Skip to content

Self-hosting

Honest scope first: the engine is open source and self-hostable; this control plane is not published. What that means in practice:

  • The engine — the node agent that runs microVMs and pauses them with their memory, the guest agent, the barista node CLI, the fleet coordination model — is open source, documented at barista.sh docs, and runs on infrastructure you own: a single x86_64 Linux host with /dev/kvm, no cluster, no external control plane. Fleets coordinate through any S3-compatible bucket. Start there if you want Barista on your own boxes.
  • The hosted control plane — tenants, API keys, templates, the console, published URLs, the SDK's endpoint — is the managed service at beta.barista.sh. It is operated, not distributed.

What self-hosting the engine gives you

Everything in the engine docs: create instances from digest-pinned OCI images, exec into them, pause/resume with memory, named snapshots, scheduled wake, fleet desired-state via your bucket. What it does not give you is this site's cloud layer (multi-tenancy, templates-by-name, public URLs, the console) — those are the hosted service.

Notes an engine operator will want anyway

Two operational facts from running the hosted fleet, both engine-relevant:

  • Private registry pulls: hypeman resolves image pulls with the standard Docker credential keychain read from the service's HOME — its unit sets HOME=/var/lib/hypeman, so the credential belongs at /var/lib/hypeman/.docker/config.json (a file under /root is silently ignored). It is consulted per pull; no restart, rotation is replacing the file.
  • Co-located Caddy: hypeman's embedded ingress Caddy needs admin port :2019; a system Caddy on the same host must move its admin port or hypeman's ingress silently serves nothing.

Hosted-service operational notes

For completeness, two behaviors of the managed service worth knowing as a user: a gateway restart (deploys) invalidates saved CLI keys — re-run barista login; and the fleet may declare which registries its nodes pull from, which the console's Templates page and GET /v1/templates/-/registries surface (see tutorial 9).