One description of your service. The right resources on each cloud.
Each environment is declared in ske.yml and turned into compute, data, queues and networking in your own account.
ske.yml
name: storefront
type: laravel
environments:
production:
network: aws-maingcp-main
region: us-east-1us-central1
memory: 1024
scheduler: true
queues:
default:
timeout: 60
domains:
- shop.example.comProvisions in your account
- ComputeCompute
- LambdaCloud Run
- ImagesImages
- ECRArtifact Registry
- QueuesQueues
- SQSCloud Tasks
- ScheduleSchedule
- EventBridgeCloud Scheduler
- LogsLogs
- CloudWatchCloud Logging
- StackNetwork
- CloudFormationVPC connector
Google Cloud is in early access.
Engineers keep a workflow they can script.
Deploys, rollbacks and secrets run from one CLI, so pipelines and people follow the same process. Everything else is in the dashboard and the API.
curl -fsSL https://get.ske.io | sh- 1
Connect
Sign in, then link an AWS role or a GCP service account from the dashboard.
ske login - 2
Describe
Writes ske.yml with the runtime, environments, memory, queues and domains. It lives in your repository.
ske init - 3
Configure
Values are prompted, stored in your account and injected at startup. Never committed.
ske secret set STRIPE_SECRET --env production - 4
Ship
Builds the image, pushes it to your registry, runs deploy hooks and switches traffic.
ske deploy --env production - 5
Undo
Points traffic back at the previous release. No rebuild.
ske rollback
Everything included, grouped the way you evaluate it.
Governance and access
Control who can see, change and ship each part of your estate, and prove it later.
- Organizations and workspaces
- Group projects and cloud accounts by team, business unit or client, each with its own access.
- Roles at every level
- Grant roles on the organization, a workspace, a project or a single environment. Teams inherit their roles.
- Custom roles
- Compose roles from granular permissions, from viewing logs to deploying to protected environments.
- Protected environments
- Production deploys require a dedicated permission and an explicit confirmation.
- Scoped API tokens
- Tokens are limited to chosen projects or environments, cannot exceed their creator, and expire within a year.
- Audit log
- Every change to deployments, environments, roles and infrastructure, with before and after values.
Deployment
Releases are immutable images in your own registry, so every deploy is repeatable and reversible.
- One-command deploys
- The CLI builds the image, pushes it to ECR or Artifact Registry, runs deploy hooks and switches traffic.
- Instant rollback
- Point traffic at any previous release in seconds. No rebuild, no waiting on CI.
- Maintenance mode
- Take an environment offline and back through a redeployment, which suits serverless compute.
- Configuration as code
- Runtime, environments, memory, queues and domains live in ske.yml and go through code review.
Infrastructure
The services your application depends on, created in your account and sized per environment.
- Networks
- A VPC with private subnets and optional NAT, shared by the environments you attach to it.
- Databases
- MySQL and Postgres on RDS, Aurora or Cloud SQL, reachable only from your private network.
- Caches
- Redis-compatible caches on ElastiCache or Memorystore, including serverless options on AWS.
- Queues and schedules
- Workers on SQS or Cloud Tasks; the scheduler runs on EventBridge or Cloud Scheduler.
- Custom domains
- Attach your own hostnames per environment with managed TLS certificates.
- Secrets
- Stored in SSM Parameter Store or Secret Manager in your account and injected at startup.
Operations
Day-two tooling for running services, so on-call engineers rarely need the cloud console.
- Logs and metrics
- Search application logs and follow request, error and duration metrics per environment.
- Queue control
- Pause and resume individual queues during incidents or migrations.
- Warmup
- Pre-warm instances before a launch or a traffic spike to avoid cold starts.
- Remote commands
- Run one-off maintenance commands against an environment, gated by their own permission.
- Diagnostics
- Health checks that verify cloud access, configuration and connectivity for an environment.
- Notifications
- Deployment and incident alerts to Slack, Microsoft Teams, email or any webhook.
The services it uses on each cloud.
Native managed services only, so your cloud team already knows how to monitor, secure and support them.
Compute and delivery
Data
Operations
Bring serverless to your platform, on your terms.
Tell us about your cloud setup and the services you want to move. We will walk your team through a pilot in your own account.