What Vhostly writes
The app edits system files and takes ownership of a few of them. Here is the complete list, so nothing it does is a surprise.
Every path below assumes Homebrew's default prefix on Apple silicon, /opt/homebrew.
Files it takes ownership of
During the one-time setup these four are chowned to your user account, so the app can
edit them afterwards without asking for a password each time:
| Path | Why |
|---|---|
/etc/hosts | One entry per active site |
/opt/homebrew/etc/httpd/httpd.conf | Modules, Listen 443, the Include lines, the PHP module |
/opt/homebrew/etc/httpd/extra/httpd-vhosts.conf | Active sites |
/opt/homebrew/etc/httpd/extra/httpd-vhosts.conf.disabled | Disabled sites |
Ownership is the trade being made: no repeated password prompts, in exchange for these files being writable by anything running as you.
Files it creates
| Path | Holds |
|---|---|
/etc/sudoers.d/vhostly | One rule: NOPASSWD for apachectl, and nothing else |
/opt/homebrew/etc/httpd/extra/httpd-vhosts-ssl.conf | Every <VirtualHost *:443> block |
/opt/homebrew/etc/httpd/extra/httpd-vhosts-lan.conf | Sites shared on your network, each on its own port |
/opt/homebrew/etc/httpd/certs/ | Per-site certificates, <name>.pem and <name>-key.pem |
/opt/homebrew/etc/httpd/extra/*.backup-* | Config snapshots, 50 kept per file |
~/Library/Application Support/Vhostly/state.json | App settings — notifications, onboarding, and the random id behind the launch ping |
Certificates are signed by mkcert's authority, which lives in $(mkcert -CAROOT) and is
mkcert's to manage, not Vhostly's.
What it changes inside httpd.conf
Narrow, specific edits — the file is never reformatted or reordered:
- Uncomments
LoadModulelines formod_proxy,mod_proxy_http,mod_proxy_wstunnel,mod_rewrite,mod_sslandmod_socache_shmcb, when you turn those on. - Rewrites the
LoadModule php_modulepath when you switch Apache's PHP version. - Adds
Listen 443afterListen 80, the first time a site gets HTTPS. - Adds
Include …/httpd-vhosts-ssl.confafter the existing vhostsInclude. - Adds
Include …/httpd-vhosts-lan.confwhile network mode is on, and removes it when network mode is switched off.
Everything else in that file stays yours.
What it changes inside /etc/hosts
Site hostnames are appended as extra tokens on the lines that already exist:
127.0.0.1 localhost myapp.test
::1 localhost myapp.test
Both lines, because macOS queries IPv6 first and an absent ::1 entry costs a five-second
timeout on every lookup. If neither line exists, one is inserted.
Vhostly does not mark its entries with a comment. Removing a site strips just that token and leaves the rest of the line intact.
Logs
Per-site logs are written by Apache, to Apache's own directory —
/opt/homebrew/var/log/httpd/. Vhostly names them and reads them but does not rotate or
delete them. See logs.
What it never touches
Your document roots. Your project files. Your databases. Your shell configuration. Any Apache config file other than the ones listed above.
Reverting by hand
To return the machine to its previous state without the app:
-
Remove your site hostnames from the
127.0.0.1and::1lines in/etc/hosts. -
Delete
/opt/homebrew/etc/httpd/extra/httpd-vhosts-ssl.conf, and remove itsIncludeline plusListen 443fromhttpd.conf. Do the same forhttpd-vhosts-lan.confand itsIncludeline, if you ever shared a site on your network. -
Empty or delete
/opt/homebrew/etc/httpd/extra/httpd-vhosts.confand its.disabledtwin, and their*.backup-*files. -
Delete
/opt/homebrew/etc/httpd/certs/, and untrust the mkcert authority —mkcert -uninstall, or remove it in Keychain Access. -
Give the four files back to root:
sudo chown root:wheel /etc/hosts \ /opt/homebrew/etc/httpd/httpd.conf \ /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf \ /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf.disabled -
Remove the sudoers rule:
sudo rm /etc/sudoers.d/vhostly -
Delete
~/Library/Application Support/Vhostly.
Then sudo apachectl restart. Uninstalling Apache and PHP themselves is brew uninstall,
and has nothing to do with Vhostly.