From nothing to a VM you can SSH into
eitri.sh runs a control plane so you don't have to. You bring the hardware; the console, sync, and SSH gate are already up. No server install at all. Prefer to run the plane yourself? self-hosting does the same job on your own box, and the three steps below are unchanged after it.
Open https://console.eitri.sh and sign in with Google. Your first sign-in creates your tenant.
Any machine with KVM, or a Mac. + Add host in the console prints a one-shot command; the machine dials out, and no inbound port is needed. joining has the commands for both, and the sharp edges of a Mac.
SSH access uses certificates signed by your CA—eitri never holds a user key that can enter your VMs. A guest trusts the CA set it is created with, so the client and its CA come before your first VM. One binary, targeting the hosted service by default:
OS=$(uname -s | tr A-Z a-z) ARCH=amd64 # arm64 laptop → ARCH=arm64
curl -fsSLO https://eitri.sh/dl/latest/SHA256SUMS
V=$(sed -n "s/.*eitri-cli_\(v[^_]*\)_${OS}_${ARCH}\.tar\.gz\$/\1/p" SHA256SUMS)
curl -fsSLO "https://eitri.sh/dl/latest/eitri-cli_${V}_${OS}_${ARCH}.tar.gz"
sha256sum -c SHA256SUMS --ignore-missing
tar xzf "eitri-cli_${V}_${OS}_${ARCH}.tar.gz"
sudo install -m 0755 "eitri-cli_${V}_${OS}_${ARCH}/eitri" /usr/local/bin/eitri
Then the guided setup:
eitri init
It asks for a personal access token—mint one in the console under Settings →
Personal access tokens—then registers a CA if your tenant has none, generating
one only if you have no key it can use, and writes ~/.eitri/config.json.
Nothing happens without a y. connecting walks each step.
Console → + Create VM, pick your host, create; or create from the CLI with the host ID shown in the console:
EITRI_TOKEN=<pat> eitri vm create --host <host-id> --name web-1
Pass --cloud-init <file> for your guest's cloud-init user-data, --network <name> for an advertised host network, and repeat --volume-claim <name-or-id>
to attach claims. Watch it boot in the browser serial console. Defaults: 2 vCPUs, 2048 MB, 10 GB, the default image; status reads creating while the
image downloads and the guest boots, then ready.
The console's Cloud-init builder accepts an SSH public key from your .pub
file and previews the generated cloud-config. It installs the key for the image's
default user (ubuntu on the default image) at first boot. Use Custom user-data
for your own cloud-config or script; the key is added by the server. Adding a key
does not change the SSH jump gate's requirement for a tenant-signed certificate.
A tenant with no registered CA is refused here, rather than handed a guest that
nothing can reach: the CA set is baked into the guest at create and registering
one afterwards does not reach a VM that already exists. Register a CA first—the
console's Settings page, eitri ca upload <ca.pub>, or the MCP ca_upload
tool—then create the VM.
eitri init wrote the plane, the gate and your tenant, so there is nothing
left to set:
eitri ssh <vm-name>
eitri ssh <vm-name> uptime
Skipped init? The console and gate fall back to the hosted defaults, and
EITRI_TOKEN alone is enough—eitri ssh asks the plane for your tenant and
its gate.
eitri ssh by hand