Installation
Before you download
Vhostly manages the Homebrew stack, so that has to exist first. If you have never installed Homebrew:
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
Then Apache and PHP:
brew install httpd php mkcert
brew services start httpd
You can also skip all of this and let the app's first-run checks install each piece for
you — they run brew install and show you the command before it runs. Homebrew itself is
the one thing the app cannot install, because it comes from a shell script.
Download
Grab the latest .dmg from the
releases page, open it, and drag
Vhostly.app to /Applications.
Getting past Gatekeeper
The build is not notarised by Apple yet, so macOS will refuse it on the first open and say it "cannot be opened because Apple cannot check it for malicious software". That is Gatekeeper reacting to the missing notarisation, not to anything about the app.
Open it once this way and macOS remembers the decision:
- Double-click
Vhostly.appand dismiss the warning. - Open System Settings → Privacy & Security, scroll to the Security section, and press Open Anyway next to the message about Vhostly.
- Confirm once more.
On macOS 14 and earlier, Control-clicking the app and choosing Open does the same job in one step.
If you would rather clear the quarantine flag directly:
xattr -dr com.apple.quarantine /Applications/Vhostly.app
Either way it is a one-time step. Once a notarised build ships, none of this will be needed.
The one-time permission
On first launch Vhostly checks whether it can already do its job. If it cannot, it asks for your administrator password once, with the prompt "Vhostly: one-time setup permission".
Granting it runs four commands:
touch /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf \
/opt/homebrew/etc/httpd/extra/httpd-vhosts.conf.disabled
chown <you> <those two files> /etc/hosts /opt/homebrew/etc/httpd/httpd.conf
printf '<you> ALL=(ALL) NOPASSWD: /opt/homebrew/bin/apachectl' > /etc/sudoers.d/vhostly
chmod 440 /etc/sudoers.d/vhostly
Two things are worth understanding before you agree.
Your user account becomes the owner of /etc/hosts and httpd.conf. That is what lets
the app edit them without prompting you for every site. It also means anything running as
you can now edit them.
The sudoers rule is scoped to one binary. It permits apachectl and nothing else, so
restarting Apache stops asking for a password. It does not grant general sudo access.
If you decline the prompt, the app cannot run — it exits with an explanation rather than half-working. The permission is re-checked on every launch, so if something later removes the sudoers file or changes ownership back, you will simply be asked again.
The environment checks
After that, the first-run wizard runs a full check of the machine. Anything missing can be
installed from the screen, and Show command reveals the exact brew install line
before you press the button — nothing is installed silently.
Required — Homebrew, PHP, Apache, whether Apache is running, whether its configuration
parses, whether /etc/hosts and the vhosts file are writable, and whether the sudoers rule
is in place.
Recommended — OpenSSL, mkcert, Composer and Node. Vhostly runs without them; mkcert is the one that decides whether local HTTPS is trusted or merely encrypted. You can skip it here: enabling HTTPS on a site installs it then.
You can leave with Skip for now or Continue anyway and finish later. The same screen is always available from Settings → Setup guide → Show it, and the same checks live under Environment → Health.
Uninstalling
Delete Vhostly.app. Your sites keep serving, because the configuration it wrote is
ordinary Apache configuration and Apache does not know the app is gone.
To take the sites down too, disable each one in the app first — that removes the vhost block and the hosts entry — and then delete the app. To undo every trace, including the file ownership and the sudoers rule, follow reverting by hand.