Self-hosting¶
Honest scope first: the engine is open source and self-hostable; this control plane is not published. What that means in practice:
- The engine — the node agent that runs microVMs and pauses them with
their memory, the guest agent, the
baristanode CLI, the fleet coordination model — is open source, documented at barista.sh docs, and runs on infrastructure you own: a single x86_64 Linux host with/dev/kvm, no cluster, no external control plane. Fleets coordinate through any S3-compatible bucket. Start there if you want Barista on your own boxes. - The hosted control plane — tenants, API keys, templates, the console, published URLs, the SDK's endpoint — is the managed service at beta.barista.sh. It is operated, not distributed.
What self-hosting the engine gives you¶
Everything in the engine docs: create instances from digest-pinned OCI images, exec into them, pause/resume with memory, named snapshots, scheduled wake, fleet desired-state via your bucket. What it does not give you is this site's cloud layer (multi-tenancy, templates-by-name, public URLs, the console) — those are the hosted service.
Notes an engine operator will want anyway¶
Two operational facts from running the hosted fleet, both engine-relevant:
- Private registry pulls: hypeman resolves image pulls with the standard
Docker credential keychain read from the service's
HOME— its unit setsHOME=/var/lib/hypeman, so the credential belongs at/var/lib/hypeman/.docker/config.json(a file under/rootis silently ignored). It is consulted per pull; no restart, rotation is replacing the file. - Co-located Caddy: hypeman's embedded ingress Caddy needs admin port
:2019; a system Caddy on the same host must move its admin port or hypeman's ingress silently serves nothing.
Hosted-service operational notes¶
For completeness, two behaviors of the managed service worth knowing as a
user: a gateway restart (deploys) invalidates saved CLI keys — re-run
barista login; and the fleet may declare which registries its nodes pull
from, which the console's Templates page and
GET /v1/templates/-/registries surface (see
tutorial 9).