Skip to content

One description of your service. The right resources on each cloud.

Each environment is declared in ske.yml and turned into compute, data, queues and networking in your own account.

ske.yml

name: storefront
type: laravel

environments:
  production:
    network: aws-maingcp-main
    region: us-east-1us-central1
    memory: 1024
    scheduler: true
    queues:
      default:
        timeout: 60
    domains:
      - shop.example.com

Provisions in your account

ComputeCompute
LambdaCloud Run
ImagesImages
ECRArtifact Registry
QueuesQueues
SQSCloud Tasks
ScheduleSchedule
EventBridgeCloud Scheduler
LogsLogs
CloudWatchCloud Logging
StackNetwork
CloudFormationVPC connector

Google Cloud is in early access.

Engineers keep a workflow they can script.

Deploys, rollbacks and secrets run from one CLI, so pipelines and people follow the same process. Everything else is in the dashboard and the API.

curl -fsSL https://get.ske.io | sh
  1. 1

    Connect

    Sign in, then link an AWS role or a GCP service account from the dashboard.

    ske login
  2. 2

    Describe

    Writes ske.yml with the runtime, environments, memory, queues and domains. It lives in your repository.

    ske init
  3. 3

    Configure

    Values are prompted, stored in your account and injected at startup. Never committed.

    ske secret set STRIPE_SECRET --env production
  4. 4

    Ship

    Builds the image, pushes it to your registry, runs deploy hooks and switches traffic.

    ske deploy --env production
  5. 5

    Undo

    Points traffic back at the previous release. No rebuild.

    ske rollback

Everything included, grouped the way you evaluate it.

Governance and access

Control who can see, change and ship each part of your estate, and prove it later.

Organizations and workspaces
Group projects and cloud accounts by team, business unit or client, each with its own access.
Roles at every level
Grant roles on the organization, a workspace, a project or a single environment. Teams inherit their roles.
Custom roles
Compose roles from granular permissions, from viewing logs to deploying to protected environments.
Protected environments
Production deploys require a dedicated permission and an explicit confirmation.
Scoped API tokens
Tokens are limited to chosen projects or environments, cannot exceed their creator, and expire within a year.
Audit log
Every change to deployments, environments, roles and infrastructure, with before and after values.

Deployment

Releases are immutable images in your own registry, so every deploy is repeatable and reversible.

One-command deploys
The CLI builds the image, pushes it to ECR or Artifact Registry, runs deploy hooks and switches traffic.
Instant rollback
Point traffic at any previous release in seconds. No rebuild, no waiting on CI.
Maintenance mode
Take an environment offline and back through a redeployment, which suits serverless compute.
Configuration as code
Runtime, environments, memory, queues and domains live in ske.yml and go through code review.

Infrastructure

The services your application depends on, created in your account and sized per environment.

Networks
A VPC with private subnets and optional NAT, shared by the environments you attach to it.
Databases
MySQL and Postgres on RDS, Aurora or Cloud SQL, reachable only from your private network.
Caches
Redis-compatible caches on ElastiCache or Memorystore, including serverless options on AWS.
Queues and schedules
Workers on SQS or Cloud Tasks; the scheduler runs on EventBridge or Cloud Scheduler.
Custom domains
Attach your own hostnames per environment with managed TLS certificates.
Secrets
Stored in SSM Parameter Store or Secret Manager in your account and injected at startup.

Operations

Day-two tooling for running services, so on-call engineers rarely need the cloud console.

Logs and metrics
Search application logs and follow request, error and duration metrics per environment.
Queue control
Pause and resume individual queues during incidents or migrations.
Warmup
Pre-warm instances before a launch or a traffic spike to avoid cold starts.
Remote commands
Run one-off maintenance commands against an environment, gated by their own permission.
Diagnostics
Health checks that verify cloud access, configuration and connectivity for an environment.
Notifications
Deployment and incident alerts to Slack, Microsoft Teams, email or any webhook.

The services it uses on each cloud.

Native managed services only, so your cloud team already knows how to monitor, secure and support them.

Compute and delivery

ServiceAWSGCPComputeLambdaCloud RunImagesECRArtifact RegistryProvisioningCloudFormation stacksGoogle Cloud APIs

Data

ServiceAWSGCPDatabaseRDS, AuroraCloud SQLCacheElastiCacheMemorystoreSecretsSSM Parameter StoreSecret Manager

Operations

ServiceAWSGCPQueuesSQSCloud TasksSchedulesEventBridgeCloud SchedulerLogsCloudWatchCloud Logging

Bring serverless to your platform, on your terms.

Tell us about your cloud setup and the services you want to move. We will walk your team through a pilot in your own account.