Self-host anything, automatically test it works.
Services arrive wired: SSO, mail, encrypted backups, monitoring. Plain rootless podman and systemd underneath, in files you can read. Every service in the registry proven by end-to-end tests in a fresh VM.
$ ryra add prometheus grafana
→ wires grafana into prometheus (scrape target)
→ provisions prometheus datasource in grafana
→ starts grafana on http://127.0.0.1:3000curl -fsSL https://ryra.dev/install.sh | shOr with Rust:
cargo install ryraWorks on any Linux with systemd and podman >= 5.3 (current Debian-based, Fedora, and Arch releases all qualify). ryra doctor checks your setup.
ryra search # browse the registry
ryra add <service> # install one
ryra init # ...or scaffold your own project
ryra add . # and run your own code on ryraryra add <service> reads a recipe from a curated registry and writes:
- A rootless Podman container, owned by your user
- A systemd quadlet, so
systemctl --userandjournalctl --userwork like normal - Optionally: a Caddy route with auto-HTTPS, and an Authelia OIDC client for SSO
Service data lives at ~/.local/share/services/<name>/. Back it up with tar. Uninstall ryra and your stack keeps running, because the systemd units and containers stay.
SaaS prices keep climbing and the products keep moving slower than you want. Self-hosting is the way out, but the operational cost (compose files, reverse proxies, expiring certs, half-finished install scripts) is what stops most people from leaving.
No other self-hosting toolkit ships the full combination: rootless podman quadlets for security and clean systemd integration, automated VM tests that prove every registry service works before you install it, and a TOML-based recipe format that an AI can read and extend without hand-holding. You stay in control: customise per host, add your own services, and grow your stack at the pace your vendors won't.
Honest scoping, so you know before you commit:
- One box, not a fleet. Ryra manages the machine it runs on. Multi-machine orchestration (spreading services across hosts, moving them between boxes) is a deliberate non-goal today; treat it as roadmap, not a promise. If you need a scheduler, you want Kubernetes or Nomad.
- Not a build platform. Ryra deploys services from recipes; it does not
turn arbitrary source trees into images (no buildpacks). Local projects
bring their own quadlet or a
buildcommand. - Not high availability. One instance per service, restarted by systemd. No replicas, no failover, no load balancing.
- Linux only, rootless podman only. No Docker socket, no macOS/BSD hosts (a Linux VM works fine).
Ryra is a scaffolding tool, not a runtime. It writes plain files and exits, so the box ends up looking like a sysadmin set it up by hand.
Every quadlet, env file, network, and bind-mounted data directory for a service lives under ~/.local/share/services/<name>/. Back up the whole folder with tar, or just the data dirs like db-data/ and upload/. Move the folder to another box, the service comes with it.
SMTP credentials, OIDC provider, Tailscale key, custom registries: all the cross-service settings ryra reads at startup live in a single TOML file. The rest is just service folders.
Each .container and .network is symlinked from its service folder into ~/.config/containers/systemd/, where systemd's user generator picks it up. Remove the service and the symlink goes with it. Uninstall ryra and the symlinks plus the services keep running, because there is no ryra runtime.
ryra add seafileryra add vikunjaryra add openclawThe registry is plain TOML and quadlet files. Drop a definition in for your own app, point ryra at your registry, and install it the same way as anything in the default registry.
Run ryra search for the full list, or browse the services catalog. The default registry includes Immich, Forgejo, Vaultwarden, Nextcloud, Twenty CRM, Paperless-ngx, Synapse, Supabase, Open WebUI, Authelia, Uptime Kuma, Caddy, DocuSeal, Zammad, Seafile, Vikunja, OpenClaw, and more.
Full docs at ryra.dev/intro.
AGPL-3.0-or-later. See LICENCE.md.






