Open Source · Desktop
Luman
macOS storage intelligence — understand disk use, reclaim space safely, and see why every cleanup is safe.
Overview
Offline-first disk cleanup for developers and power users — scans are read-only, cleanup is always explicit, and the UI never owns the business rules.
The challenge
Disk-cleanup tools either hide why a file is safe to remove or make deletion too easy. Developers need an explanation for every recommendation, a dry-run default, and a hard line between scanning and changing the filesystem.
The solution
A Tauri v2 desktop app with a React + TypeScript UI, Rust native shell, and SQLite persistence. Scans are read-only; cleanup is a separate, confirmed path. Business rules live in domain and application packages, never in the UI. A single safety gate evaluates every destructive plan fail-closed.
What we delivered
- Tauri v2 + React 18 + TypeScript + Vite desktop shell with Zustand state and theme routing
- Domain models and service contracts (`VolumeService`, `ScanEngine`, `SafetyGate`, repositories) in a pnpm workspace (`@luman/core`, `@luman/domain`, `@luman/scanner`, `@luman/cleanup`)
- Event bus for scan progress and results; cleanup events declared so they cannot fire as commands
- PathGuard + protected-path classification; SQLite via `tauri-plugin-sql`
- Plugin SDK contracts, Vitest unit/integration tests, and Playwright E2E
Architecture
UI (React) → Application (services, event bus, safety gate)
→ Domain (Scan, Finding, CleanupAction)
→ Infrastructure (scanner, cleanup, SQLite, filesystem port)Key engineering decisions
- Strict layered packages so the UI cannot touch the filesystem or own cleanup rules
- Fail-closed safety gate — omitted mode is dry-run; execute is never the default
- Read-only filesystem port so a scanner cannot delete even by accident
- SQLite for scan history and settings; event bus payloads stay serializable across Tauri IPC
Tech stack
Engagement
2026 · Creator & Lead Engineer · Open source
Results
A complete open-source macOS storage app with a safety architecture that keeps scanning and cleanup on opposite sides of a confirmation boundary.
Lessons learned
- For destructive desktop tools, make the unsafe operation unrepresentable on the scan path — a type and a port beat a comment that says “don’t delete.”
Have a hard problem like this?
Let's talk about what you're building.