[01] STORAGE
Private at the origin.
Versioned S3 storage, blocked public access, and CloudFront Origin Access Control. Your bucket is storage; your domain is the front door.
A SMALL TOOL FOR YOUR CORNER OF THE WEB
Your files. Your domain. Your AWS.
One little binary to bring them together.
xiaoyu publishes a folder of static files to private S3 storage and serves it through CloudFront over HTTPS. It handles the infrastructure, releases, and the way back.
[ Go binary ] [ runs locally or in CI ]
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣤⣤⣤⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⡿⠿⣿⣷⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⣿⣿⣿⠋⢀⣠⣾⣿⣷⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⡿⣡⣾⣿⣿⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣰⣿⣷⠿⠟⠛⠛⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠀⠀⢀⣠⣤⣶⣶⣦⣤⡀⢿⣿⡿⣿⣥⣤⣂⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⣠⣶⣿⣿⣿⠟⠛⠛⣻⣿⣿⣏⠁⠀⠹⣿⣿⣿⣷⣦⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠀⠻⣿⣿⠟⠁⢀⣠⣾⣿⡿⣿⣿⣄⠀⠀⠉⠙⠛⠿⠿⠿⠿⠽⢽⣿⣿⡿⢿⣿⣿⣿⣶⣄⠀⠀⠀ ⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⡟⠀⣿⣿⣿⣷⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⢿⣿⣿⣧⠀⠀ ⠀⠀⠀⠀⢻⣿⣿⣿⣿⠟⠁⠀⢸⣿⡿⠛⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣿⣿⣿⡀⠀ ⠀⠀⠀⠀⠀⠉⠚⠋⠀⠀⢀⣠⣾⡟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣿⣿⣿⣷⠀ ⠀⠀⢀⣠⣴⣶⣶⣶⣿⣿⣿⣿⡿⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠹⣿⡟⠋⠓ ⠀⣴⣿⠇⠉⠉⠛⠛⠙⠛⠛⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠁⠃⠀⠀ ⣴⣿⣿⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⢻⣿⣿⣷⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀ ⠀⠳⡏⠋⠉⠂⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
/01 — THE SHORT VERSION
Bring the output of your favorite static site generator, a single HTML file, or a whole frontend build. xiaoyu takes it from there.
S3 stays private. CloudFront signs origin requests. Visitors arrive over HTTPS.
/02 — SMALL BINARY. CONSIDERED DETAILS.
[01] STORAGE
Versioned S3 storage, blocked public access, and CloudFront Origin Access Control. Your bucket is storage; your domain is the front door.
[02] DELIVERY
A DNS-validated ACM certificate, HTTP-to-HTTPS redirects, compression, and managed security headers. Delivered through CloudFront.
[03] RELEASES
Content-addressed, immutable releases. Switch the origin to publish, and point it back to a retained release when you need to undo a change.
[04] VERIFICATION
SHA-256 change detection and optional verification of public HTTPS responses against local files. Know whether what you sent is what visitors get.
[05] ROUTING
Direct files, directory-style URLs, or SPA routing. Add domain aliases and canonical redirects that preserve paths and query strings.
[06] WORKFLOW
A guided setup wizard, readable YAML, environment overrides, and optional Namecheap DNS automation. Run the same executable locally or in CI.
/03 — FROM HERE TO HTTPS
You’ll need a domain, an AWS account, and a folder of built static files. Use temporary administrator credentials for the first provisioning.
Download it for your platform, or run make build from a checkout with Go 1.25 or newer. Put xiaoyu on your PATH. Target machines only need that one file.
Run xiaoyu init from your site folder. The wizard writes .xiaoyu.yaml. Check it locally before talking to AWS.
Launch the bootstrap stack below, then run xiaoyu login and paste its two outputs. Already have administrator credentials? Export them instead and skip this step.
Bootstrap prepares AWS resources and prints certificate-validation CNAMEs. Add them at your DNS provider, wait for ACM to issue the certificate, then rerun bootstrap.
Load the generated runtime credentials and point your domain to the printed CloudFront target. Verify your site. Future updates are xiaoyu deploy.
# 1. In the project checkout (Go 1.25+)
make build# Add bin/xiaoyu to your PATH, then
# cd into your built static-site folder.
xiaoyu initxiaoyu config check# 2. With temporary AWS admin credentials
xiaoyu bootstrap-user --deploy# Add the printed ACM validation CNAMEs.
# Wait for ISSUED, then rerun:
xiaoyu bootstrap-user --deploy# 3. Source the credentials file printed
# by bootstrap. Add the final site DNS
# records and wait for them to resolve.
xiaoyu verify --all --wait your next update: xiaoyu deploy
The stack creates one temporary IAM user scoped to this account, hands you its key, and nothing else. xiaoyu login verifies that key and stores it outside your site folder. Delete the stack (in ap-northeast-2) once bootstrap finishes: xiaoyu will have created a minimal runtime user for everyday deploys. Prefer your own administrator role? That path is unchanged.
Need the full walkthrough? Open the setup manual →
/04 — TAKE IT WITH YOU
No runtime, no installer, no package manager. Download the executable for your machine, or take the source and build it yourself. This page serves build dev, published by xiaoyu itself.
| PLATFORM | FILE |
|---|---|
| macOS · Apple Silicon | xiaoyu-darwin-arm64.tar.gz |
| macOS · Intel | xiaoyu-darwin-amd64.tar.gz |
| Linux · x86-64 | xiaoyu-linux-amd64.tar.gz |
| Linux · arm64 | xiaoyu-linux-arm64.tar.gz |
| Source archive | xiaoyu-source.tar.gz |
| Checksums | SHA256SUMS.txt |
# In ~/Downloads, next to SHA256SUMS.txt
shasum -a 256 --ignore-missing -c SHA256SUMS.txttar -xzf xiaoyu-darwin-arm64.tar.gz# macOS quarantines downloads. If it says
# the developer cannot be verified, clear it:
xattr -c xiaoyuchmod +x xiaoyu && ./xiaoyu version# Optional: keep it on your PATH
sudo mv xiaoyu /usr/local/bin/ then: xiaoyu init
These builds are unsigned and not notarized, so Gatekeeper blocks them until you clear the quarantine attribute above, or allow the binary once under System Settings → Privacy & Security → Open Anyway. Compare the checksum before you run it — or skip the download and build from source with make build. Linux and other platforms: extract, chmod +x, run.
/05 — KEEP THESE CLOSE
| COMMAND | WHAT IT DOES |
|---|---|
xiaoyu login | Verify and store pasted provisioning credentials. |
xiaoyu plan | Preview infrastructure and content changes. |
xiaoyu deploy | Publish an update to your provisioned site. |
xiaoyu sync --dry-run | See exactly which files would change. |
xiaoyu verify --all --wait | Wait for CloudFront, then check every local file over HTTPS. |
xiaoyu releases | List the immutable releases you can return to. |
xiaoyu rollback --yes <release-id> | Switch CloudFront to a retained release. |
xiaoyu doctor | Diagnose configuration, AWS, DNS, HTTPS, and content. |
/06 — BEFORE YOU GO
Bring already-built static files. xiaoyu provisions the AWS delivery infrastructure and publishes those files. Your existing generator or frontend build stays in charge of creating them.
Download the executable, or build it with Go 1.25 or newer, then copy that one file to your target machine. Running it requires system CA certificates, network access, and AWS credentials. No AWS CLI, Node.js, daemon, or database is required.
In your own AWS account. Files live in a private S3 bucket; CloudFront serves the public site. AWS usage is billed directly to your account. xiaoyu supports AWS commercial regions.
No. You can add the printed DNS records with your own provider. Namecheap automation is optional, with a plan step before applying changes. For an apex domain, your DNS provider needs ALIAS, ANAME, or CNAME-flattening support for CloudFront.
Atomic deployments are enabled by default. Each release has an immutable, content-addressed prefix in S3. Rollback points the CloudFront origin to a retained release and invalidates the cache; edge propagation still takes time. Five releases are retained by default.
Yes. Use the executable, a configuration file or environment variables, and credentials from the AWS SDK chain. Profiles, SSO, web identity, and instance or task roles are supported. The optional bootstrap workflow creates a dedicated user scoped to the provisioned site.
THAT’S THE WHOLE IDEA.
Make something.
Give it a place on the web.