Skip to content

Quickstart

Arnel Robles edited this page Sep 26, 2026 · 2 revisions

Quickstart

From "I have a VM and an SSH key" to a running stack. Every command in full, nothing assumed.

What this is not. BaryoVM deploys to machines you already own, over SSH. It does not create the VM, buy the domain, or terminate TLS for you. If you have no VM yet, get one anywhere, put your public key on it, and come back.

0. Install and check

brew install arnelirobles/tap/baryovm     # macOS; see Installation for Linux
baryovm version
baryovm doctor

doctor tells you what is missing before it costs you a failed release. stack release needs rsync and ssh on your machine.

1. Register the VM

baryovm vm add demo --host 203.0.113.10 --user ubuntu --key ~/.ssh/id_ed25519
baryovm vm ping demo

ping proves the key works and reports whether Docker is there. The first connection also records the VM's SSH host key and prints its fingerprint when the command finishes. Every later connection must offer the same key, or the command stops. See Troubleshooting if it does.

baryovm vm bootstrap demo     # installs Docker if it is missing

2. Harden it, while it is still boring

A VM with a public SSH port is found within minutes and guessed at continuously.

baryovm vm harden demo --dry-run    # see what it would change
baryovm vm harden demo

It will not change your SSH port, disable key authentication or touch authorized_keys, so it cannot lock you out. Later, to see what it is absorbing:

baryovm vm threats demo

3. Put a compose project on the VM

Nothing BaryoVM-specific. Any directory with a docker-compose.yml:

ssh ubuntu@203.0.113.10 'mkdir -p ~/hello'
cat > /tmp/docker-compose.yml <<'YAML'
services:
  web:
    image: nginx:alpine
    ports: ["127.0.0.1:8080:80"]
    restart: unless-stopped
YAML
scp /tmp/docker-compose.yml ubuntu@203.0.113.10:~/hello/

Binding to 127.0.0.1 keeps it off the public internet until you put a proxy in front.

4. Register it as a stack

baryovm stack add hello --vm demo --path /home/ubuntu/hello
baryovm stack list

5. Bring it up

baryovm stack deploy hello
baryovm stack ps hello
baryovm stack logs hello --tail 20

Check it from the VM, since the port is bound to loopback:

ssh ubuntu@203.0.113.10 'curl -sS -o /dev/null -w "%{http_code}\n" http://127.0.0.1:8080'

200 means you are done. That is a deployed, managed stack.

6. What to add next, when you need it

Backups, once there is a database worth losing:

baryovm stack add hello --vm demo --path /home/ubuntu/hello \
  --db-container hello-postgres-1 --db-name hello --env-file .env
baryovm stack backup hello
baryovm stack backups hello

Re-running stack add on an existing stack changes only the fields its flags name, so the update policy and anything else you set earlier are kept.

Releases from source, when you are building images rather than pulling them. Write a baryovm.release.json and register it with --release-file, then baryovm stack release hello syncs, builds on the VM and brings it up, taking a backup first. See Concepts.

Unattended updates, once there is a health URL to judge by:

baryovm stack set-update hello --auto --health-url http://127.0.0.1:8080/
baryovm stack update hello --auto --dry-run

If something failed

Every command takes -o json, and failure envelopes carry the exact remote command that ran, which is usually the whole answer. See Troubleshooting.

Clone this wiki locally