
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
@tdk-landscape/tdk-cli-core
Advanced tools
English | 简体中文 | 繁體中文 | 日本語 | 한국어
TDK CLI starts your services on your laptop. It is not a deploy and not a Compose file: define each service in service.json, then run tdk up. No Kubernetes is needed on the machine.
Stability: 1.x local dev. Write service.json; TDK generates the local runtime files. See what TDK writes and how to check for drift. Core CLI is MIT and needs no key. Premium is optional.
Docker runs the containers. Tilt watches services and live-updates containers while you code. TDK CLI writes the configuration Tilt uses. Production deployment stays with Helm, Argo CD, or Kustomize.
Website · Quickstart · Examples · Awesome TDK · Demo · Report a bug
No teams are listed yet. Be the first: tell us you use TDK or add a row to ADOPTERS.md.
mkdir shop && cd shop
tdk project --yes
tdk resource orders-api --type backend --stack shop --yes
tdk up shop
curl http://api.shop.localhost/api/orders-api/health
Scaffolding a backend and frontend, then listing the stack.
You maintain service.json; TDK generates the local runtime files. A frontend such as services/store/storefront-web has files like these after generation:
services/store/storefront-web/
├── service.json # your service definition
└── .autogenerated/ # TDK writes these files
├── nginx.autogenerated.conf # serves the build and routes API requests
├── Dockerfile.app.autogenerated # local app image
├── .env.frontend.autogenerated # local frontend environment
├── vite.config.frontend.autogenerated.ts
├── tsconfig.autogenerated.json
└── api-client.ts # generated API client
You do not need to write the nginx config, Dockerfile, or a docker-compose.yml for this local stack. tdk up uses Docker and Tilt to start it. The generated-files guide lists the other outputs and explains how regeneration and drift checks work.

If Helm, Compose, or your existing Tilt setup already gives you a working local environment, keep using it. TDK CLI is for engineers managing several services who want a clear local service contract and one command to start the stack.
See how TDK CLI works alongside Helm, the service schema, and the project configuration schema.
Install the CLI from npm (requires Node.js 22.12+) or use the prebuilt binary (no Node.js or Bun required):
npm install -g @tdk-landscape/tdk-cli-core
# or install the prebuilt binary
curl -fsSL https://tdk-landscape.github.io/install.sh | sh
tdk up shop --dry-run previews selected local services and URLs before starting containers. The default starter is Bun/TypeScript; TDK's core role is running local containers through Docker + Tilt, not providing a Node.js application framework. See the one-backend example.
service.json manifests and generated local configuration.TDK development began on 21 April 2026. The archived, read-only tdk-landscape/tdk
repository records its first commit
("Initial commit: TDK specs, generators, CLI, and standards") from that day. A separate tdk-cli history spanning 21 April to
18 September 2026 was imported into this repository as 306 filtered
commits. Those commits are now ancestors of main; the import did not change the source tree.
This tdk-cli-core repository was created on 19 September 2026, and the @tdk-landscape/tdk-cli-core npm package was first
published on 21 September 2026. Those dates describe the current repository and package, not the start of TDK development.
For the local runtime, install Docker (Desktop, OrbStack, or Colima; Engine 25+, Compose 2.20+) and Tilt. Bun 1.2+ is used by the default generated services. TDK selects host ports from bounded fallback ranges for HTTP, HTTPS, and Postgres; set TDK_HTTP_PORT, TDK_HTTPS_PORT, or TDK_POSTGRES_PORT to override them. TDK supports macOS, Linux, and Windows through WSL2 Ubuntu; native Windows supports CLI inspection only. Run tdk doctor to check local readiness (supports --no-ping to skip service health checks and --ping-timeout <ms>). See WSL2 setup.
On native Windows, tdk --version, tdk doctor, and tdk up --dry-run are inspect-only commands. tdk up exits 2 with “Landscape startup needs Ubuntu on WSL2. Native Windows is inspect-only.”
| Capability | Free | Premium |
|---|---|---|
tdk up, scaffold, Traefik, Postgres, Tilt live update, golden layers | yes | yes |
| Verdaccio, DDD scaffold, Sablier idle stop | no | key |
| Playwright, C4, AGENTS.md | free if generated in-repo | only if the implementation is downloaded with a key |
Core stays free. Premium is a separate key for the extras above; no key required to run tdk up.
Ecosystem map: examples, articles, related tools, and notes live in awesome-tdk-framework. Star this repo (tdk-cli-core) if the CLI is what you run; use the awesome list to browse the rest.
Contributions are welcome. Start with CONTRIBUTING.md and the contributor guide. Report security issues using SECURITY.md.
TDK is MIT-licensed; see LICENSE. The license boundary says which code is MIT and which is downloaded with a key.
Project governance: GOVERNANCE.md, MAINTAINERS.md, ADOPTERS.md.
Use tdk ui to inspect stacks and resources. Arrow keys or j/k move the
selection; g/G or Home/End jump to the first/last item, and PageUp/PageDown
move one visible page. / searches; navigation letters remain search text
while searching. The selected row stays visible when the terminal is resized.
FAQs
TDK CLI — start services on your laptop.
The npm package @tdk-landscape/tdk-cli-core receives a total of 6,377 weekly downloads. As such, @tdk-landscape/tdk-cli-core popularity was classified as popular.
We found that @tdk-landscape/tdk-cli-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.