Installation

Before you download

Vhostly manages the Homebrew stack, so that has to exist first. If you have never installed Homebrew:

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"

Then Apache and PHP:

brew install httpd php mkcert
brew services start httpd

You can also skip all of this and let the app's first-run checks install each piece for you — they run brew install and show you the command before it runs. Homebrew itself is the one thing the app cannot install, because it comes from a shell script.

Download

Grab the latest .dmg from the releases page, open it, and drag Vhostly.app to /Applications.

Getting past Gatekeeper

The build is not notarised by Apple yet, so macOS will refuse it on the first open and say it "cannot be opened because Apple cannot check it for malicious software". That is Gatekeeper reacting to the missing notarisation, not to anything about the app.

Open it once this way and macOS remembers the decision:

  1. Double-click Vhostly.app and dismiss the warning.
  2. Open System Settings → Privacy & Security, scroll to the Security section, and press Open Anyway next to the message about Vhostly.
  3. Confirm once more.

On macOS 14 and earlier, Control-clicking the app and choosing Open does the same job in one step.

If you would rather clear the quarantine flag directly:

xattr -dr com.apple.quarantine /Applications/Vhostly.app

Either way it is a one-time step. Once a notarised build ships, none of this will be needed.

The one-time permission

On first launch Vhostly checks whether it can already do its job. If it cannot, it asks for your administrator password once, with the prompt "Vhostly: one-time setup permission".

Granting it runs four commands:

touch  /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf \
       /opt/homebrew/etc/httpd/extra/httpd-vhosts.conf.disabled
chown  <you>  <those two files>  /etc/hosts  /opt/homebrew/etc/httpd/httpd.conf
printf '<you> ALL=(ALL) NOPASSWD: /opt/homebrew/bin/apachectl' > /etc/sudoers.d/vhostly
chmod  440 /etc/sudoers.d/vhostly

Two things are worth understanding before you agree.

Your user account becomes the owner of /etc/hosts and httpd.conf. That is what lets the app edit them without prompting you for every site. It also means anything running as you can now edit them.

The sudoers rule is scoped to one binary. It permits apachectl and nothing else, so restarting Apache stops asking for a password. It does not grant general sudo access.

If you decline the prompt, the app cannot run — it exits with an explanation rather than half-working. The permission is re-checked on every launch, so if something later removes the sudoers file or changes ownership back, you will simply be asked again.

The environment checks

After that, the first-run wizard runs a full check of the machine. Anything missing can be installed from the screen, and Show command reveals the exact brew install line before you press the button — nothing is installed silently.

Required — Homebrew, PHP, Apache, whether Apache is running, whether its configuration parses, whether /etc/hosts and the vhosts file are writable, and whether the sudoers rule is in place.

Recommended — OpenSSL, mkcert, Composer and Node. Vhostly runs without them; mkcert is the one that decides whether local HTTPS is trusted or merely encrypted. You can skip it here: enabling HTTPS on a site installs it then.

You can leave with Skip for now or Continue anyway and finish later. The same screen is always available from Settings → Setup guide → Show it, and the same checks live under Environment → Health.

Uninstalling

Delete Vhostly.app. Your sites keep serving, because the configuration it wrote is ordinary Apache configuration and Apache does not know the app is gone.

To take the sites down too, disable each one in the app first — that removes the vhost block and the hosts entry — and then delete the app. To undo every trace, including the file ownership and the sudoers rule, follow reverting by hand.