Torso is an open source, self-hosted infrastructure orchestration engine written in Rust. Define your infrastructure, databases, applications, DNS, load balancers, and more in a declarative .Torso file, and let Torso handle the rest.
Think of it as CloudFormation, but one you own, run yourself, and extend however you want.
Torso runs as a long lived HTTP server on your infrastructure. You bootstrap it once using the CLI with an initial environment file. After that, everything is driven by HTTP request an .Torso file to the server, and Torso will reconcile your desired state with reality.
Torso init --file environment.Torso # Bootstrap your environment
Torso serve # Start the Torso HTTP server
curl -X POST http://localhost:7070/apply \
-H "Content-Type: application/x-Torso" \
--data-binary @my-service.Torso # Deploy a new service
No proprietary dashboards. No cloud lock in. Just Rust, HTTP, and a file.
An .Torso file is a declarative YAML based configuration that describes the desired state of a resource or environment. It follows a simple kind + spec structure:
kind: Database
metadata:
name: my_postgres
spec:
engine: postgres
version: "15"
storage: 20Gi
replicas: 1kind: App
metadata:
name: my_api
spec:
image: ghcr.io/myorg/api:latest
port: 8080
replicas: 2
env:
- name: DATABASE_URL
value: postgres://...Torso reads the kind field and routes it to the correct provisioner under the hood.
- Self hosted first — Torso runs on your hardware, your cloud, your rules.
- File driven — everything is defined in an
.Torsofile. No hidden state in a UI. - HTTP native — the engine is an API. Automate it, wrap it, integrate it.
- Pluggable — providers are first-class. Torso doesn't dictate where you run.
- Rust all the way — single binary, fast startup, easy to deploy Torso itself.
- Define the
.Torsofile specification (YAML-based,kind+specpattern) - Build the CLI (
Torso init,Torso serve,Torso apply,Torso status,Torso destroy) - Bootstrap environment from an initial
.Torsofile viaTorso init - Start the Torso HTTP server via
Torso init - Accept
.Torsofile payloads over HTTPPOST /apply - Parse, validate, and route resource kinds to their provisioners
- Basic state tracking, know what has been created, updated, or removed
- Provision PostgreSQL instances
- Provision MySQL instances
- Provision Redis instances
- Support configurable storage size, version, and replica count
- Lifecycle management, create, update, and destroy
- Connection string output exposed after provisioning
- Deploy containerized applications from an image registry
- Configure environment variables and secrets
- Set replica count and resource limits (CPU/memory)
- Rolling deploy support, update without downtime
- Health check configuration (HTTP or TCP)
- Restart policies and crash recovery
- Register and manage DNS records (A, CNAME, TXT, MX)
- Attach a domain to a deployed application automatically
- Support multiple DNS providers (Cloudflare, Route53, etc.) via pluggable drivers
- TTL configuration per record
- Automatic DNS cleanup on resource destroy
- Create and configure HTTP/HTTPS load balancers
- Route traffic to one or more application instances
- Support round-robin and least-connections strategies
- SSL/TLS termination with automatic certificate provisioning (via Let's Encrypt)
- Health-check-aware routing, remove unhealthy instances automatically
- Secrets store, store and inject secrets into apps at deploy time
- Support referencing secrets inside
.Torsofiles via${{ secret.name }}syntax - Encryption at rest for stored secrets
- Secret rotation support
- Define virtual private networks (VPNs/VPCs) and subnets
- Configure firewall rules, allow/deny by port, protocol, and CIDR
- Private networking between services (service discovery by name)
- Public/private toggle per service
- Provision and manage object storage buckets
- Configure bucket policies (public read, private, etc.)
- Mount buckets as volumes in application containers
- S3 compatible API support
- Expose resource status via
GET /status/:name - Structured event log per resource (created, updated, failed, destroyed)
- Metrics endpoint (
/metrics) compatible with Prometheus - Deploy time dry run mode, validate a file without applying it (
POST /plan)
- Pluggable provider architecture, write your own provisioner in Rust
- Official providers: Docker, Kubernetes, DigitalOcean, Hetzner, AWS
- Provider registry, install providers via
Torso provider add <name> - Provider versioning and pinning inside
.Torsofiles
Torso is in early development. Contributions, ideas, and feedback are very welcome. Open an issue or a pull request.
Apache 2.0