Skip to content

Graphs

One environment. One file.

Several named machines plus the edges that say who can reach whom. An edge is an authorization, not “the network”.

tienda.yaml
name: tienda
nodes:
db: {from: pg16-golden, ports: [5432], wake: lazy, idle_freeze: 120}
api: {from: api-node, ports: [8081], egress: allowlist, allow_domains: [api.stripe.com]}
web: {from: web-static, ports: [8000]}
edges:
- {from: api, to: db, kind: credential, port: 5432, user: app, database: shop, env: PGPASSWORD, secret_env: SHOP_PG_PASS}
- {from: web, to: api, kind: link, port: 8081}
Terminal window
SHOP_PG_PASS=... kling graph up tienda.yaml

Output

graph tienda (4f2a9c1e0b7d) up in 412ms
NODE STATE MACHINE WAKE FROM PORTS
api running 9c1e0b7d4f2a eager api-node 8081
db (not started) - lazy pg16-golden 5432
web running 0b7d4f2a9c1e eager web-static 8000
  • Inside web, http://api.graph:8081 reaches api.
  • Inside api, db.graph:5432 reaches db with the password filled in by the proxy: api only sees a placeholder.
  • db is lazy: it does not exist until the first psql.
Terminal window
kling graph snapshot tienda -name t0 # one template per node, from the same instant
kling graph fork tienda -n 3 # 3 new graphs that cannot see each other
kling graph freeze tienda ; kling graph thaw tienda
kling graph audit tienda -since 10m # every connection per edge, on a timeline

Limits: 32 nodes, 64 edges.