How Dewy Deploys Applications to Non-Kubernetes Environments: Bare Metal and VM Guide
Dewy is purpose-built to deploy applications to non-Kubernetes environments, including bare-metal servers, virtual machines, and standard Linux hosts using Docker or Podman runtimes.
Dewy (linyows/dewy) is an open-source deployment supervisor designed for declarative application delivery on infrastructure that lacks Kubernetes orchestration. Unlike tools that require cluster APIs, Dewy deploys applications to non-Kubernetes environments by treating each target host as an independent supervisor that polls artifact registries and manages local processes through three distinct deployment modes.
Why Dewy Targets Non-Kubernetes Infrastructure
Traditional container orchestration platforms like Kubernetes introduce significant complexity for teams running simple workloads on bare metal or virtual machines. Dewy fills this gap by providing a lightweight supervisor that runs directly on the host, continuously polling registries such as GitHub Releases, OCI registries, Amazon S3, or Google Cloud Storage for new artifacts.
When Dewy detects a newer semantic version, it automatically downloads the artifact and deploys it using one of three modes: Server (compiled binaries), Assets (static files), or Container (OCI images). This architecture eliminates the need for control planes, etcd clusters, or complex networking overlays while still enabling zero-downtime deployments.
Three Deployment Modes for Bare-Metal Hosts
Server Mode: Binary Deployment on Bare Metal
Server mode deploys compiled binaries—typically Go applications—directly onto the host filesystem. Dewy pulls the binary from the configured registry, extracts it into a releases/ directory, updates a current symlink to point to the latest version, and starts the process under its own supervision using exec.Command.
The supervisor continuously monitors the registry for newer versions. When detected, Dewy downloads the update, swaps the symlink, and restarts the process. This mechanism is implemented in dewy.go and provides automatic rollback capabilities by simply reverting the symlink if the new binary fails health checks.
Assets Mode: Static File Synchronization
Assets mode synchronizes static files—HTML, CSS, JavaScript, or configuration files—directly to a target directory on the host. Dewy polls the artifact registry for new versions of the asset bundle, downloads the archive, and extracts it to the specified destination, such as /var/www/html for web servers.
This mode keeps the document root in sync with the latest release without requiring manual SCP or rsync operations. The implementation handles atomic updates by writing to a temporary directory and performing a rename operation, ensuring that web servers never serve partially written files during the deployment process.
Container Mode: Docker and Podman on Linux Hosts
Container mode enables zero-downtime deployment of OCI container images on standard Linux hosts using either Docker or Podman. Dewy abstracts the container runtime through the container.Runtime interface defined in container/container.go, allowing the same deployment logic to work with either runtime.
When deploying, Dewy pulls the image, starts a new container with a unique name, performs health checks against the specified endpoint, and then swaps traffic to the new container before terminating the old one. This rolling-update strategy works on any host where the Docker or Podman CLI is installed, without requiring Kubernetes Deployments or Services.
The Docker implementation resides in container/docker.go and handles registry authentication, image pulling, and container lifecycle management. The Podman implementation in container/podman.go provides identical functionality for daemon-less environments, supporting RHEL, CentOS Stream, and other enterprise Linux distributions.
Key Architecture Components for Non-Kubernetes Deployment
The Container Runtime Interface
The container.Runtime interface in container/container.go (lines 16-56) abstracts container operations, enabling Dewy to deploy to non-Kubernetes environments using either Docker or Podman. This interface defines methods for pulling images, logging into registries, running containers, and checking container status.
Docker and Podman Implementations
The container/docker.go file (lines 17-106) implements the Runtime interface for Docker, handling image pulls, registry authentication, and container execution with proper user permissions (adding --user to avoid root execution). The container/podman.go file provides an identical implementation for Podman, allowing deployment on systems where Docker is unavailable or undesirable.
Supervisor Loop and CLI
The core deployment logic resides in dewy.go, which implements the supervisor loop that continuously polls registries, detects semantic version updates, and triggers the appropriate deployment mode. The CLI entry point in cmd/dewy/main.go exposes the three deployment modes through the dewy server, dewy assets, and dewy container commands.
Deploying to Bare Metal: Practical Examples
Deploy a Container Image on Bare Metal with Docker
Run the following command on your Linux host to deploy a container image with zero-downtime rolling updates:
dewy container \
--registry img://ghcr.io/linyows/myapp \
--port 8080 \
--health-path /health \
-- -e DATABASE_URL=postgres://db:5432/mydb -v /data:/app/data
This command uses Dewy’s container mode, which internally calls the Docker runtime implementation in container/docker.go to pull images, create containers, and manage health checks.
Deploy a Binary Server Application on Bare Metal
For compiled binaries without containerization, use server mode:
dewy server \
--registry ghr://linyows/myapp \
-p 8000 -l info \
-- /opt/myapp/current/myapp
Dewy pulls the binary from GitHub Releases, places it under a releases/ directory, updates the current symlink, and runs the binary as a supervised process. The supervisor logic in dewy.go automatically restarts the process when new versions appear.
Deploy Static Assets on a Bare-Metal Web Server
For frontend applications or static content:
dewy assets \
--registry ghr://linyows/frontend \
-d /var/www/html \
-l info
Dewy synchronizes files from the registry to the target directory, ensuring your web server serves the latest version without manual file transfers.
Using the Go API for Custom Deployments
Integrate Dewy’s container runtime directly into your Go applications:
package main
import (
"context"
"log/slog"
"os"
"time"
"github.com/linyows/dewy/container"
)
func main() {
logger := slog.New(slog.NewTextHandler(os.Stderr, nil))
rt, err := container.NewDocker(logger, 30*time.Second)
if err != nil {
panic(err)
}
// Pull and run an image on the host
if err := rt.Pull(context.Background(), "ghcr.io/linyows/myapp:latest"); err != nil {
panic(err)
}
_, err = rt.Run(context.Background(), container.RunOptions{
Image: "ghcr.io/linyows/myapp:latest",
AppName: "myapp",
Ports: []string{"8080:8080"},
Detach: true,
})
if err != nil {
panic(err)
}
}
The container.Runtime interface works on any Linux host with the Docker or Podman CLI installed, enabling programmatic deployments without Kubernetes APIs.
Summary
- Dewy is purpose-built for non-Kubernetes environments, providing declarative deployment capabilities for bare-metal servers, virtual machines, and standard Linux hosts.
- Three deployment modes support diverse application types: Server mode for compiled binaries, Assets mode for static files, and Container mode for OCI images using Docker or Podman.
- Zero-downtime updates are achieved through symlink swapping for binaries and rolling container updates for images, all without requiring orchestration layers.
- Pluggable container runtimes via the
container.Runtimeinterface allow Dewy to work with either Docker or Podman on any compatible Linux host.
Frequently Asked Questions
Can Dewy deploy to servers without Docker installed?
Yes, Dewy can deploy to servers without Docker using Server mode for compiled binaries or Assets mode for static files. These modes require only a Linux host capable of executing binaries or serving files, with no container runtime necessary. Server mode manages binary releases through symlinks and process supervision, while Assets mode synchronizes files directly to target directories.
Does Dewy support Podman for container deployments on RHEL systems?
Yes, Dewy supports Podman through the container.Runtime interface implemented in container/podman.go. This allows deployment on Red Hat Enterprise Linux, CentOS Stream, and other enterprise distributions where Podman is the preferred daemon-less container runtime. The Podman implementation provides identical functionality to the Docker backend, including image pulling, registry authentication, and zero-downtime rolling updates.
How does Dewy achieve zero-downtime deployments without Kubernetes?
Dewy achieves zero-downtime deployments through host-local orchestration strategies. For Container mode, Dewy starts a new container alongside the running instance, performs health checks, and then swaps traffic by stopping the old container only after the new one is healthy. For Server mode, Dewy uses atomic symlink operations to switch between binary versions, ensuring the running process always points to a complete release. These mechanisms are implemented in dewy.go and the respective container runtime files without requiring Kubernetes Deployments or Services.
What artifact registries does Dewy support for bare-metal deployments?
Dewy supports multiple artifact registries for bare-metal deployments, including GitHub Releases (ghr://), OCI registries (img:// such as GHCR or Docker Hub), Amazon S3, and Google Cloud Storage. The supervisor continuously polls these registries to detect new semantic versions, then downloads and deploys artifacts using the appropriate mode for the application type.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →