<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Barn — Linux and macOS virtual machines on Barn</title>
    <link>https://barn.pgsty.com/</link>
    <description>Recent content in Barn — Linux and macOS virtual machines on Barn</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    
    
    
      <lastBuildDate>Wed, 30 Sep 2026 00:00:00 +0800</lastBuildDate>
    
    
      <atom:link href="https://barn.pgsty.com/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
        <title>Install Barn</title>
        <link>https://barn.pgsty.com/docs/start/installation/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/installation/</guid>
        <description>&lt;p&gt;Barn 0.9.0 provides archives for macOS and Linux on &lt;strong&gt;arm64 and amd64&lt;/strong&gt;,&#xA;plus DEB and RPM packages for Linux. Install it as your normal user, then follow&#xA;the &lt;a href=&#34;../tutorial/&#34;&gt;Linux quick start&lt;/a&gt; or &lt;a href=&#34;../macos/&#34;&gt;macOS VM guide&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;install-the-release&#34;&gt;Install the release&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Choose your &lt;strong&gt;host operating system&lt;/strong&gt;: use Homebrew on macOS or the download&#xA;installer on Linux.&lt;/p&gt;&#xA;&lt;div class=&#34;td-tabs td-tabs--shortcode&#34; id=&#34;td-tabs-5caa8b5d-0&#34;&gt;&#xA;  &lt;div class=&#34;td-tabs__panel&#34; id=&#34;barn-install-macos&#34; data-td-tabs-value=&#34;macos&#34; data-td-tabs-active&gt;&#xA;    &lt;div class=&#34;td-tabs__panel-title&#34; aria-hidden=&#34;true&#34;&gt;macOS&lt;/div&gt;&#xA;    &lt;div class=&#34;td-tabs__panel-body&#34;&gt;&lt;p&gt;Install Barn and its QEMU dependency with &lt;a href=&#34;https://brew.sh/&#34;&gt;Homebrew&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-5caa8b5d-tabs0-macos-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;2&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-5caa8b5d-tabs0-macos-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;brew install pgsty/infra/barn&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn version&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;Run &lt;code&gt;brew&lt;/code&gt; as your normal user, without sudo. macOS guests also require Apple&#xA;Silicon, macOS 27+, and &lt;code&gt;Barn Mac.app&lt;/code&gt;. Run &lt;code&gt;barn mac doctor&lt;/code&gt; to check the native&#xA;component; see the &lt;a href=&#34;../macos/#install&#34;&gt;Mac installation instructions&lt;/a&gt;.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Why Barn Has No Projects</title>
        <link>https://barn.pgsty.com/blog/design/one-deployment-no-projects/</link>
        <pubDate>Thu, 27 Aug 2026 19:00:00 +0800</pubDate>
        
        <guid>https://barn.pgsty.com/blog/design/one-deployment-no-projects/</guid>
        <description>&lt;p&gt;This article describes Barn 0.9.0. The VM lifecycle and network design here&#xA;apply to Linux guests; &lt;a href=&#34;https://barn.pgsty.com/docs/start/macos/&#34;&gt;Mac machines&lt;/a&gt; are managed independently.&lt;/p&gt;&#xA;&lt;p&gt;Barn began with a familiar VM-manager abstraction: a working directory was&#xA;a project, a hidden marker gave it identity, a registry found projects again,&#xA;and a host-global lease kept their private networks from colliding. That model&#xA;can support many independent VM sets. It was also the wrong model for the&#xA;product Barn was actually becoming.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Configuration</title>
        <link>https://barn.pgsty.com/docs/reference/configuration/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/reference/configuration/</guid>
        <description>&lt;p&gt;This reference covers &lt;strong&gt;Barn 0.9.0&lt;/strong&gt;. Check&#xA;&lt;code&gt;barn version&lt;/code&gt; when using another version.&lt;/p&gt;&#xA;&lt;h2 id=&#34;discovery&#34;&gt;Discovery&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Configuration lookup order is explicit &lt;code&gt;-f&lt;/code&gt;, then &lt;code&gt;barn.yml&lt;/code&gt;,&#xA;&lt;code&gt;barn.yaml&lt;/code&gt;, &lt;code&gt;pigsty.yml&lt;/code&gt;, and &lt;code&gt;pigsty.yaml&lt;/code&gt; in the current directory. Every&#xA;name uses the same Pigsty-compatible YAML inventory format.&lt;/p&gt;&#xA;&lt;p&gt;For &lt;code&gt;plan&lt;/code&gt;, &lt;code&gt;up&lt;/code&gt;, &lt;code&gt;reload&lt;/code&gt;, and &lt;code&gt;recreate&lt;/code&gt;, absence of a file falls back to&#xA;the applied spec when a deployment exists. &lt;code&gt;validate&lt;/code&gt; has no fallback. A&#xA;configuration must be a regular non-symlink file no larger than 4 MiB. The first&#xA;existing discovery candidate wins; if it is invalid, Barn reports the error&#xA;instead of trying the next filename. Renaming a file or moving directories does&#xA;not create another deployment; applied state lives in &lt;code&gt;BARN_HOME&lt;/code&gt;.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Linux Quick Start</title>
        <link>https://barn.pgsty.com/docs/start/tutorial/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/tutorial/</guid>
        <description>&lt;p&gt;Create an Ubuntu 24.04 VM on your Mac or Linux host, then expand it into a lab.&#xA;For macOS guests, use the separate &lt;a href=&#34;../macos/&#34;&gt;Mac guide&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;install&#34;&gt;Before you start&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;../installation/&#34;&gt;Install Barn 0.9.0&lt;/a&gt; and reserve at least 4 GiB of guest memory&#xA;plus room for the host. Run these commands as your normal user in a terminal.&#xA;Barn can prepare QEMU and the private network; host changes may require sudo.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Platforms and Limits</title>
        <link>https://barn.pgsty.com/docs/about/status/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/about/status/</guid>
        <description>&lt;p&gt;Barn is built for &lt;strong&gt;local development and testing&lt;/strong&gt;. This page helps you choose&#xA;a host and understand what each guest type supports.&lt;/p&gt;&#xA;&lt;h2 id=&#34;documentation-baseline&#34;&gt;Version&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;These docs cover &lt;strong&gt;Barn 0.9.0&lt;/strong&gt;. Install the &lt;a href=&#34;../../start/installation/&#34;&gt;release&lt;/a&gt;,&#xA;check &lt;code&gt;barn version&lt;/code&gt;, and read the &lt;a href=&#34;https://barn.pgsty.com/blog/release/0.9.0/&#34;&gt;release notes&lt;/a&gt; for changes.&#xA;The Linux image catalog updates independently with &lt;code&gt;barn update&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;linux-guests&#34;&gt;Linux guests&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table class=&#34;platform-table&#34;&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Host&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Architecture&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Native acceleration&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Minimum QEMU&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;macOS&lt;/td&gt;&#xA;      &lt;td&gt;arm64 (Apple Silicon), amd64 (Intel)&lt;/td&gt;&#xA;      &lt;td&gt;HVF&lt;/td&gt;&#xA;      &lt;td&gt;8.2.1&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Linux&lt;/td&gt;&#xA;      &lt;td&gt;amd64, arm64&lt;/td&gt;&#xA;      &lt;td&gt;KVM&lt;/td&gt;&#xA;      &lt;td&gt;6.2&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;Barn builds for all four targets. The principal native test paths are macOS&#xA;arm64 and Linux amd64; Intel macOS and Linux arm64 have narrower validation&#xA;coverage. Linux also requires usable &lt;code&gt;/dev/kvm&lt;/code&gt; and NetworkManager or&#xA;systemd-networkd. &lt;code&gt;barn doctor&lt;/code&gt; checks the host; &lt;code&gt;barn setup --dry-run&lt;/code&gt; shows&#xA;the dependency and network changes for your machine.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Why Every Barn Node Has Two NICs</title>
        <link>https://barn.pgsty.com/blog/design/fixed-ip-two-nics/</link>
        <pubDate>Thu, 27 Aug 2026 20:00:00 +0800</pubDate>
        
        <guid>https://barn.pgsty.com/blog/design/fixed-ip-two-nics/</guid>
        <description>&lt;p&gt;This article describes Barn 0.9.0. The VM lifecycle and network design here&#xA;apply to Linux guests; &lt;a href=&#34;https://barn.pgsty.com/docs/start/macos/&#34;&gt;Mac machines&lt;/a&gt; are managed independently.&lt;/p&gt;&#xA;&lt;p&gt;A Pigsty inventory names machines by stable addresses. PostgreSQL replication,&#xA;etcd membership, HAProxy backends, VIPs, monitoring targets, and Ansible all&#xA;assume that &lt;code&gt;10.10.10.11&lt;/code&gt; continues to mean the same node. A loopback port&#xA;forward can expose SSH or PostgreSQL to the host, but it cannot provide that&#xA;network identity to peers.&lt;/p&gt;</description>
      </item>
    <item>
        <title>CLI</title>
        <link>https://barn.pgsty.com/docs/reference/cli/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/reference/cli/</guid>
        <description>&lt;p&gt;This reference covers common options and Linux lab commands in &lt;strong&gt;Barn 0.9.0&lt;/strong&gt;.&#xA;For macOS guests, see &lt;a href=&#34;../mac/&#34;&gt;Mac commands&lt;/a&gt;. Check&#xA;&lt;code&gt;barn version&lt;/code&gt; when using another version.&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-9455d335-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;text&#34; data-td-line-count=&#34;1&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-9455d335-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn [--json|--yaml] [-v|--verbose] &amp;lt;command&amp;gt; [flags] [node...]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;The installed binary is the authoritative reference for its own version. Every&#xA;visible command includes its operational boundary and copyable examples:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-9455d335-fence-1&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;3&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-9455d335-fence-1-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn --help&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn setup --help&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn image pull --help&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;Bare &lt;code&gt;barn&lt;/code&gt; prints a short welcome with next commands, exits 0, and exposes&#xA;&lt;code&gt;actions[]&lt;/code&gt; in JSON/YAML. A bare namespace&#xA;such as &lt;code&gt;barn image&lt;/code&gt; still exits 2 (human help in text mode, a structured usage&#xA;error in JSON/YAML). Explicit &lt;code&gt;--help&lt;/code&gt; always renders human help and exits 0.&#xA;Use &lt;code&gt;barn --version&lt;/code&gt; or &lt;code&gt;barn version&lt;/code&gt; to inspect the build identity.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Design</title>
        <link>https://barn.pgsty.com/docs/about/design/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/about/design/</guid>
        <description>&lt;p&gt;Barn provides two workflows that share a CLI but keep their configuration and&#xA;lifecycle separate.&lt;/p&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Linux labs&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;macOS guests&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Virtualization&lt;/td&gt;&#xA;      &lt;td&gt;QEMU with HVF or KVM; TCG for selected compatibility cases&lt;/td&gt;&#xA;      &lt;td&gt;Apple Virtualization.framework&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Desired state&lt;/td&gt;&#xA;      &lt;td&gt;A Pigsty-compatible YAML inventory&lt;/td&gt;&#xA;      &lt;td&gt;Named machines configured with &lt;code&gt;barn mac&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;State directory&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;~/.barn&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;~/.barn/mac&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Networking&lt;/td&gt;&#xA;      &lt;td&gt;Management NIC plus a fixed-IP lab subnet&lt;/td&gt;&#xA;      &lt;td&gt;One NAT subnet and DHCP reservation per machine&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Typical work&lt;/td&gt;&#xA;      &lt;td&gt;Database clusters, Linux development and automation&lt;/td&gt;&#xA;      &lt;td&gt;macOS builds, desktop tools and isolated development&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;The sections below explain the Linux lab model. For the native macOS workflow,&#xA;see &lt;a href=&#34;../../start/macos/&#34;&gt;macOS guests&lt;/a&gt; and the &lt;a href=&#34;../../reference/mac/&#34;&gt;Mac reference&lt;/a&gt;.&lt;/p&gt;</description>
      </item>
    <item>
        <title>macOS Virtual Machines</title>
        <link>https://barn.pgsty.com/docs/start/macos/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/macos/</guid>
        <description>&lt;p&gt;&lt;code&gt;barn mac&lt;/code&gt; creates and runs macOS virtual machines on an Apple Silicon Mac.&#xA;Each machine is a clean, disposable macOS with an administrator account,&#xA;passwordless sudo, pinned SSH keys and a fixed address — for testing, building&#xA;and reproducing macOS-specific behavior. It uses Apple&amp;rsquo;s Virtualization&#xA;framework directly and needs no administrator access.&lt;/p&gt;&#xA;&lt;p&gt;Mac machines are separate from the Linux lab. They never read &lt;code&gt;barn.yml&lt;/code&gt;,&#xA;never join a Pigsty inventory, and keep their files under &lt;code&gt;$BARN_HOME/mac&lt;/code&gt;&#xA;(default &lt;code&gt;~/.barn/mac&lt;/code&gt;). Linux &lt;code&gt;destroy&lt;/code&gt; and &lt;code&gt;purge&lt;/code&gt; leave them alone.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Mac Commands</title>
        <link>https://barn.pgsty.com/docs/reference/mac/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/reference/mac/</guid>
        <description>&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-13c8229b-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;text&#34; data-td-line-count=&#34;1&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-13c8229b-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn [--json|--yaml] [-v|--verbose] mac &amp;lt;command&amp;gt; [flags] [name...]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;&lt;code&gt;barn mac&lt;/code&gt; requires Apple Silicon and macOS 27 or later, and runs as the&#xA;logged-in user; it refuses to run as root. On other hosts the command is&#xA;hidden, and commands that need the Mac component fail with&#xA;&lt;code&gt;mac_host_unsupported&lt;/code&gt;. Bare &lt;code&gt;barn mac&lt;/code&gt; is &lt;code&gt;barn mac ls&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;commands&#34;&gt;Commands&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Command&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Purpose&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;ls&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;every machine with state, address, SSH, macOS, resources and shares; aliases &lt;code&gt;list&lt;/code&gt;, &lt;code&gt;status&lt;/code&gt;, &lt;code&gt;st&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;up [name]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;create the machine if needed, start it, wait for SSH and sudo&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;start [name...]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;start existing machines&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;stop [name...]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;shut down normally; power off after two minutes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;restart [name]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;stop, then start, applying configuration changes&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;open [name]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;show the desktop, starting the machine first if needed&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;ssh [name]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;interactive shell, or, after &lt;code&gt;--&lt;/code&gt;, a command line for the guest shell&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;exec [name] -- cmd&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;run a command, keeping argument boundaries&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;configure name&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;change a machine&amp;rsquo;s settings&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;recreate name&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;replace the machine with a fresh macOS, keeping its settings&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;destroy name...&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;delete machines&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;password [name]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;show or copy the login password&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;ssh-config&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;print, install or remove the OpenSSH entries&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;logs [name]&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;recent runtime log&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;setup&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;prepare the macOS base without creating a machine&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;image ls&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;restore images and bases with the machines using them; alias &lt;code&gt;list&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;image update&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;prepare Apple&amp;rsquo;s newest macOS 27 as the default base&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;image prune&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;list, and with &lt;code&gt;--yes&lt;/code&gt; delete, unused images&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;doctor&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;check the host, the component, the base and every machine&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;h3 id=&#34;flags-by-command&#34;&gt;Flags by command&#xA;&lt;/h3&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Command&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Flags&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;up&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--cpu&lt;/code&gt; &lt;code&gt;--memory&lt;/code&gt; &lt;code&gt;--disk&lt;/code&gt; &lt;code&gt;--user&lt;/code&gt; &lt;code&gt;--share&lt;/code&gt; &lt;code&gt;--clipboard&lt;/code&gt; &lt;code&gt;--subnet&lt;/code&gt; &lt;code&gt;--ipsw&lt;/code&gt; &lt;code&gt;-y&lt;/code&gt;/&lt;code&gt;--yes&lt;/code&gt; &lt;code&gt;-n&lt;/code&gt;/&lt;code&gt;--no-wait&lt;/code&gt; &lt;code&gt;--open&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;start&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--all&lt;/code&gt; &lt;code&gt;-n&lt;/code&gt;/&lt;code&gt;--no-wait&lt;/code&gt; &lt;code&gt;--open&lt;/code&gt; &lt;code&gt;--recovery&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;stop&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--all&lt;/code&gt; &lt;code&gt;--force&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;restart&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;-n&lt;/code&gt;/&lt;code&gt;--no-wait&lt;/code&gt; &lt;code&gt;--open&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;configure&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--cpu&lt;/code&gt; &lt;code&gt;--memory&lt;/code&gt; &lt;code&gt;--share&lt;/code&gt; &lt;code&gt;--unshare&lt;/code&gt; &lt;code&gt;--clipboard&lt;/code&gt; &lt;code&gt;--subnet&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;recreate&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--update&lt;/code&gt; &lt;code&gt;--force&lt;/code&gt; &lt;code&gt;-n&lt;/code&gt;/&lt;code&gt;--no-wait&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;destroy&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--force&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;password&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;-c&lt;/code&gt;/&lt;code&gt;--copy&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;ssh-config&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;-i&lt;/code&gt;/&lt;code&gt;--install&lt;/code&gt; &lt;code&gt;--remove&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;logs&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;-n&lt;/code&gt;/&lt;code&gt;--lines&lt;/code&gt; (default 100, at most 10000)&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;setup&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--ipsw&lt;/code&gt; &lt;code&gt;--disk&lt;/code&gt; &lt;code&gt;-y&lt;/code&gt;/&lt;code&gt;--yes&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;image update&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--ipsw&lt;/code&gt; &lt;code&gt;-y&lt;/code&gt;/&lt;code&gt;--yes&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;&lt;code&gt;image prune&lt;/code&gt;&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;--installers&lt;/code&gt; &lt;code&gt;-y&lt;/code&gt;/&lt;code&gt;--yes&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;A command without a machine name acts on the only machine, or on &lt;code&gt;mac1&lt;/code&gt;; with&#xA;several machines and none named &lt;code&gt;mac1&lt;/code&gt;, it asks for a name. &lt;code&gt;start&lt;/code&gt; and &lt;code&gt;stop&lt;/code&gt;&#xA;accept several names, or &lt;code&gt;--all&lt;/code&gt;. &lt;code&gt;destroy&lt;/code&gt; and &lt;code&gt;recreate&lt;/code&gt; describe what they&#xA;delete and ask for the command name to be typed; &lt;code&gt;--force&lt;/code&gt; confirms without a&#xA;terminal.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Declarative Does Not Mean Destructive</title>
        <link>https://barn.pgsty.com/blog/design/convergence-without-surprise/</link>
        <pubDate>Thu, 27 Aug 2026 21:00:00 +0800</pubDate>
        
        <guid>https://barn.pgsty.com/blog/design/convergence-without-surprise/</guid>
        <description>&lt;p&gt;This article describes Barn 0.9.0. The VM lifecycle and network design here&#xA;apply to Linux guests; &lt;a href=&#34;https://barn.pgsty.com/docs/start/macos/&#34;&gt;Mac machines&lt;/a&gt; are managed independently.&lt;/p&gt;&#xA;&lt;p&gt;“Declarative” is often shortened to “make reality equal the file.” That is a&#xA;useful slogan until the file is incomplete, the wrong branch is checked out,&#xA;or one YAML group is temporarily removed. If absence is treated as deletion,&#xA;an ordinary editing mistake becomes a destructive operation.&lt;/p&gt;&#xA;&lt;p&gt;Barn uses a narrower rule:&lt;/p&gt;</description>
      </item>
    <item>
        <title>Contributing</title>
        <link>https://barn.pgsty.com/docs/about/engineering/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/about/engineering/</guid>
        <description>&lt;p&gt;Barn is an Apache-2.0 project. Contributions to the CLI, native macOS&#xA;component, documentation, and image tooling are welcome.&lt;/p&gt;&#xA;&lt;h2 id=&#34;choose-a-repository&#34;&gt;Choose a repository&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;What you want to change&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Where to work&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;CLI behavior, VM lifecycle, native macOS component, installer, packages&lt;/td&gt;&#xA;      &lt;td&gt;&lt;a href=&#34;https://github.com/pgsty/barn&#34;&gt;pgsty/barn&lt;/a&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;This website, tutorials, command reference, translations&lt;/td&gt;&#xA;      &lt;td&gt;&lt;a href=&#34;https://github.com/pgsty/barn.pgsty.com&#34;&gt;pgsty/barn.pgsty.com&lt;/a&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;An image definition or normalization step&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;packaging/image-repository/&lt;/code&gt; and &lt;code&gt;packaging/image-pipeline/&lt;/code&gt; in the Barn source repository&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;For a bug report, include &lt;code&gt;barn version&lt;/code&gt;, the host OS and architecture, the&#xA;command you ran, and the relevant error. Remove private keys, passwords, and&#xA;other secrets from logs and inventories. Report security issues using the&#xA;&lt;a href=&#34;https://github.com/pgsty/barn/blob/main/SECURITY.md&#34;&gt;security policy&lt;/a&gt;.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Daily Operations</title>
        <link>https://barn.pgsty.com/docs/start/operations/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/operations/</guid>
        <description>&lt;p&gt;This guide covers Linux labs in &lt;strong&gt;Barn 0.9.0&lt;/strong&gt;. For Mac machines, use the&#xA;&lt;a href=&#34;../macos/#everyday-lifecycle&#34;&gt;macOS guide&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;inspect-and-access&#34;&gt;Inspect and access&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-ab9c2dd3-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;4&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-ab9c2dd3-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn status&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn ssh meta&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn &lt;span class=&#34;nb&#34;&gt;exec&lt;/span&gt; node-1 -- hostname&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn logs meta --source serial&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;Applied state is under &lt;code&gt;~/.barn&lt;/code&gt; by default (&lt;code&gt;BARN_HOME&lt;/code&gt; overrides it); these&#xA;commands work from any directory. Changing the working directory does not create&#xA;a separate deployment.&#xA;Status shows images and resources; &lt;code&gt;--verbose&lt;/code&gt; adds architecture, accelerator,&#xA;SSH ports, and PID. TCG is marked in ordinary output, and a degraded node does&#xA;not hide its peers.&#xA;&lt;code&gt;barn up&lt;/code&gt; rebuilds the default SSH aliases from the complete applied&#xA;deployment after the selected VMs are started, so a scoped &lt;code&gt;up&lt;/code&gt; never drops&#xA;unselected peers and plain &lt;code&gt;ssh meta&lt;/code&gt; just works; &lt;code&gt;barn ssh-config --install&lt;/code&gt;&#xA;rewrites it by hand if you ever need to.&#xA;&lt;code&gt;plan&lt;/code&gt;, &lt;code&gt;up&lt;/code&gt;, &lt;code&gt;reload&lt;/code&gt;, and &lt;code&gt;recreate&lt;/code&gt; prefer &lt;code&gt;-f&lt;/code&gt;, then a discovered&#xA;inventory, then the applied spec when no file exists. &lt;code&gt;validate&lt;/code&gt; always needs&#xA;a file.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Images</title>
        <link>https://barn.pgsty.com/docs/reference/images/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/reference/images/</guid>
        <description>&lt;p&gt;Barn uses a materialized static-file catalog plus immutable qcow2 artifacts.&#xA;Official and HTTP Catalogs are signed; explicitly selected local and HTTPS&#xA;repositories may be unsigned. A catalog update does not require a new Barn&#xA;binary, but the binary decides which signing keys and image safety rules are&#xA;trusted.&lt;/p&gt;&#xA;&lt;div class=&#34;td-callout td-callout--warning&#34; role=&#34;note&#34;&gt;&#xA;  &lt;div class=&#34;td-callout__title&#34;&gt;&lt;i class=&#34;td-callout__icon fa-solid fa-triangle-exclamation&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;&lt;span class=&#34;td-callout__label&#34;&gt;Warning&lt;/span&gt;&lt;/div&gt;&#xA;  &lt;div class=&#34;td-callout__body&#34;&gt;&#xA;&lt;p&gt;EL7, EL9 9.3/9.6, and EL10 10.0 are &lt;code&gt;deprecated&lt;/code&gt; compatibility images. All&#xA;other built-in versions are &lt;code&gt;supported&lt;/code&gt;.&lt;/p&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&lt;h2 id=&#34;aliases-and-pull-order&#34;&gt;Aliases and pull order&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Barn 0.9.0 embeds catalog &lt;code&gt;2026093001&lt;/code&gt;: 9 families and 41 artifacts. &lt;code&gt;el7&lt;/code&gt; is&#xA;amd64-only; every other family has amd64 and arm64 artifacts. EL9 includes 9.3, 9.6, 9.7, and 9.8;&#xA;EL10 includes 10.0, 10.1, and 10.2. &lt;code&gt;u24:stable&lt;/code&gt; (Ubuntu 24.04) on the native&#xA;architecture is the default request.&lt;/p&gt;</description>
      </item>
    <item>
        <title>A PID Is Not a Virtual Machine</title>
        <link>https://barn.pgsty.com/blog/design/identity-before-pid/</link>
        <pubDate>Fri, 28 Aug 2026 10:00:00 +0800</pubDate>
        
        <guid>https://barn.pgsty.com/blog/design/identity-before-pid/</guid>
        <description>&lt;p&gt;This article describes Barn 0.9.0. The VM lifecycle and network design here&#xA;apply to Linux guests; &lt;a href=&#34;https://barn.pgsty.com/docs/start/macos/&#34;&gt;Mac machines&lt;/a&gt; are managed independently.&lt;/p&gt;&#xA;&lt;p&gt;A pidfile answers one question: which integer did a process have when the file&#xA;was written? It does not prove that the process is still alive, that the PID&#xA;was not reused, that the executable is QEMU, or that this particular QEMU owns&#xA;the node an operator wants to stop.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Image Pipeline</title>
        <link>https://barn.pgsty.com/docs/reference/image-pipeline/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/reference/image-pipeline/</guid>
        <description>&lt;p&gt;The low-level &lt;code&gt;packaging/image-pipeline/build.sh&lt;/code&gt; accepts one already-downloaded&#xA;immutable qcow2 and an independently obtained SHA-256. It never downloads,&#xA;uploads, touches Barn runtime/network state, reads signing keys, or marks an&#xA;image &lt;code&gt;supported&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Run these commands from the Barn source checkout. Python 3 and &lt;code&gt;qemu-img&lt;/code&gt;&#xA;are required; &lt;code&gt;offline&lt;/code&gt; additionally needs working &lt;code&gt;virt-customize&lt;/code&gt; and&#xA;&lt;code&gt;virt-cat&lt;/code&gt; tools from libguestfs. These are build-host dependencies, separate&#xA;from the dependencies that &lt;code&gt;barn setup&lt;/code&gt; installs for running VMs.&lt;/p&gt;&#xA;&lt;h2 id=&#34;modes&#34;&gt;Modes&#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;validate&lt;/code&gt;: copy/re-hash, force qcow2 inspection, validate the single backing&#xA;chain, run &lt;code&gt;qemu-img check&lt;/code&gt;, and emit an explicitly unpublishable evidence&#xA;bundle. guest credentials are not changed.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;offline&lt;/code&gt;: additionally use libguestfs &lt;code&gt;virt-customize --no-network&lt;/code&gt; and&#xA;&lt;code&gt;virt-cat&lt;/code&gt; on the staged copy. It rejects unrelated UID/GID 88 occupants,&#xA;normalizes the locked &lt;code&gt;dba&lt;/code&gt;/&lt;code&gt;admin&lt;/code&gt; identity, disables password/root SSH,&#xA;removes keys/history/host identity/cloud-init cache, restores targeted SELinux&#xA;labels, and reads back a deterministic marker.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;official-candidate-matrix&#34;&gt;Official candidate matrix&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;build-official.py&lt;/code&gt; wraps the same offline boundary for a fixed eight-target&#xA;matrix: Debian 12/13 and Rocky Linux 8/9, each on amd64 and arm64. Every&#xA;upstream qcow2, RPM/DEB input, release name, digest, and source epoch is pinned&#xA;in &lt;code&gt;official-v1.json&lt;/code&gt;.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Storage, Files, and Service Access</title>
        <link>https://barn.pgsty.com/docs/start/storage/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/storage/</guid>
        <description>&lt;p&gt;This guide uses the &lt;strong&gt;Barn 0.9.0&lt;/strong&gt; interface. Start with the &lt;a href=&#34;../tutorial/&#34;&gt;Quick Start&lt;/a&gt; before running the&#xA;guest-side checks. The examples use node &lt;code&gt;meta&lt;/code&gt; and the default subnet; retain&#xA;your actual names and addresses when adapting an existing inventory.&lt;/p&gt;&#xA;&lt;h2 id=&#34;choose-disks-before-creating-the-vm&#34;&gt;Choose disks before creating the VM&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Every node has a 64 GiB root disk and, by default, one 128 GiB non-persistent&#xA;data disk at &lt;code&gt;/data&lt;/code&gt;. &lt;code&gt;vm_disk&lt;/code&gt; sets the root disk size in GiB. &lt;code&gt;vm_disks&lt;/code&gt;&#xA;replaces the entire data-disk list; &lt;code&gt;vm_disks: []&lt;/code&gt; disables extra data disks.&lt;/p&gt;</description>
      </item>
    <item>
        <title>repo.yaml Is Intent; catalog.json Is Evidence</title>
        <link>https://barn.pgsty.com/blog/design/repo-yaml-catalog-json/</link>
        <pubDate>Sat, 29 Aug 2026 19:00:00 +0800</pubDate>
        
        <guid>https://barn.pgsty.com/blog/design/repo-yaml-catalog-json/</guid>
        <description>&lt;p&gt;This article describes Barn 0.9.0. The VM lifecycle and network design here&#xA;apply to Linux guests; &lt;a href=&#34;https://barn.pgsty.com/docs/start/macos/&#34;&gt;Mac machines&lt;/a&gt; are managed independently.&lt;/p&gt;&#xA;&lt;p&gt;A static image repository sounds like a directory of qcow2 files plus a JSON&#xA;index. The difficult part is deciding which facts a maintainer may write by&#xA;hand and which facts must be derived from the bytes being published.&lt;/p&gt;&#xA;&lt;p&gt;If checksums and sizes live in the hand-authored source, they are easy to copy&#xA;incorrectly. If policy exists only in generated JSON, reviewing a channel&#xA;change or deprecation requires reading machine output. Barn keeps the two&#xA;jobs separate.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Image Repositories</title>
        <link>https://barn.pgsty.com/docs/start/images/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/images/</guid>
        <description>&lt;p&gt;Normal use needs no image command first: &lt;code&gt;barn up&lt;/code&gt; resolves &lt;code&gt;u24:stable&lt;/code&gt; for&#xA;the native host architecture and pulls the resulting immutable version.&#xA;Barn uses the catalog embedded in the installed build until you run&#xA;&lt;code&gt;barn update&lt;/code&gt;, which fetches, verifies, and activates the repository&amp;rsquo;s current&#xA;catalog. Nothing refreshes it automatically; &lt;code&gt;image sync&lt;/code&gt; explicitly activates&#xA;an exact URL or file for recovery.&lt;/p&gt;&#xA;&lt;h2 id=&#34;choose-an-image&#34;&gt;Choose an image&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Inspect the available aliases:&lt;/p&gt;</description>
      </item>
    <item>
        <title>Automation and Guest Scripts</title>
        <link>https://barn.pgsty.com/docs/start/automation/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/automation/</guid>
        <description>&lt;p&gt;These examples target the &lt;strong&gt;Barn 0.9.0&lt;/strong&gt;. Run host commands as the Unix user who owns the deployment.&#xA;Use the same inventory and &lt;code&gt;BARN_HOME&lt;/code&gt; on every invocation; a new working&#xA;directory does not create an independent lab.&lt;/p&gt;&#xA;&lt;h2 id=&#34;prepare-a-predictable-lab&#34;&gt;Prepare a predictable lab&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;For a first lab, create and review the inventory before starting automation:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-fa288e4a-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;8&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-fa288e4a-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;mkdir -p ~/barn-lab&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;cd&lt;/span&gt; ~/barn-lab&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn init dual&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;c1&#34;&gt;# Edit barn.yml before proceeding.&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn version&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn validate -f barn.yml&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn plan -f barn.yml&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn setup -f barn.yml --dry-run&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;Keep the selected inventory in version control. Set &lt;code&gt;vm_image&lt;/code&gt; explicitly;&#xA;use a version such as &lt;code&gt;vm_image: u24@20260926.0.0&lt;/code&gt; when new nodes must use the&#xA;same base after a catalog update. Explicit &lt;code&gt;-f&lt;/code&gt; also prevents first-run setup&#xA;from automatically moving an untouched default template to another subnet.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Troubleshooting</title>
        <link>https://barn.pgsty.com/docs/start/troubleshooting/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/troubleshooting/</guid>
        <description>&lt;p&gt;This page covers &lt;strong&gt;Barn 0.9.0&lt;/strong&gt;. Check &lt;code&gt;barn version&lt;/code&gt;&#xA;before applying version-specific guidance.&lt;/p&gt;&#xA;&lt;p&gt;For macOS guests, use &lt;code&gt;barn mac doctor&lt;/code&gt; and the &lt;a href=&#34;../macos/#troubleshooting&#34;&gt;Mac troubleshooting guide&lt;/a&gt;.&#xA;The diagnostics below apply to Linux labs.&lt;/p&gt;&#xA;&lt;p&gt;Start with diagnostics (&lt;code&gt;status&lt;/code&gt; may reconcile interrupted runtime state):&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-651a117f-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;3&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-651a117f-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn doctor --json&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn network status --json&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;barn status --json&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;download-and-path-problems&#34;&gt;Download and PATH problems&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;The installer uses GitHub Release assets; &lt;code&gt;--mirror&lt;/code&gt; selects the Barn image&#xA;repository and does not redirect installer downloads. If your network needs a&#xA;proxy, set &lt;code&gt;HTTPS_PROXY&lt;/code&gt; or &lt;code&gt;ALL_PROXY&lt;/code&gt; in the terminal to your existing proxy&amp;rsquo;s&#xA;address. A macOS system proxy setting alone does not configure these environment&#xA;variables for command-line tools.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Build from Source</title>
        <link>https://barn.pgsty.com/docs/start/source-build/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/source-build/</guid>
        <description>&lt;p&gt;Use a source build to develop Barn, inspect a change, or build the native Mac&#xA;component. For a packaged CLI, use &lt;a href=&#34;../installation/&#34;&gt;installation&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;select-the-version&#34;&gt;Select the version&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Clone the documented release:&lt;/p&gt;&#xA;&lt;div class=&#34;td-code td-code--untitled&#34; id=&#34;td-code-8c60e4bc-fence-0&#34; data-td-code data-td-code-auto-id&#xA;     data-td-language=&#34;bash&#34; data-td-line-count=&#34;2&#34;&gt;&#xA;  &lt;div class=&#34;td-code__viewport&#34; id=&#34;td-code-8c60e4bc-fence-0-viewport&#34; data-td-code-viewport&gt;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;git clone --branch v0.9.0 https://github.com/pgsty/barn.git&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;nb&#34;&gt;cd&lt;/span&gt; barn&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;For the development branch, omit &lt;code&gt;--branch v0.9.0&lt;/code&gt;. Check &lt;code&gt;git log -1 --oneline&lt;/code&gt;&#xA;and &lt;code&gt;git status --short&lt;/code&gt; to identify your source before comparing behavior.&lt;/p&gt;&#xA;&lt;h2 id=&#34;build-the-cli&#34;&gt;Build the CLI&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Barn 0.9.0 pins &lt;strong&gt;Go 1.27.1&lt;/strong&gt; in &lt;code&gt;go.mod&lt;/code&gt; and &lt;code&gt;packaging/toolchain.env&lt;/code&gt;.&#xA;You also need Git, Make, Bash, and standard build tools. Compiling the CLI&#xA;does not require QEMU or host-network setup.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Uninstall and Clean Up</title>
        <link>https://barn.pgsty.com/docs/start/uninstall/</link>
        <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
        
        <guid>https://barn.pgsty.com/docs/start/uninstall/</guid>
        <description>&lt;p&gt;Barn manages Linux and macOS machines separately. &lt;strong&gt;&lt;code&gt;barn purge&lt;/code&gt; deletes only&#xA;the Linux deployment; it does not remove Mac machines.&lt;/strong&gt; Keep Barn installed&#xA;until you have finished VM and host cleanup.&lt;/p&gt;&#xA;&lt;h2 id=&#34;choose-what-to-remove&#34;&gt;Choose what to remove&#xA;&lt;/h2&gt;&#xA;&lt;div class=&#34;td-table-scroll td-table-scroll--static&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Goal&lt;/th&gt;&#xA;      &lt;th scope=&#34;col&#34;&gt;Operation&lt;/th&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Free running resources, keep disks&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;barn stop&lt;/code&gt;; &lt;code&gt;barn mac stop --all&lt;/code&gt; for Mac machines&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Delete a Linux node&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;barn destroy &amp;lt;node&amp;gt;&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Delete the Linux lab, keep persistent disks&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;barn destroy&lt;/code&gt;&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Delete the Linux lab, including persistent disks and keys&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;barn purge&lt;/code&gt; — no confirmation&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;    &lt;tr&gt;&#xA;      &lt;td&gt;Delete named Mac machines&lt;/td&gt;&#xA;      &lt;td&gt;&lt;code&gt;barn mac destroy &amp;lt;name...&amp;gt;&lt;/code&gt; — asks for confirmation&lt;/td&gt;&#xA;    &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&#xA;&lt;p&gt;Use actual names from &lt;code&gt;barn status&lt;/code&gt; and, if you use Mac guests, &lt;code&gt;barn mac ls&lt;/code&gt;.&#xA;Back up files you need before deleting machines.&lt;/p&gt;</description>
      </item>
    <item>
        <title>Barn 0.9.0</title>
        <link>https://barn.pgsty.com/blog/release/0.9.0/</link>
        <pubDate>Wed, 30 Sep 2026 00:00:00 +0800</pubDate>
        
        <guid>https://barn.pgsty.com/blog/release/0.9.0/</guid>
        <description>&lt;p&gt;Barn 0.9.0 brings Linux labs and native macOS machines into one command-line&#xA;tool, with clearer diagnostics and recovery for interrupted operations.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://barn.pgsty.com/docs/start/installation/&#34;&gt;Install 0.9.0&lt;/a&gt; · &lt;a href=&#34;https://github.com/pgsty/barn/releases/tag/v0.9.0&#34;&gt;Download assets&lt;/a&gt; · &lt;a href=&#34;https://github.com/pgsty/barn/blob/v0.9.0/CHANGELOG.md&#34;&gt;Full changelog&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;macos-machines-on-apple-silicon&#34;&gt;macOS machines on Apple Silicon&#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;barn mac&lt;/code&gt; creates named macOS 27 machines with a desktop, SSH, shared folders,&#xA;and text clipboard sharing. The first machine installs a base from Apple&amp;rsquo;s&#xA;verified restore image; subsequent machines clone it with separate writable&#xA;disks, credentials, and private subnets.&lt;/p&gt;</description>
      </item>
    
  </channel>
</rss>
