VPS manager written in Rust. One command install with a clean GUI. Deploy Apps & Databases, Git, DB viewer, built-in fail2ban, and resource monitoring.
Rust
0
12 commits
updated Sep 9, 2026
Deploy your apps to a server you own, from one binary.
GitHub → build → nginx → certificate → PostgreSQL → Redis — no glue, no YAML, no agent to babysit.
A VPS is cheap. Running an app on it is not: nginx, a certificate that renews, a systemd unit
per app, a database with a role that is not postgres, a firewall, a way to deploy without
SSHing in at midnight. Every one of those is a thing to learn, configure and keep alive.
Ferrum is all of it in a single Rust binary. You run one install command on a fresh Ubuntu server, answer two questions, and you have a panel in your browser. Connect GitHub, pick a repository, push a tag, and it is live on your domain with HTTPS. Databases, Redis, logs, rollbacks and host hardening are one click each, in the same panel.
Published by irixsoft.com.
On a fresh Ubuntu 22.04 or 24.04 server, x86_64 or arm64:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo sh
The installer downloads the latest release for your architecture, verifies its signature and checksum, installs the binary and a systemd unit, and starts setup. Setup asks for two things:
panel.example.com. It prints the DNS record to add and
waits for it to resolve.On a small server it offers to create a swapfile, because builds routinely need more memory than the machine has. Then it installs nginx, requests a Let's Encrypt certificate for the panel, starts Ferrum, and prints a single-use link to create your passkey. Open it, and you are in.
To install a specific release instead of the latest, pass FERRUM_VERSION:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo FERRUM_VERSION=v0.1.0 sh
| Requirement | Detail |
|---|---|
| A server | Ubuntu 22.04 or 24.04, x86_64 or arm64, that is yours alone. Ferrum runs as root and owns nginx on it. |
| A hostname | An A record for the panel, such as panel.example.com, pointing at the server's public IP. Setup prints it. |
| Open ports | 22 for SSH, 80 and 443 for the panel and your apps. Nothing else. |
| A GitHub account | Ferrum creates a private GitHub App in it, with read access only to the repositories you pick. |
Everything else is installed when you first need it: PostgreSQL the first time you create a database, Redis the first time an app asks for one, the firewall and fail2ban when you enable them on the System page.
Ferrum's panel is a web app that installs to a phone home screen or a desktop dock. You sign in with a passkey; there are no passwords.
Apps
.env and the rows fill in.
Nothing leaves your browser until you click Save.Databases
DATABASE_URL, and no other role can connect to it.pg_dump wrote, from any PostgreSQL host.
Ferrum turns on the extensions the dump needs, then loads it, and every table ends up owned
by the app's role.System
Settings
Press ⌘K anywhere for the command palette.
Deploy
Data
pg_dump in custom or plain SQL formatnoevictionHost
127.0.0.1 onlyOperations
ferrum update, previous binary kept at
/usr/local/bin/ferrum.prev| Command | Description |
|---|---|
ferrum setup | Prepares the host: packages, nginx, the panel's certificate and the first passkey. Resumable. |
ferrum doctor | Checks that this host is an Ubuntu release Ferrum supports. |
ferrum passkey enroll | Prints a single-use link to create a passkey. |
ferrum token create --name <what for> | Mints an API token, shown once. Add --read-only for one that can only watch. |
ferrum deploy <app> | Queues a deploy and follows its log. --ref picks a tag, branch or commit. |
ferrum status | Prints the host card the Dashboard shows. |
ferrum logs <app> | Prints an app's log. --follow streams it, --source picks app, access or error. |
ferrum restart <app> | Restarts an app's unit and prints its status. |
ferrum rollback <app> | Rolls back to the previous release. --to picks one, --restore brings the database snapshot with it. |
ferrum update | Installs the latest release. --check only reports whether there is one. |
ferrum version | Prints the version, build id and commit this binary was built from. |
deploy, status, logs, restart, rollback and update talk to the daemon with a token:
pass --token or set FERRUM_TOKEN.
| Port | Use |
|---|---|
| 22 | SSH, yours |
| 80 | HTTP, the certificate challenge and the redirect to 443 |
| 443 | HTTPS, the panel and every app |
The Ferrum daemon listens on 127.0.0.1:8443 only. nginx is the only thing facing the network.
ferrum/
├─ crates/
│ ├─ ferrum/ # the binary: CLI, HTTP server, routes, MCP
│ ├─ ferrum-core/ # deploys, apps, databases, certificates, host state
│ └─ ferrum-platform/ # everything that touches Ubuntu, behind one trait
├─ web/ # the panel (React, Vite, Tailwind), embedded in the binary
├─ packaging/ # systemd unit, nginx templates, the release signing public key
└─ install.sh # the install command above
The panel is compiled and embedded, so a running Ferrum has no static files to serve or keep in sync.
Ferrum is for one person, or a small team, running their own applications on one server they own. It is built to be understood and operated by one person, from the panel, without a deployment tool to learn first.
It is not aimed at fleets, multi-tenant hosting or anything spanning more than one machine.
0.1.0 is the first stable release. Static Linux binaries for x86_64 and arm64 ship on the releases page, and the installer always fetches the latest.
It has not yet accumulated years of production hours across many servers. Keep backups of your databases, and open an issue when something breaks.
Issues and pull requests are welcome; see CONTRIBUTING.md.
Pull requests require agreement to the Contributor License Agreement. It is a one-time agreement, given as a sentence on your first pull request. You keep the copyright in your contribution; IRIXSOFT LTD receives the rights needed to distribute and license Ferrum as a whole.
Ferrum and the Ferrum logo are trademarks of IRIXSOFT LTD. The license below covers the source code and grants no rights to the name or the logo.
Forks and modified versions may not use the Ferrum name or logo in a way that suggests they are the official project or endorsed by IRIXSOFT LTD. Naming your fork something else is the simplest way to stay clear of this.
AGPL-3.0-only. Copyright © 2026 IRIXSOFT LTD. See LICENSE for the full text.
Rust
78.8%
TypeScript
20.2%
VPS manager written in Rust. One command install with a clean GUI. Deploy Apps & Databases, Git, DB viewer, built-in fail2ban, and resource monitoring.
Rust
0
12 commits
updated Sep 9, 2026
Deploy your apps to a server you own, from one binary.
GitHub → build → nginx → certificate → PostgreSQL → Redis — no glue, no YAML, no agent to babysit.
A VPS is cheap. Running an app on it is not: nginx, a certificate that renews, a systemd unit
per app, a database with a role that is not postgres, a firewall, a way to deploy without
SSHing in at midnight. Every one of those is a thing to learn, configure and keep alive.
Ferrum is all of it in a single Rust binary. You run one install command on a fresh Ubuntu server, answer two questions, and you have a panel in your browser. Connect GitHub, pick a repository, push a tag, and it is live on your domain with HTTPS. Databases, Redis, logs, rollbacks and host hardening are one click each, in the same panel.
Published by irixsoft.com.
On a fresh Ubuntu 22.04 or 24.04 server, x86_64 or arm64:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo sh
The installer downloads the latest release for your architecture, verifies its signature and checksum, installs the binary and a systemd unit, and starts setup. Setup asks for two things:
panel.example.com. It prints the DNS record to add and
waits for it to resolve.On a small server it offers to create a swapfile, because builds routinely need more memory than the machine has. Then it installs nginx, requests a Let's Encrypt certificate for the panel, starts Ferrum, and prints a single-use link to create your passkey. Open it, and you are in.
To install a specific release instead of the latest, pass FERRUM_VERSION:
curl -fsSL https://raw.githubusercontent.com/irixsoft/ferrum/main/install.sh | sudo FERRUM_VERSION=v0.1.0 sh
| Requirement | Detail |
|---|---|
| A server | Ubuntu 22.04 or 24.04, x86_64 or arm64, that is yours alone. Ferrum runs as root and owns nginx on it. |
| A hostname | An A record for the panel, such as panel.example.com, pointing at the server's public IP. Setup prints it. |
| Open ports | 22 for SSH, 80 and 443 for the panel and your apps. Nothing else. |
| A GitHub account | Ferrum creates a private GitHub App in it, with read access only to the repositories you pick. |
Everything else is installed when you first need it: PostgreSQL the first time you create a database, Redis the first time an app asks for one, the firewall and fail2ban when you enable them on the System page.
Ferrum's panel is a web app that installs to a phone home screen or a desktop dock. You sign in with a passkey; there are no passwords.
Apps
.env and the rows fill in.
Nothing leaves your browser until you click Save.Databases
DATABASE_URL, and no other role can connect to it.pg_dump wrote, from any PostgreSQL host.
Ferrum turns on the extensions the dump needs, then loads it, and every table ends up owned
by the app's role.System
Settings
Press ⌘K anywhere for the command palette.
Deploy
Data
pg_dump in custom or plain SQL formatnoevictionHost
127.0.0.1 onlyOperations
ferrum update, previous binary kept at
/usr/local/bin/ferrum.prev| Command | Description |
|---|---|
ferrum setup | Prepares the host: packages, nginx, the panel's certificate and the first passkey. Resumable. |
ferrum doctor | Checks that this host is an Ubuntu release Ferrum supports. |
ferrum passkey enroll | Prints a single-use link to create a passkey. |
ferrum token create --name <what for> | Mints an API token, shown once. Add --read-only for one that can only watch. |
ferrum deploy <app> | Queues a deploy and follows its log. --ref picks a tag, branch or commit. |
ferrum status | Prints the host card the Dashboard shows. |
ferrum logs <app> | Prints an app's log. --follow streams it, --source picks app, access or error. |
ferrum restart <app> | Restarts an app's unit and prints its status. |
ferrum rollback <app> | Rolls back to the previous release. --to picks one, --restore brings the database snapshot with it. |
ferrum update | Installs the latest release. --check only reports whether there is one. |
ferrum version | Prints the version, build id and commit this binary was built from. |
deploy, status, logs, restart, rollback and update talk to the daemon with a token:
pass --token or set FERRUM_TOKEN.
| Port | Use |
|---|---|
| 22 | SSH, yours |
| 80 | HTTP, the certificate challenge and the redirect to 443 |
| 443 | HTTPS, the panel and every app |
The Ferrum daemon listens on 127.0.0.1:8443 only. nginx is the only thing facing the network.
ferrum/
├─ crates/
│ ├─ ferrum/ # the binary: CLI, HTTP server, routes, MCP
│ ├─ ferrum-core/ # deploys, apps, databases, certificates, host state
│ └─ ferrum-platform/ # everything that touches Ubuntu, behind one trait
├─ web/ # the panel (React, Vite, Tailwind), embedded in the binary
├─ packaging/ # systemd unit, nginx templates, the release signing public key
└─ install.sh # the install command above
The panel is compiled and embedded, so a running Ferrum has no static files to serve or keep in sync.
Ferrum is for one person, or a small team, running their own applications on one server they own. It is built to be understood and operated by one person, from the panel, without a deployment tool to learn first.
It is not aimed at fleets, multi-tenant hosting or anything spanning more than one machine.
0.1.0 is the first stable release. Static Linux binaries for x86_64 and arm64 ship on the releases page, and the installer always fetches the latest.
It has not yet accumulated years of production hours across many servers. Keep backups of your databases, and open an issue when something breaks.
Issues and pull requests are welcome; see CONTRIBUTING.md.
Pull requests require agreement to the Contributor License Agreement. It is a one-time agreement, given as a sentence on your first pull request. You keep the copyright in your contribution; IRIXSOFT LTD receives the rights needed to distribute and license Ferrum as a whole.
Ferrum and the Ferrum logo are trademarks of IRIXSOFT LTD. The license below covers the source code and grants no rights to the name or the logo.
Forks and modified versions may not use the Ferrum name or logo in a way that suggests they are the official project or endorsed by IRIXSOFT LTD. Naming your fork something else is the simplest way to stay clear of this.
AGPL-3.0-only. Copyright © 2026 IRIXSOFT LTD. See LICENSE for the full text.
Rust
78.8%
TypeScript
20.2%