Managed File Transfer

Your partners' file transfers, under control end to end

Your partners upload and fetch their files over SFTP, through an API or in a browser. You decide where they land, who can reach them and for how long. You see everything that happens to them.

acme-batchuploads over SFTP etl-nuitreads via the API mariebrowses, downloads SFTP API REST File explorer Console roles, ACL, audit pod 1 pod 2 pod 3 pod 3 joinsthroughput follows pod 1 failsnothing stops Local diskmarie's /scratch S3partners' /inbox Upstream SFTP/archives, pinned host key HDFS/lake, read-only

What it does

Receive, store, authorise, trace

01

Your partners come in the way they know

SFTP for batch jobs, a REST API with an OpenAPI contract for your orchestrators, a web explorer for people. One account, one file tree, whichever door they use.

02

You store where you want

S3, HDFS, an existing SFTP server or local disk: a role mounts each storage at a path, with per-path rights denied by default. Access can be granted until a date and closes on its own.

03

You see everything

One audit line per operation, with the account, the path, the storage and the outcome. Prometheus metrics, OpenTelemetry traces, and a console to watch, kick and unban, live.

Security and operations

Built to hold the door, with one instance or many

Get started

One binary, one image, one chart

Binary

Linux, ARM64, Windows. Static, no dependencies.

craft-file-gate config check config.toml
craft-file-gate --config config.toml

Docker

Distroless, scratch and alpine images, unprivileged.

docker run -p 2222:2222 -p 8080:8080 \
  -v ./config:/config -v data:/data \
  craftogether/craft-file-gate:latest

Kubernetes

Helm chart, multi-pod cluster ready out of the box.

helm install acme craft-file-gate \
  --set replicaCount=3