v0.3 · open source · written in Rust
One spec.
Every environment.
Describe your machines, networks and services once. Isoloom weaves them into Docker, local VMs, Proxmox or the cloud, and proves they behave the same on each.
- version:
- 1
- name:
- invoice-portal
- machines:
- database:
- postgres:16 · debian-12
- web:
- build/web · debian-12
- Dockercontainers
- Local VMsVagrant
- Proxmoxyour server
- CloudAWS · Azure · GCP
The drift problem
The same environment,
written five times.
A Compose file for laptops, a Vagrantfile for local VMs, Terraform for the server, more for each cloud. They drift, and nobody notices until the same thing behaves differently somewhere else.
Isoloom keeps one description and treats every other file as output.
How it works
Describe it once. Weave it anywhere.
- 01Now
Describe
One YAML file: machines, networks, reachability, services.
- 02Now
Derive
Isoloom works out where it can run, and tells you why it can't elsewhere.
- 03Now
Weave
It writes each target's files: Compose and Vagrant today, Proxmox and cloud next.
- 04Now
Prove
The same checks run against the environment. Docker today, VMs next.
version: 1
name: invoice-portal
networks:
app: { cidr: 10.20.0.0/24 }
machines:
database:
networks: { app: 32 }
services: [{ port: 5432 }]
docker: { image: "postgres:16" } # as a container
vm: { os: debian-12, provision: [db.sh] } # as a VM
web:
networks: { app: 31 }
services: [{ port: 8080, http: true }]
depends_on: [database]
docker: { build: build/web }
vm: { os: debian-12, provision: [web.sh] }
checks: [checks/portal-answers.sh]
The spec
The behavior is
the contract.
A spec says what the environment looks like from outside. How each machine gets built is a separate, per-machine choice.
- 01
Networks
Address blocks, and which network may reach which. Everything else stays blocked.
- 02
Machines
Where each one sits, what answers on it, what it waits for.
- 03
Two shapes
A container, a VM with its services installed natively, or both. You choose per machine.
- 04
Checks
Black-box tests that every target must pass. Same behavior, proven.
Targets
Seven places to run.
Derived, never guessed.
Every machine with a container form unlocks the container targets; every machine with a VM form unlocks the VM targets. A Windows domain controller has no container form, so that environment never gets a broken Compose file.
Containers
Docker
On your machine
docker
Containers
Hosted
Run for your users
hosted
Containers
Cloud, one host
AWS, Azure, GCP, DigitalOcean, Linode, Oracle
cloud-docker
VMs
Local VMs
VirtualBox, VMware, Parallels, Hyper-V, libvirt
vagrant
VMs
Proxmox
Your server, its own SDN network
proxmox
VMs
Cloud, per machine
One VM per machine, real subnets
cloud-vm
VMs
Ludus
An export for Ludus ranges
ludus
All or nothing
One machine without a container form rules out every container target. A copy missing a machine doesn’t behave like the original.
The command line
Errors that say
what to do.
Every problem names the exact field and the fix, so a person, a CI job or an AI assistant can correct a spec without reading the tool’s source.
The commands$ isoloom validate
✓ corp-ad-basics is valid
$ isoloom targets
✗ docker (needs `docker:` on dc01, ws01)
✗ hosted (needs `docker:` on dc01, ws01)
✓ vagrant
✓ proxmox
✓ cloud-vm
$ isoloom resources
4 machines · 6 CPUs · 10.0 GB memory · 160 GB diskBuilt for
Anything made of several machines.
Training labs
Every learner gets the same lab, on a laptop, a lab server or the cloud.
Security ranges
Segmented networks, edge firewalls, domains: described once, rebuilt anywhere.
Product demos
A multi-service demo that runs on the prospect's machine or yours.
Integration environments
The same topology in CI containers and in real VMs before release.
Behavior first
Machines, networks, services: what users see.
Native VMs
No Docker inside a VM. Real machines.
Generic inputs
Launch-time values reach only the machines that ask.
Not a replacement for Docker, Vagrant or Terraform: Isoloom writes their files.
Start with one file.
Write a spec for something you already run. Isoloom tells you everywhere it can go.