Graft

skssmd·skssmd.Graft

A high-performance, zero-overhead deployment engine that extends the Docker Compose workflow to cloud infrastructure via SSH

A high-performance, zero-overhead deployment engine that extends the Docker Compose workflow to cloud infrastructure via SSH. Graft enables native remote management of AWS, GCP, and VPS instances with no agent installs or server-side overhead required. With V2.0 Graft is now optimized for git and github actions ci/cd flow

winget install --id skssmd.Graft --exact --source winget

Latest 2.5.9·September 8, 2026

Release Notes
  • Service Scaling: Scale any service to N replicas with [graft scale ] — Traefik load balances automatically. Scale persists through deploys.
  • PSQL Passthrough: Full psql passthrough with env-aware auto-connect. Supports all native psql flags (-c, -f, -t, etc.).
  • Isolated DB Credentials (Security): Each database gets a dedicated Postgres user and password. Admin credentials never leak to project secrets.
  • Per-Environment Database Linking: Database auto-linked per environment. [graft psql] connects to the right db for the current env.
  • Unified DB Init: Initialize databases from project scope, host scope [graft host db], or registry scope [graft -r db]. All paths prompt to link with overwrite protection.
  • SSH Database Tunnel: [graft db serve :port] tunnels remote Postgres to localhost via SSH for local dev tools. No public port exposure.
  • Generic Service Tunnel: [graft host tunnel :port] tunnels any Docker container to localhost. Auto-detects exposed ports.
  • SSH Connection Reliability: Multiple concurrent sessions and tunnels no longer hang. The liveness probe, SSH handshake and authentication, channel opens, and SFTP startup are all bounded by timeouts, so a half-dead connection fails fast and self-heals instead of blocking forever.
  • Faster Connections: SFTP starts only when a command actually transfers files, and tunnels no longer spend a network round trip probing liveness before each forwarded connection.
  • known_hosts Correctness (Security): Non-default ports are recorded in the format the lookup uses, so repeat connections stop appending duplicates. An unreadable known_hosts is reported instead of silently skipping host key verification.
  • Environment Listing: [graft env ls] shows all environments with registry, domain, and mode.
  • Graft SSH Key: Manage SSH keys with [graft pub] and rotate with [graft pub rollout].
  • Cloudflare API Integration: Automated DNS zone mapping based on Traefik host labels.
  • Cloudflare Zone Registry: Manage multiple Cloudflare accounts and zones with an interactive selection menu.
  • Database Backup Automation: Backup infrastructure databases to S3/R2 (Experimental).
  • Rollback to versions: Rollback and revert changes to previous deployments.
  • Docker Passthrough Commands: Execute docker commands on remote hosts or registries via Graft.
  • Optimized for Git and GitHub Actions CI/CD flows.
  • Multi-environment support with separate configs, workflows, and DNS.
  • Webhook detection and error handling.

Installer type: zip

arm64—2daa992903c2082ec511474620e737f84b496e35649c21fbff4dd3226babb769
x64—6af3519ebbe927b8999c0dc132889bbcc5146bae2902d0b00bc2eec625decd5c

Details

Homepage
https://github.com/the-graft-project/graft
License
MIT
Publisher
skssmd
Support
https://github.com/skssmd/Graft/issues
Copyright
Copyright (c) 2025 skssmd
Moniker
Graft

Tags

graftdeploymentdevopsdev-opseasy-deploymentdocker-composedockersshhostingcloud

Older versions (16)

2.5.7
arm64—4d48b3c0f76f49286e36516a6bd5338a01114e41b0789d952acc02a38e26d172
x64—c4ac29e258925e493e464495e2ef09b33c8a8070fe87eded649a119c01eea984
2.5.5
x64—0c1690dd86bfa1c11b17ca1e68a6625e9aaff0cfd94bc3cf82fcf7bf3faabadf
arm64—35a04d8dc5188698f1e1befd5f9e3d4805f9ae0e68f85718c9be305076dd529e
2.5.4
arm64—de970dba0e2fe535c6733af10604de4c44f4853f03c8666ca9103ff139f3627e
x64—4328e34b801789894beb11cde0cfe5dec45d02b03710fe1185b01c23c4eb4667
2.5.2
x64—411585b6bfd0b507cf4d56c5045d084f81d8c6d3ddce4c8ab018ede300c3a096
arm64—45a8d27d9da0b8b5c12ae886465e7377ae586b5d5e365cb548cf13932fa380e6
2.5.1
arm64—bd6e9da12363a6a7d344bd2f52b7c1266ed5e4811fac9a261ec0cab92cca78de
x64—883775e42472091ebb6561a5cb62696f9db4bd35df7cc5c20d899dbe881e6ce2
2.4.9
arm64—f7909c5ed2725fa7f7a13e8c01d61bbed8498b5251b69a127ed0dc4ef61c8c5f
x64—63d26e5792a852fab1ee9e09085f6a5c6fa6048653a6f0f5dab8d13b927c78a8
2.4.8
arm64—2dfdccc8169b387fb1ed5c121f4199c22481fe56574c367c0dec013e90f1f0e0
x64—6a92747dd5272379a368b1a6dd593be475eb86e93fe4d2a8e27a9c5481809acf
2.4.6
x64—6769df2b06b608f66144d078d6c76b5c696009d306de846fc0d4341b80649b00
arm64—ee1d7e437a2b74b49c42a92b8b45b6098c53b35015c89cd865ec91a085d4cf67
2.4.2
arm64—03856e4e8db093b843fb162b4a6e254a2201701c384e75495431ac15d892477e
x64—1a73643ba82b134ca93f3e1aad7819b7140df782cd7a19be2fffee04413c66dd
2.3.3
arm64—ed1c7a9e5f5c52302962b00da84165176e77ffc782df00fe191f509985c9e63c
x64—145486f29591aa3ec5b7c8eeb49a92416ad3cc85a79d8da2ff6c12d56db011a7
2.3.2
arm64—a03922d685db8288e3ce7de01f93d0cb3da6f5918a8b7690c03e3da58707f0ef
x64—0a5779c4ecc57674a3d434268a24910239a04a1aa9e5f597d1340875ba1de338
2.2.1
x64—E74DCA499729D047FF8791E28DD36B5E99506AF068071F19647C868FFF4AC4BE
2.1.3
x64—A45C821096E82B5B5BECE99639A2C2828FBD67E0387AF4AB562F088909FFE8A3
2.1.2
x64—8834993A5D7B104B8A0C126B5726B71F4E3CAC2796755CE58FEDC680F6F3FC2E
2.1.1
x64—7F1A66D6E54E1C741173BD477C7BE0FD4355C213AFA231CCC18E622A0A1837A8
2.0.0
x64—F279FEC992120DDA3FFBF47AE18D423A223A897ED321E3AE0DB8EF8E80EC75E6