Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/guilherme-grimm/graph-go
Cloud Infrastructure SecurityContainer SecurityNetwork MappingConfiguration AuditingDevSecOpsDatabase SecurityLog Analysis
GitHubguilherme-grimm/graph-go

graph-go

simply nodes and graphs

View Repository
1245201 month agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

graph-go

See your infrastructure. Zero Config.

Point graph-go at your stack and get a live, interactive map of every database, table, service, and storage bucket — with real-time health monitoring.

License: AGPL v3 graph-go demo


graph-go is a CLI-first infrastructure mapper. It auto-discovers your infrastructure by connecting to the Docker daemon, inspecting running containers, and probing databases and storage services. The UI is served by the backend and reflects real backend state — no manual inventory needed.

CapabilityDetails
Auto-discoveryDetects infrastructure from Docker containers and Kubernetes clusters — no manual inventory needed
KubernetesNamespaces, Deployments, StatefulSets, DaemonSets, Pods, Services — with informer-based real-time watching
DockerClassifies running containers, extracts credentials, watches Docker events, honors graphgo.* labels to override type/DSN/node-type/name or ignore a container
PostgreSQLTables, foreign key relationships, schema topology
MongoDBDatabases and collections
MySQLTables, foreign key relationships
RedisKeyspaces and key distribution
ElasticsearchIndices, cluster health, shard status
S3 / MinIOBuckets and top-level prefixes
HTTP servicesHealth endpoints, dependency mapping between services
Real-time healthWebSocket-powered live status updates every 5 seconds
Interactive graphSwimlane layout, namespace group containers, pan/zoom, filter by type/health, search nodes

Docker labels

graph-go respects a small set of graphgo.* container labels (set them on any container you want to control):

LabelEffect
graphgo.ignore=trueSkip this container entirely
graphgo.type=postgresForce the adapter type (postgres, mongodb, mysql, redis, elasticsearch, s3, http)
graphgo.dsn=...Inject a connection string (DSN for postgres/mysql, URI for mongodb, falls back to dsn otherwise)
graphgo.node-type=gatewayOverride the visual node type (service, gateway, auth, api, queue, cache)
graphgo.name=...Override the node name shown in the graph and used in node IDs / logs

Use these to rescue misclassified containers, point graph-go at a custom DSN, or hide a container from the graph without removing it.


Quick Start — try it in 30 seconds

Boot the seeded demo stack with the CLI. This is the fastest way to see graph-go against a realistic environment and the intended onboarding path for first-time users:

git clone https://github.com/guilherme-grimm/graph-go.git
cd graph-go
go run ./cmd/app demo

Open http://localhost:8080. The command runs attached via Docker Compose. Press Ctrl+C to stop the attached session.

The first run can take several minutes on a cold machine because Docker may need to pull base images and build the local demo images. Later runs are much faster.

The demo stack expects these host ports to be free: 8080, 5432, 27017, 9000, and 9001.

If you need an explicit teardown afterward:

docker compose -f docker-compose.demo.yml down

Run against your own stack

One container, one port. Mount the Docker socket read-only and graph-go auto-discovers everything running on the host:

docker run -d -p 8080:8080 \
  -v /var/run/docker.sock:/var/run/docker.sock:ro \
  ghcr.io/guilherme-grimm/graph-go:latest

graph-go only reads from the Docker socket. The :ro flag enforces this — keep it.

Open http://localhost:8080. Auto-discovery handles Docker containers and (when a kubeconfig or in-cluster service account is present) Kubernetes resources without any config file.

For services that live outside Docker/Kubernetes (remote databases, managed cloud services), mount a config file — see Configuration.


Pre-built binary

Single self-contained binary — UI is embedded, but the entrypoint is still the CLI.

# Linux amd64 (requires the GitHub CLI; browse Releases for other platforms)
gh release download --repo guilherme-grimm/graph-go --pattern 'graph-go_*_linux_amd64.tar.gz' --clobber
tar xzf graph-go_*_linux_amd64.tar.gz
./graph-go serve   # or just `./graph-go` - same thing

Open http://localhost:8080. Other platforms on the Releases page.


Commands

CommandWhat it does
graph-go demoBoot the seeded Docker Compose demo stack from the repository and stream its output in the foreground.
graph-go serveStart the HTTP server with auto-discovery and live updates (default - same as running with no args).
graph-go scanRun discovery once and emit the graph as JSON to stdout. Useful for piping into jq, CI checks, or one-shot exports.
graph-go versionPrint version, commit, and build date.
graph-go --health-checkHit local /health and exit 0/1. Used by the container HEALTHCHECK; not for interactive use.

Global flags (apply to every subcommand): --config, --log-level, --log-format. See graph-go <command> --help for the full per-command surface.

Typical flow:

  1. graph-go demo for a realistic local walkthrough.
  2. graph-go serve to run against your own infrastructure.
  3. graph-go scan for one-shot automation, exports, or CI checks.

Ports

PortPurpose
8080graph-go (UI + API + WebSocket — production)
5173Vite dev server (development only — see CONTRIBUTING.md)
9001MinIO console (demo stack only)

Configuration

Auto-discovery is the path. Mount the Docker socket and/or run inside a Kubernetes cluster — graph-go discovers your infrastructure with no config file needed.

Use the YAML config (conf/config.yaml) only as an escape hatch for services that aren't reachable via discovery — remote databases, managed cloud services, external endpoints. See conf/config.sample.yaml for the full schema — examples for every adapter and every config block (server, docker, kubernetes, connections).

To use a config file with the Docker run above:

docker run -d -p 8080:8080 \
  -v /var/run/docker.sock:/var/run/docker.sock:ro \
  -v $(pwd)/conf/config.yaml:/app/conf/config.yaml:ro \
  ghcr.io/guilherme-grimm/graph-go:latest

Authorized use only: graph-go is for visualizing infrastructure you own or have permission to access. Do not point it at systems without authorization.


Architecture Overview

Backend (Go)

Download Tool