Skip to content
Arnel Robles edited this page Sep 10, 2026 · 2 revisions

BaryoVM

PaaS-style deploys on VMs you already own. Agentless, over plain SSH, from one CLI.

There is no control plane to host, no agent to install and nothing extra listening on your servers. Everything runs from your machine, over the SSH connection you already have.

brew install arnelirobles/tap/baryovm

Start here

If you are Read
new, and have a VM and an SSH key Quickstart
installing Installation
looking for a specific flag Command reference
writing something that calls BaryoVM The JSON contract
wondering what a "stack" is Concepts
stuck Troubleshooting

The mental model in one minute

A VM is a machine you already own, registered by host, user and the path to an SSH key. BaryoVM stores the path, never the key itself.

A stack is a Docker Compose project living in a directory on one of those VMs. Registering a stack tells BaryoVM where that directory is and, optionally, how to back its database up and how to release new code into it.

A release syncs your source to the VM, builds the images there, and brings the stack up, taking a database backup first. The build happens on the VM, so your laptop does not need a registry, a build farm or a fast uplink.

Everything else is a variation on those three. There is no fourth concept waiting to be learned.

What it is not

It does not provision VMs for you as a primary path, it does not manage DNS or TLS for you, and it does not run anything in the cloud on your behalf. It drives machines you already have. If you want a platform that owns the whole lifecycle, this is the wrong tool and that is deliberate.

Two ideas that explain most decisions here

The CLI is the whole surface. Every command supports -o json and emits one envelope, because an app and an MCP server are meant to drive exactly the same commands a person types. Nothing is reachable only through pretty output.

The tool holds no secrets. It stores SSH key paths, not key material, and it never reads your application secrets, except when a backup copies a stack's .env into a backup directory on your own VM. See SECURITY.md.

Project

  • Source and releases
  • Contributing, which leads with the rule that matters most here: a change to command construction needs a test that reads the generated string.
  • Licence: MPL-2.0

Clone this wiki locally