Quickstart

From nothing to a VM you can SSH into

eitri.sh runs a control plane so you don't have to. You bring the hardware; the console, sync, and SSH gate are already up. No server install at all. Prefer to run the plane yourself? self-hosting does the same job on your own box, and the three steps below are unchanged after it.

Create an account

Open https://console.eitri.sh and sign in with Google. Your first sign-in creates your tenant.

Join a host

Any machine with KVM, or a Mac. + Add host in the console prints a one-shot command; the machine dials out, and no inbound port is needed. joining has the commands for both, and the sharp edges of a Mac.

Start a client

SSH access uses certificates signed by your CA—eitri never holds a user key that can enter your VMs. A guest trusts the CA set it is created with, so the client and its CA come before your first VM. One binary, targeting the hosted service by default:

OS=$(uname -s | tr A-Z a-z) ARCH=amd64             # arm64 laptop → ARCH=arm64
curl -fsSLO https://eitri.sh/dl/latest/SHA256SUMS
V=$(sed -n "s/.*eitri-cli_\(v[^_]*\)_${OS}_${ARCH}\.tar\.gz\$/\1/p" SHA256SUMS)
curl -fsSLO "https://eitri.sh/dl/latest/eitri-cli_${V}_${OS}_${ARCH}.tar.gz"
sha256sum -c SHA256SUMS --ignore-missing
tar xzf "eitri-cli_${V}_${OS}_${ARCH}.tar.gz"
sudo install -m 0755 "eitri-cli_${V}_${OS}_${ARCH}/eitri" /usr/local/bin/eitri

Then the guided setup:

eitri init

It asks for a personal access token—mint one in the console under Settings → Personal access tokens—then registers a CA if your tenant has none, generating one only if you have no key it can use, and writes ~/.eitri/config.json. Nothing happens without a y. connecting walks each step.

Boot a VM

Console → + Create VM, pick your host, create; or create from the CLI with the host ID shown in the console:

EITRI_TOKEN=<pat> eitri vm create --host <host-id> --name web-1

Pass --cloud-init <file> for your guest's cloud-init user-data, --network <name> for an advertised host network, and repeat --volume-claim <name-or-id> to attach claims. Watch it boot in the browser serial console. Defaults: 2 vCPUs, 2048 MB, 10 GB, the default image; status reads creating while the image downloads and the guest boots, then ready.

The console's Cloud-init builder accepts an SSH public key from your .pub file and previews the generated cloud-config. It installs the key for the image's default user (ubuntu on the default image) at first boot. Use Custom user-data for your own cloud-config or script; the key is added by the server. Adding a key does not change the SSH jump gate's requirement for a tenant-signed certificate.

A tenant with no registered CA is refused here, rather than handed a guest that nothing can reach: the CA set is baked into the guest at create and registering one afterwards does not reach a VM that already exists. Register a CA first—the console's Settings page, eitri ca upload <ca.pub>, or the MCP ca_upload tool—then create the VM.

SSH in

eitri init wrote the plane, the gate and your tenant, so there is nothing left to set:

eitri ssh <vm-name>
eitri ssh <vm-name> uptime

Skipped init? The console and gate fall back to the hosted defaults, and EITRI_TOKEN alone is enough—eitri ssh asks the plane for your tenant and its gate.

Then what