No project description provided
Project description
deploy-vm
Python CLI for deploying web applications to cloud providers (DigitalOcean and AWS).
Installation
uv tool install deploy-vm
Quick Start
1. Configure Provider
Create .env in your project root (optional - defaults to DigitalOcean):
# AWS (recommended for production)
DEPLOY_VM_PROVIDER=aws
AWS_PROFILE=default
AWS_REGION=ap-southeast-2
# Or use DigitalOcean (default)
DEPLOY_VM_PROVIDER=digitalocean
Note: This configures
deploy-vmitself. Your application credentials go in a separate.envinside your app directory (see Application Credentials).
Setup requirements:
- AWS: Run
aws configure(setup guide) - DigitalOcean: Run
doctl auth init
2. Deploy Your App
Simple deployment (no SSL):
uv run deploy-vm fastapi deploy my-server /path/to/app --no-ssl
With domain + SSL:
# 1. Get nameservers first (see Domain Setup section for details)
uv run deploy-vm dns nameservers example.com --provider aws
# 2. Configure at registrar, wait 24-48h for propagation
# 3. Deploy with SSL
uv run deploy-vm fastapi deploy my-server /path/to/app \
--domain example.com --email you@example.com
Supported app types:
fastapi deploy- FastAPI apps with uvicorn + supervisordnuxt deploy- Nuxt apps with PM2
3. Manage Your Deployment
# Check status
uv run deploy-vm instance verify my-server --domain example.com
# View logs
uv run deploy-vm fastapi logs my-server
# Restart app
uv run deploy-vm fastapi restart my-server
# Redeploy code
uv run deploy-vm fastapi sync my-server /path/to/app
Common Workflows
Add SSL After Deployment
Deploy first, add SSL when domain is ready:
# 1. Deploy without SSL
uv run deploy-vm fastapi deploy my-server /path/to/app --no-ssl
# 2. Configure domain (see Domain Setup section)
uv run deploy-vm dns nameservers example.com --provider aws
# 3. Update nameservers at registrar, wait 24-48h
# 4. Add SSL
uv run deploy-vm nginx ssl my-server example.com you@example.com --port 8000
Multiple Apps on One Instance
# Deploy first app
uv run deploy-vm fastapi deploy my-server /path/to/api \
--app-name api --port 8000 --domain api.example.com --email you@example.com
# Deploy second app
uv run deploy-vm nuxt deploy my-server /path/to/frontend \
--app-name frontend --port 3000 --domain example.com --email you@example.com
# List all apps
uv run deploy-vm instance apps my-server
# Manage specific app
uv run deploy-vm fastapi restart my-server --app-name api
Configuration Reference
Environment Variables
Deploy-VM Configuration (.env in project root):
| Variable | Description | Default |
|---|---|---|
DEPLOY_VM_PROVIDER |
Cloud provider (aws or digitalocean) |
digitalocean |
AWS_PROFILE |
AWS CLI profile name | None |
AWS_REGION |
Default AWS region | ap-southeast-2 |
Priority: Command-line flags > .env file > Built-in defaults
Application Credentials (.env)
Important: This is a different
.envfile than the deploy-vm configuration above.
Your deployed apps use a .env file inside the app directory for credentials:
- Location:
.envin your app's root (e.g.,/path/to/app/.env) - Purpose: API keys, database URLs, secrets your app needs to run
- Deployment: Automatically uploaded during
deployorsync
AWS credential filtering:
When deploying to AWS EC2, credentials are automatically filtered:
- ❌ Removed:
AWS_PROFILE,AWS_ACCESS_KEY_ID,AWS_SECRET_ACCESS_KEY(EC2 uses IAM roles) - ✅ Preserved/Added:
AWS_REGION(required for Bedrock and other services)
Example app .env:
# API credentials
ANTHROPIC_API_KEY=sk-ant-...
OPENAI_API_KEY=sk-proj-...
# AWS region (auto-added if missing when deploying to AWS)
AWS_REGION=ap-southeast-2
# Other config
DATABASE_URL=postgresql://...
SECRET_KEY=your-secret-key
Provider-Specific Settings
| Setting | AWS | DigitalOcean |
|---|---|---|
| Regions | us-east-1, us-west-2, ap-southeast-2 |
syd1, sgp1, nyc1, sfo3, lon1 |
| VM Sizes | t3.micro, t3.small, t3.medium |
s-1vcpu-1gb, s-2vcpu-2gb, s-4vcpu-8gb |
| DNS | Route53 hosted zone (auto-created) | DigitalOcean nameservers required |
| Auth | aws configure |
doctl auth init |
See PROVIDER_COMPARISON.md for complete details.
AWS-Specific Features
Bedrock Access
AWS EC2 instances automatically get full Bedrock access via IAM roles:
Default behavior:
# Bedrock access included automatically
uv run deploy-vm fastapi deploy my-server /path/to/app --no-ssl
Custom IAM role:
# Use custom role name
uv run deploy-vm fastapi deploy my-server /path/to/app \
--iam-role custom-role-name --no-ssl
What's included:
- IAM role with EC2 trust policy
AmazonBedrockFullAccessmanaged policy attached- Instance profile created and attached
- Access to all Bedrock foundation models and runtime APIs
Configuration:
- Default role name:
deploy-vm-bedrock - Customize with
--iam-role <name>flag - Your app must include
AWS_REGIONin.env(auto-added if missing)
IAM Role Details
The IAM setup enables your application to call Bedrock APIs without hardcoded credentials:
# Your app code (no credentials needed)
import boto3
bedrock = boto3.client('bedrock-runtime', region_name=os.getenv('AWS_REGION'))
response = bedrock.invoke_model(...)
Commands Reference
deploy-vm --help # See all commands
# Core commands
deploy-vm instance create|delete|list|verify|apps
deploy-vm dns nameservers
deploy-vm nginx ip|ssl
deploy-vm fastapi deploy|sync|restart|status|logs
deploy-vm nuxt deploy|sync|restart|status|logs
Common options:
--provider aws|digitalocean- Cloud provider--region <region>- Provider region--vm-size <size>- Instance size--domain <domain>- Domain for SSL--no-ssl- Skip SSL configuration--app-name <name>- App identifier (for multiple apps)--iam-role <name>- AWS only: Custom IAM role name
See full documentation: deploy-vm <command> --help
Domain & SSL Setup
Prerequisites
AWS Route53:
# Creates hosted zone automatically
uv run deploy-vm dns nameservers example.com --provider aws
DigitalOcean:
- Configure
ns1.digitalocean.com,ns2.digitalocean.com,ns3.digitalocean.comat your registrar
Deployment Paths
Path A - SSL from start:
- Get nameservers:
uv run deploy-vm dns nameservers example.com --provider aws - Configure at registrar, wait 24-48h
- Deploy with
--domain example.com --email you@example.com
Path B - Add SSL later:
- Deploy with
--no-ssl - Get nameservers (creates hosted zone automatically)
- Configure at registrar, wait 24-48h
- Add SSL:
uv run deploy-vm nginx ssl my-server example.com you@example.com --port 8000
Troubleshooting
See DOMAIN_SETUP.md for:
- Detailed setup instructions
- DNS propagation checking
- Common issues and solutions
- Technical reference
Requirements
Local Tools
| Tool | Purpose | Required | Install |
|---|---|---|---|
uv |
Python package manager | ✅ Yes | curl -LsSf https://astral.sh/uv/install.sh | sh |
ssh, rsync, tar, scp |
File transfer & remote ops | ✅ Yes | Pre-installed (macOS/Linux) |
doctl |
DigitalOcean CLI | Optional | brew install doctl |
aws |
AWS CLI | Optional | brew install awscli |
npm |
Nuxt local builds | Optional | brew install node |
Install uv:
curl -LsSf https://astral.sh/uv/install.sh | sh
Install provider CLIs:
# AWS
brew install awscli
aws configure
# DigitalOcean
brew install doctl
doctl auth init
FastAPI Deployment Requirements
- Uses
uvfor Python package management - Expects
pyproject.tomlwith project dependencies - Runs via
uvicornwith supervisord for process management - App source must be a valid Python package
SSH Key
Tool automatically uploads your SSH key (~/.ssh/id_ed25519.pub, id_rsa.pub, or id_ecdsa.pub) to the provider on first use.
Server User Management
All server operations use the deploy user:
- Initial creation: Connects as cloud default (
rootfor DigitalOcean,ubuntufor AWS) - Setup: Creates
deployuser with passwordless sudo - All operations: Use
deployuser withsudofor privileged commands
Override with --ssh-user flag if needed.
Advanced Topics
Instance State
Instance metadata stored in <name>.instance.json:
{
"id": "i-0abc123",
"ip": "54.123.45.67",
"provider": "aws",
"region": "ap-southeast-2",
"os_image": "ubuntu/images/hvm-ssd-gp3/ubuntu-noble-24.04-amd64-server-*",
"vm_size": "t3.small",
"user": "deploy",
"iam_role": "deploy-vm-bedrock",
"apps": [
{"name": "api", "type": "fastapi", "port": 8000},
{"name": "frontend", "type": "nuxt", "port": 3000}
]
}
DNS nameservers cached in <domain>.nameservers.json (auto-generated).
Additional Resources
- Domain & SSL: DOMAIN_SETUP.md - Complete guide with troubleshooting
- Provider comparison: PROVIDER_COMPARISON.md - Detailed feature matrix
- Multiple environments: Use different
.envfiles or AWS profiles - CI/CD integration: Use
--forceflags to skip confirmations
Support
- Issues: GitHub Issues
- Documentation:
deploy-vm --helpordeploy-vm <command> --help
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file deployvm-0.1.3.tar.gz.
File metadata
- Download URL: deployvm-0.1.3.tar.gz
- Upload date:
- Size: 168.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: uv/0.7.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
37fefd2baea738f9bddfdee87e49dd794bc6a63f6d4d542ad7bde177cdc63b9c
|
|
| MD5 |
d52c790fa023fc269af4bee6e50a45d4
|
|
| BLAKE2b-256 |
5f981333217f4525b9ae3c6dc3ed813cdbb0534156f7dbdef18214976202e07c
|
File details
Details for the file deployvm-0.1.3-py3-none-any.whl.
File metadata
- Download URL: deployvm-0.1.3-py3-none-any.whl
- Upload date:
- Size: 35.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: uv/0.7.5
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1c2ef3c4820c858281495bf626742d4031135f7d23182b3e9aaf21169972824b
|
|
| MD5 |
6d85b6fb90241f7a1b5b781052ac71c2
|
|
| BLAKE2b-256 |
ed66dfc0797552a3f4fe8d733c511754cd69457acad3316a701e4697109ed9b4
|