Skip to content

v0.3 · open source

One spec.
Every environment.

Describe your machines, networks and services once. Isoloom weaves them into Docker, local VMs, Proxmox or the cloud, and proves they behave the same on each.

isoloom.ymlone spec
version:
1
name:
invoice-portal
machines:
database:
postgres:16 · debian-12
web:
build/web · debian-12
  • Dockercontainers
  • Local VMsVagrant
  • Proxmoxyour server
  • CloudAWS · Azure · GCP

The drift problem

The same environment,
written five times.

A Compose file for laptops, a Vagrantfile for local VMs, Terraform for the server, more for each cloud. They drift, and nobody notices until the same thing behaves differently somewhere else.

Isoloom keeps one description and treats every other file as output.

docker-compose.ymlport 8080drifted
Vagrantfileport 8081drifted
proxmox/main.tfno databasedrifted
aws/main.tfport 8080in sync
azure/main.tfold imagedrifted
isoloom.ymlone source of truth

How it works

Describe it once. Weave it anywhere.

  1. 01Now

    Describe

    One YAML file: machines, networks, reachability, services.

  2. 02Now

    Derive

    Isoloom works out where it can run, and tells you why it can't elsewhere.

  3. 03Now

    Weave

    It writes each target's files: Compose and Vagrant today, Proxmox and cloud next.

  4. 04Now

    Prove

    The same checks run against the environment. Docker today, VMs next.

isoloom.yml
version: 1
name: invoice-portal

networks:
  app: { cidr: 10.20.0.0/24 }

machines:
  database:
    networks: { app: 32 }
    services: [{ port: 5432 }]
    docker: { image: "postgres:16" }        # as a container
    vm: { os: debian-12, provision: [db.sh] } # as a VM

  web:
    networks: { app: 31 }
    services: [{ port: 8080, http: true }]
    depends_on: [database]
    docker: { build: build/web }
    vm: { os: debian-12, provision: [web.sh] }

checks: [checks/portal-answers.sh]

The spec

The behavior is
the contract.

A spec says what the environment looks like from outside. How each machine gets built is a separate, per-machine choice.

01

Networks

Address blocks, and which network may reach which. Everything else stays blocked.

02

Machines

Where each one sits, what answers on it, what it waits for.

03

Two shapes

A container, a VM with its services installed natively, or both. You choose per machine.

04

Checks

Black-box tests that every target must pass. Same behavior, proven.

Every field, in the reference

Targets

Seven places to run.
Derived, never guessed.

Every machine with a container form unlocks the container targets; every machine with a VM form unlocks the VM targets. A Windows domain controller has no container form, so that environment never gets a broken Compose file.

  • Containers

    Docker

    On your machine

    docker

  • Containers

    Hosted

    Run for your users

    hosted

  • Containers

    Cloud, one host

    AWS, Azure, GCP, DigitalOcean, Linode, Oracle

    cloud-docker

  • VMs

    Local VMs

    VirtualBox, VMware, Parallels, Hyper-V, libvirt

    vagrant

  • VMs

    Proxmox

    Your server, its own SDN network

    proxmox

  • VMs

    Cloud, per machine

    One VM per machine, real subnets

    cloud-vm

  • VMs

    Ludus

    An export for Ludus ranges

    ludus

  • All or nothing

    One machine without a container form rules out every container target. A copy missing a machine doesn’t behave like the original.

The command line

Errors that say
what to do.

Every problem names the exact field and the fix, so a person, a CI job or an AI assistant can correct a spec without reading the tool’s source.

The commands
~/corp-ad-basics
$ isoloom validate
✓ corp-ad-basics is valid

$ isoloom targets
✗ docker (needs `docker:` on dc01, ws01)
✗ hosted (needs `docker:` on dc01, ws01)
✓ vagrant
✓ proxmox
✓ cloud-vm

$ isoloom resources
4 machines · 6 CPUs · 10.0 GB memory · 160 GB disk

Built for

Anything made of several machines.

01

Training labs

Every learner gets the same lab, on a laptop, a lab server or the cloud.

02

Security ranges

Segmented networks, edge firewalls, domains: described once, rebuilt anywhere.

03

Product demos

A multi-service demo that runs on the prospect's machine or yours.

04

Integration environments

The same topology in CI containers and in real VMs before release.

Behavior first

Machines, networks, services: what users see.

Native VMs

No Docker inside a VM. Real machines.

Generic inputs

Launch-time values reach only the machines that ask.

Not a replacement for Docker, Vagrant or Terraform: Isoloom writes their files.

Start with one file.

Write a spec for something you already run. Isoloom tells you everywhere it can go.