What Vhostly writes

The app edits system files and takes ownership of a few of them. Here is the complete list, so nothing it does is a surprise.

Every path below assumes Homebrew's default prefix on Apple silicon, /opt/homebrew.

Files it takes ownership of

During the one-time setup these four are chowned to your user account, so the app can edit them afterwards without asking for a password each time:

PathWhy
/etc/hostsOne entry per active site
/opt/homebrew/etc/httpd/httpd.confModules, Listen 443, the Include lines, the PHP module
/opt/homebrew/etc/httpd/extra/httpd-vhosts.confActive sites
/opt/homebrew/etc/httpd/extra/httpd-vhosts.conf.disabledDisabled sites

Ownership is the trade being made: no repeated password prompts, in exchange for these files being writable by anything running as you.

Files it creates

PathHolds
/etc/sudoers.d/vhostlyOne rule: NOPASSWD for apachectl, and nothing else
/opt/homebrew/etc/httpd/extra/httpd-vhosts-ssl.confEvery <VirtualHost *:443> block
/opt/homebrew/etc/httpd/extra/httpd-vhosts-lan.confSites shared on your network, each on its own port
/opt/homebrew/etc/httpd/certs/Per-site certificates, <name>.pem and <name>-key.pem
/opt/homebrew/etc/httpd/extra/*.backup-*Config snapshots, 50 kept per file
~/Library/Application Support/Vhostly/state.jsonApp settings — notifications, onboarding, and the random id behind the launch ping

Certificates are signed by mkcert's authority, which lives in $(mkcert -CAROOT) and is mkcert's to manage, not Vhostly's.

What it changes inside httpd.conf

Narrow, specific edits — the file is never reformatted or reordered:

  • Uncomments LoadModule lines for mod_proxy, mod_proxy_http, mod_proxy_wstunnel, mod_rewrite, mod_ssl and mod_socache_shmcb, when you turn those on.
  • Rewrites the LoadModule php_module path when you switch Apache's PHP version.
  • Adds Listen 443 after Listen 80, the first time a site gets HTTPS.
  • Adds Include …/httpd-vhosts-ssl.conf after the existing vhosts Include.
  • Adds Include …/httpd-vhosts-lan.conf while network mode is on, and removes it when network mode is switched off.

Everything else in that file stays yours.

What it changes inside /etc/hosts

Site hostnames are appended as extra tokens on the lines that already exist:

127.0.0.1       localhost myapp.test
::1             localhost myapp.test

Both lines, because macOS queries IPv6 first and an absent ::1 entry costs a five-second timeout on every lookup. If neither line exists, one is inserted.

Vhostly does not mark its entries with a comment. Removing a site strips just that token and leaves the rest of the line intact.

Logs

Per-site logs are written by Apache, to Apache's own directory — /opt/homebrew/var/log/httpd/. Vhostly names them and reads them but does not rotate or delete them. See logs.

What it never touches

Your document roots. Your project files. Your databases. Your shell configuration. Any Apache config file other than the ones listed above.

Reverting by hand

To return the machine to its previous state without the app:

  1. Remove your site hostnames from the 127.0.0.1 and ::1 lines in /etc/hosts.

  2. Delete /opt/homebrew/etc/httpd/extra/httpd-vhosts-ssl.conf, and remove its Include line plus Listen 443 from httpd.conf. Do the same for httpd-vhosts-lan.conf and its Include line, if you ever shared a site on your network.

  3. Empty or delete /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf and its .disabled twin, and their *.backup-* files.

  4. Delete /opt/homebrew/etc/httpd/certs/, and untrust the mkcert authority — mkcert -uninstall, or remove it in Keychain Access.

  5. Give the four files back to root:

    sudo chown root:wheel /etc/hosts \
      /opt/homebrew/etc/httpd/httpd.conf \
      /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf \
      /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf.disabled
    
  6. Remove the sudoers rule: sudo rm /etc/sudoers.d/vhostly

  7. Delete ~/Library/Application Support/Vhostly.

Then sudo apachectl restart. Uninstalling Apache and PHP themselves is brew uninstall, and has nothing to do with Vhostly.