Start by tracing the altimate local CLI entry point, the ALTIMATE_TOOL_RETRIEVAL context-compaction path, and the first-run TUI picker. Review how web tools (websearch, webfetch, and codesearch) permissions are applied, then define the registry, verified setup, certification probes, reversible egress rules, and documentation needed for the proposed first cut.
Written by the indexing model from the issue text.
Description
Data teams in compliance-bound environments (finance, healthcare) cannot send warehouse schemas, query results, or dbt project contents to cloud LLM providers — today that rules altimate-code out for them entirely, or forces a hand-rolled Ollama/LM Studio setup with no verification that the endpoint actually works for agent workloads (tool calls, long-context prefill, reasoning renders).
Proposal: a managed local mode — altimate local — that makes the local path a first-class, verified experience:
- one command: hardware detection → pinned, SHA-256-verified model + runtime download → server lifecycle on
127.0.0.1→ certification probes (tool-call round trip, reasoning render, 8K prefill) that must pass before any config is touched - a model registry (multi-model by design;
--model <id>,altimate local models) - an egress guard: wiring local mode adds
askpermission rules for the web tools (websearch/webfetch/codesearch) so a local-first session reaches the internet only with per-step approval; reversible, never overwrites user-set permissions - context diet for small-context local models (skill-listing compaction under the existing
ALTIMATE_TOOL_RETRIEVALflag) - first-run TUI picker row + docs integration so the option is discoverable
Out of scope for the first cut (tracked as follow-ups): Linux AMD/Intel GPU auto-detection (runtime already works via Vulkan), native-Windows certification, live prefill progress in the TUI.
- Dominant language
- TypeScript
- Stars
- 813
- Forks
- 134
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 63
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from AltimateAI/altimate-code
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
AltimateAI/altimate-code#1323 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
AltimateAI/altimate-code#1288 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
AltimateAI/altimate-code#1285 ·
-
privacy: Altimate Base consent dialog no longer discloses persistent per-installation identifier Open
Difficulty 1/5 Under an hour Newbie friendliness 88/100
AltimateAI/altimate-code#1284 ·
-
Difficulty 2/5 Under an hour Newbie friendliness 72/100
AltimateAI/altimate-code#1283 ·
All issues in AltimateAI/altimate-code
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
bug v2
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
modelcontextprotocol/inspector#2458 · 1 comment ·
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
railmapgen/rmp-gallery#4068 ·
-
Mend: dependency security vulnerability status: needs triage 🕵️♀️
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
carbon-design-system/ibm-products#9907 ·