惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MongoDB | Blog
MongoDB | Blog
博客园 - 聂微东
Attack and Defense Labs
Attack and Defense Labs
WordPress大学
WordPress大学
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Spread Privacy
Spread Privacy
AI
AI
宝玉的分享
宝玉的分享
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
Cyber Attacks, Cyber Crime and Cyber Security
爱范儿
爱范儿
Help Net Security
Help Net Security
V
Visual Studio Blog
大猫的无限游戏
大猫的无限游戏
Forbes - Security
Forbes - Security
P
Privacy & Cybersecurity Law Blog
Project Zero
Project Zero
IT之家
IT之家
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
有赞技术团队
有赞技术团队
T
Troy Hunt's Blog
美团技术团队
T
Threatpost
K
Kaspersky official blog
V
V2EX
Scott Helme
Scott Helme
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
T
Tailwind CSS Blog
V
Vulnerabilities – Threatpost
Last Week in AI
Last Week in AI
PCI Perspectives
PCI Perspectives
Google Online Security Blog
Google Online Security Blog
Apple Machine Learning Research
Apple Machine Learning Research
Engineering at Meta
Engineering at Meta
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
I
InfoQ
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
L
LINUX DO - 最新话题
T
The Exploit Database - CXSecurity.com
L
LangChain Blog
S
Security @ Cisco Blogs
The Last Watchdog
The Last Watchdog
H
Hacker News: Front Page
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
TaoSecurity Blog
TaoSecurity Blog

Show HN

GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - fayzan123/claude-workflow-composer: Visual desktop app for composing multi-agent coding workflows. Drag agents, attach skills and MCPs, wire handoffs, export to .claude/ GitHub - harshaneel/humanize: Best static AI text humanizer. Two research-grounded skills that work in any LLM (Claude, ChatGPT, Gemini, Codex): humanize beats perplexity-based detectors, ai-check produces forensic scoring with evidence-quoted flags. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature. GitHub - StackOneHQ/stack-nudge GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - alkait/WhatsKept: Agent-queryable WhatsApp history from an iOS backup — a single Go binary. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. WAR.GOV/UFO Microfilm5 GitHub - scosman/videowright: Build animated explainer videos with your coding agent GitHub - dipankar/dscode: The code editor you can take apart. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - ruvnet/RuView: π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - MarcellM01/TinySearch: Shrink the web for your local LLMs! GitHub - pileax-ai/pileax: PileaX is an all-in-one AI knowledge base system. 🍀 GitHub - TangibleResearch/Halgorithem: A Algo designed to detect AI Hallucitions GitHub - DO-SAY-GO/freelang: I love freelang GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - tommyjepsen/awesome-ux-skills: UX & AI Product designs skills you can use today in Claude Code GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - kklimuk/docx-cli: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - olalie/tapmap: See where your computer connects and what stands out on a live world map. GitHub - matisiekpl/neond: DX-focused control plane for Postgres dedicated to non-critical workloads. Your postgres:latest replacement 🐘 GitHub - Diplomat-ai/diplomat-agent: What can your AI agent do to the real world? Scan your code. See which tool calls have zero checks GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - Lumen-Labs/brainapi2: BrainAPI is a knowledge graph–powered AI memory layer that transforms unstructured data into structured knowledge, enabling intelligent search, recommendations, and contextual memory for AI agents and applications. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. make sidebar/address bar rounded corner toggleable
GitHub - Arborist-sh/graft
phtowel · 2026-06-24 · via Show HN

Graft — one golden Tart VM image for your dev box and your CI (v0.5.5 Sakura)

One golden Tart VM image for macOS that powers both your dev environment and your ephemeral CI runners. Open-source and fleet-ready. (Linux guests are a planned future epic — see Status; macOS is the supported target today.)

Graft does three things off one .graft seed:

  • graft sapling grow — grow a golden image (a sapling) with your full toolchain and warm caches (Xcode, Node, CocoaPods, Detox…) baked in.
  • graft nest — develop inside that image over VS Code Remote-SSH. Codespaces for native macOS/iOS, off the exact image your CI uses.
  • graft arborist tend — ephemeral GitHub Actions runners: each boots a fresh VM, registers with GitHub, runs exactly one job, then tears itself down. No state drift, no leftover secrets — ephemerality is enforced by construction (JIT runners), not by convention.

Because dev and CI share one image, "works on my machine" stops being a thing.

Why

  • Built for fleets: scale to any number of runners across hosts, with Apple's per-host macOS-VM limits respected by construction.
  • Warm by default — caches bake into the image via APFS copy-on-write, so every ephemeral runner gets an instant private warm cache; "refresh" is just a rebuild.
  • Designed from day one to swap a local Tart backend for an Orchard fleet without touching the runner logic.

Graft owes a lot to Tartelet, which pioneered the ephemeral-Tart-runner approach on macOS — Graft pushes that idea toward multi-host fleets and a shared dev/CI image.

Status

Area State
VM layer (tart clone/boot/IP/destroy) ✅ working
GitHub App auth + JIT runner config ✅ built (HTTP unverified without a real App)
Keychain secret store (login + system) ✅ working (cross-process read needs ACL hardening)
tart exec provisioning + runner loop ✅ built (runner download unverified on a live VM)
Pool supervisor + state + daemon ✅ built & unit-tested
Image builder + graft nest + .graft recipes ✅ built & tested (real image baked end-to-end)
Orchard multi-host backend ✅ verified end-to-end against a live controller — docs/orchard.md
Health monitor (--tend on run / tree branch / tree plant) ✅ built & unit-tested — detection-only, per-role agents, docs/health-and-monitoring.md
Linux guests 📋 planned (future epic) — the OS-aware plumbing exists (runner arch, capacity, Orchard --os linux), but it's unproven and has known gaps (local tart exec is macOS-guest only; runner deps + run-as-root aren't handled; image builder is macOS-only). macOS is the supported target.

Built and driven through end-to-end on macOS; the parts that need real GitHub credentials or a booted VM to fully prove are flagged in code (TODO(real-VM)).

Requirements

  • Apple Silicon Mac
  • Tart (brew install cirruslabs/cli/tart)
  • Swift 6 toolchain
  • A GitHub App (not a PAT) with self-hosted-runner admin permission

Build

swift build -c release
sudo cp .build/release/graft /usr/local/bin/graft

The Apple 2-VM limit

Apple Silicon enforces a hard limit of 2 concurrent macOS VMs per host in the XNU kernel. Graft respects it: macOS pools are capped at 2 VMs per host, budgeted across all pools. (Linux guests would be uncapped, bounded by RAM/cores — but Linux is a planned future epic, not yet validated; see Status.) To scale macOS beyond 2, add hosts — that's what the Orchard backend is for.

Setup

1. Create a GitHub App

Give it Self-hosted runners: Read & write (org) or Administration: Read & write (repo), install it on your org/repo, and download its private key (.pem).

2. Import the key into the Keychain (never on disk)

# Interactive hosts (login keychain):
graft secrets import --app-id <APP_ID> --pem ./app.pem
rm -P ./app.pem          # then shred the file

# Headless daemon hosts (system keychain, no login session at boot):
sudo graft secrets import --app-id <APP_ID> --pem ./app.pem --keychain /Library/Keychains/System.keychain

Graft resolves the key from the Keychain by App ID — there is no key path in config. The profile records which keychain each App's key lives in (github.scope: login, system, or a path), so there's no global flag to remember at run time — graft init sets it for you.

3. Configure

graft config template > ~/.graft/config.json
graft config validate
{
  "provider": { "type": "tart" },
  "github": { "appId": 12345, "target": "org:my-org", "scope": "login" },
  "pools": [
    {
      "name": "macos-release",
      "image": "ghcr.io/cirruslabs/macos-tahoe-xcode:latest",
      "os": "macos",
      "count": 2,
      "labels": ["self-hosted", "macos", "release"],
      "cpu": 4,
      "memory": 8192
    }
  ],
  "secrets": { "store": "keychain" }
}

The provider object owns the backend ({ "type": "tart" }, or { "type": "orchard", "controllerURL": …, "serviceAccount": …, "maxVMs": … }). github (the App + where runners register) is declared once at the profile level and inherited by every pool — a pool may override it with its own github for a multi-repo profile. Its scope records which keychain that App's key lives in (login for an interactive Mac, system for a headless/daemon host) — so the App ID and its key always travel together. A pool is just its workload: image, count, os, labels (its tags — runs-on: targets these; default ["self-hosted", <os>, <name>]), and optional cpu/memory per leaf. runnerGroupId defaults to 1.

4. Tend

graft arborist tend            # backgrounds a detached supervisor, then attaches a live view
graft arborist attach          # re-attach a live, read-only view (Ctrl+C detaches; it keeps tending)
graft status                   # supervisor liveness + live runner snapshot
graft stop                     # graceful shutdown

tend backgrounds the supervisor by default and attaches a live view; Ctrl+C detaches the view, leaving the supervisor running (re-attach any time with graft arborist attach; stop it with graft stop). It survives the launching terminal closing — no nohup/launchd needed. Run a second tend and it detects the running one and offers to reconnect, kill, or cancel. Use --foreground to supervise in the current process (blocking, Ctrl+C stops it), or --daemon for launchd-managed hosts.

Running headless / on an EC2 Mac? Tart needs an active GUI login session — see docs/ec2-mac-setup.md for the auto-login setup, verification steps, and security trade-offs.

Commands

graft init                              Interactive setup: backend (Tart | Orchard tree) + profile + pools + keys

graft arborist tend [--profile NAME] [--foreground] [--daemon] [-v] [--monitor]   Tend the pool (backgrounds + attaches by default)
graft arborist attach [--profile NAME]  Attach a live, read-only view to a running supervisor
graft arborist check                    Verify GitHub App auth end-to-end (no VM boot)
graft arborist canopy / branches / leaves   Inspect the tree (capacity, workers, VMs)
graft arborist runners                  List / prune GitHub runner registrations
graft status                            Show supervisor + runner state
graft stop                              Gracefully stop a running supervisor

graft profile create                    Interactive wizard: new profile + pools
graft profile list                      List profiles (active marked *)
graft profile use <name>                Set the active profile
graft profile show [name]               Print a profile's config
graft profile rm <name>                 Delete a profile
graft pool new [--profile NAME]         Interactive wizard: add a pool (image picked from the machine)
graft pool add --name N --image I --app-id A --target T [--os] [--count] [--labels] [--cpu] [--memory]
graft pool rm <name> [--profile NAME]
graft pool list [--profile NAME]

graft sapling grow --seed <recipe.graft>   Grow a golden image (sapling) from a .graft seed
graft sapling render --seed <recipe.graft> Preview the compiled provisioning script
graft sapling list / rm / prune / push / pull / template   Manage saplings (prune clears orphaned build VMs)
graft nest [<repo>|<box>|.] [--code]    Dev box (nest): clone a repo / resume a box / mount '.' (docs/dev-boxes.md)
graft nest ls / rm [box]                List / remove nests

graft plant                             Plant the trunk — run the controller (foreground)
graft branch <trunk-url> [--reserve N] [--monitor]   Graft a branch on — run a worker that joins the tree
graft prune <name>                      Prune a branch — remove a worker
graft bonsai                            Grow a bonsai — a whole tiny tree on this machine (local)

graft leaf create <image> [--os macos|linux]   Clone + boot a VM (leaf), print name<TAB>ip
graft leaf rm <name>                    Stop + destroy a leaf (VM)
graft leaf list [--all]                 List graft-managed (or all) leaves
graft leaf ip <name> [--wait]           Print a leaf's IP
graft runners list [--profile NAME]     List graft's runner registrations on GitHub
graft runners prune [--profile NAME]    Delete offline graft runner husks on GitHub
graft secrets import --app-id N --pem P [--keychain PATH]   (default: login keychain)
graft secrets list [--keychain PATH]
graft secrets rm --app-id N [--keychain PATH]
graft config validate [--profile NAME] [--skip-keys]
graft config template

Profiles live at ~/.graft/profiles/<name>.json; the active one is used by arborist tend/arborist check/config validate unless you pass --profile or --config. Switch setups (personal vs. work) with graft profile use.

Images & local dev

Build a golden image (base + toolchain + warm caches) once and clone it for both CI runners and a local dev box — so your laptop and your runners run byte-identical environments. Tart clones are APFS copy-on-write, so baked caches cost nothing per runner. See docs/images-and-caching.md for recipes, the CoW caching strategy, and host-mount safety (read-only for shared caches).

A recipe is a declarative .graft file (YAML). Fields compile into the right provisioning, grouped: toolchain (node, ruby, python, cocoapods, xcode, fastlane, …), system config (env, known-hosts, disable-spotlight, git, …), cache warming (prefetch; repos: clones a repo to warm global caches then discards the source — no source baked), verification (verify:), and VM shape (cpu/memory/disk). network: bridged:<iface> covers hosts where the default NAT is blocked (e.g. behind Zscaler). Drop to a run: block or script: for anything custom. graft sapling template prints a starter; the full field reference is in docs/images-and-caching.md.

graft sapling render --seed examples/images/rn-detox.graft  # preview the compiled script
graft sapling grow   --seed examples/images/rn-detox.graft  # grow the golden image (sapling)
graft nest your-org/app                                     # clone into a nest, shell in
graft nest your-org/app --code                              # …or open VS Code inside the VM

Ready-to-adapt recipes (React Native/Detox, iOS/Fastlane, Node, script-based) live in examples/images/. Editing .graft files? There's a VS Code extension (highlighting incl. embedded shell, field completion/hover, render/build commands).

Dev in the VM

A dev box is a VM cloned from one of your golden images — same toolchain as CI, host stays a thin client. --code opens VS Code over Remote-SSH into the box, so the editor, terminal, language servers, and builds run guest-side. It's Codespaces, but for native macOS/iOS.

graft nest                     # picker: resume a box / clone a repo / mount here / scratch
graft nest your-org/app        # clone → persistent box, shell in   (--code for VS Code)
graft nest app                 # resume it
graft nest .                   # mount $PWD → ephemeral box → run here
graft nest ls / rm [box]        # list / remove boxes

The model: clone → persistent & resumable; mount (.) / scratch → ephemeral. Full guide — clone vs mount, --code, the picker, advanced flags — in docs/dev-boxes.md.

Desktop app

Graft.app is a full desktop companion (the menu-bar app grown up) — a sidebar over:

  • Dashboard — live runners/leaves with phase + age; start/stop.
  • Canopy — the Orchard fleet at a glance: trunk reachability, capacity, branches, leaves.
  • Nests — dev boxes: open in VS Code or a shell, start/stop, watch live provisioning status.
  • Saplings — images: grow from a seed, pull, remove, and inspect what a base already has baked in.
  • Seeds — a structured .graft builder ("+ Add" only the toolchain/scripts/sims you want, with version dropdowns) ⟷ raw YAML, with a compiled-script preview.
  • Profiles · Pools · Secrets — full config, no JSON editing.

It can create a GitHub App for you end-to-end (the manifest flow — no manual key download) or smart-import an existing key, and a Standard ↔ Graft vocabulary toggle lives in Settings. Install: brew install --cask arborist-sh/tap/graft-app.

Architecture

Everything pivots on VMProvidercapacity, acquire, release, plus an exec channel. The supervisor never calls tart directly, so LocalTartProvider (single host) and OrchardProvider (multi-host fleet) are a drop-in swap — same runner logic, different backend. The same move backs SecretStore (Keychain now, Vault/1Password later).

PoolSupervisor (actor, desired-state loop)
  └─ per slot, forever:
       provider.acquire(image, os)            → RunningVM
       GitHubAppClient.generateJITConfig(...)  → JIT blob   (App JWT → installation token → JIT)
       RunnerProvisioner.runEphemeralRunner    → tart exec ./run.sh --jitconfig, wait for exit
       provider.release(vm)                    → tart stop + delete

Provisioning uses tart exec (Tart Guest Agent) — no SSH, no keys, no passwords. Stock cirruslabs images ship the agent; custom images must include it.

Documentation

Roadmap

  • Remote host management + aggregated health ("Sapflow") — control trunk/branch hosts and stream fleet health into one panel (design)
  • Share .graft seeds, not images — a hosted minimal base ladder so a recipe is the unit you distribute (design)
  • Keychain ACL hardening for the headless daemon (bind to the graft binary)
  • --unsafe-unrestricted-quota (kernel boot-arg override, SIP off, opt-in)
  • Twig: native Virtualization.framework backend

Shipped: ✅ full desktop app (Graft.app — Dashboard, Canopy, Nests, Saplings, a .graft seed builder, and Profiles/Pools/Secrets config; creates GitHub Apps in-app); ✅ image builder + graft nest + .graft recipes (toolchain/system/cache-warming/VM-shape fields, bridged networking, repo pre-caching); ✅ OrchardProvider multi-host backend

Install

CLI + daemon:

brew install arborist-sh/tap/graft

Menu-bar app (installs the CLI too):

brew install --cask arborist-sh/tap/graft-app

Apple Silicon only. Tart is pulled in as a dependency.

License

MIT — see LICENSE.