Bzync Automation CLI
A lightweight, zero-dependency Bash automation CLI for remote command execution, Docker orchestration, file synchronization, system operations, and infrastructure automation.
bzy is designed for Bzync infrastructure and development workflows where commands should be safe, observable, reproducible, and auditable.
- Zero-dependency runtime — implemented entirely in Bash with
set -Eeuo pipefail - Remote execution over SSH — use existing SSH aliases or
user@hosttargets - Rsync synchronization — simple
pullandpushworkflows with progress - Remote Docker management — containers, images, and Compose stacks
- Interactive confirmation — destructive operations require confirmation
- Command progress — operations provide visible execution progress
- Per-command audit logs — every invocation gets its own log file
- Automatic secret redaction — sensitive values are masked before being written to logs
- Persistent configuration — global rules and timezone settings are stored under
~/.bzy/ - Temporary runtime rules —
--excludeand--includecan be applied to individual commands - Dry-run support — inspect operations before making changes
- Timezone-aware logging — configure the timezone used by audit logs
- Global installation — install
bzyinto your systemPATH - MIT licensed
Place the script somewhere in your working directory:
mkdir -p ~/bzy
cd ~/bzyFor example:
~/bzy/
├── cli.sh
├── config
└── logs/
chmod +x cli.shSet the default timezone used by bzy:
./cli.sh --tz-set Asia/ManilaThe configuration is stored in:
~/.bzy/config
Install bzy into /usr/local/bin:
./cli.sh service installAfter installation:
bzy --helpbzy service uninstallbzy stores persistent configuration under:
~/.bzy/
The directory contains:
~/.bzy/
├── config
└── logs/
Configuration can be changed through CLI flags instead of manually editing the file.
Set the persistent timezone:
bzy --tz-set Asia/ManilaOverride the timezone for one execution:
bzy --tz America/New_York docker ps cloudThe persistent timezone remains unchanged.
Add a persistent rsync exclusion:
bzy --exclude-add node_modules/Add multiple exclusions:
bzy --exclude-add node_modules/
bzy --exclude-add .git/
bzy --exclude-add "*.tmp"Remove an exclusion:
bzy --exclude-rm node_modules/Add a persistent inclusion pattern:
bzy --include-add "*.pdf"Remove an inclusion pattern:
bzy --include-rm "*.pdf"Temporary rules apply only to the current command.
Exclude .log files:
bzy --exclude "*.log" push cloud ./app /srv/app/Include PDF files:
bzy --include "*.pdf" push cloud ./documents /srv/documents/Temporary rules do not modify ~/.bzy/config.
The default configuration is stored at:
~/.bzy/config
Example:
TIMEZONE="Asia/Manila"
EXCLUDE="node_modules/"
EXCLUDE=".git/"
EXCLUDE="*.tmp"
INCLUDE="*.pdf"Persistent configuration is automatically applied to supported commands.
General syntax:
bzy [global options] <command> [arguments]Example:
bzy docker ps cloud| Option | Description |
|---|---|
-y, --yes |
Skip confirmation prompts |
--dry-run |
Simulate an operation without making changes |
--no-progress |
Suppress progress output |
--tz <timezone> |
Override the log timezone for the current run |
--exclude <pattern> |
Add a temporary exclusion pattern |
--include <pattern> |
Add a temporary inclusion pattern |
-q, --quiet |
Reduce console output |
-h, --help |
Show help |
-v, --version |
Show version |
bzy uses rsync for efficient file synchronization.
Copy files from a remote host to the local machine:
bzy pull user@remote-host /var/www/remote-dir ./local-dirDirection:
REMOTE → LOCAL
Example:
bzy pull cloud /srv/bzync ./backup/bzyncCopy files from the local machine to a remote host:
bzy push user@remote-host ./local-app /var/www/remote-appDirection:
LOCAL → REMOTE
Example:
bzy push cloud ./dist/ /srv/bzync/bzy --exclude "*.log" push cloud ./local-app /srv/remote-app/Multiple temporary exclusions can be supplied:
bzy \
--exclude node_modules/ \
--exclude .git/ \
--exclude "*.log" \
push cloud ./local-app /srv/remote-app/bzy manages Docker remotely through SSH.
No Bzync agent is required on the remote server.
bzy docker ps user@remote-hostbzy docker start user@remote-host container_namebzy docker stop user@remote-host container_namebzy docker restart user@remote-host container_namebzy docker inspect user@remote-host container_namebzy docker logs user@remote-host container_namebzy docker rm user@remote-host container_nameDestructive Docker operations require confirmation by default.
For automation:
bzy --yes docker restart user@remote-host container_namebzy docker image ls user@remote-hostbzy docker image pull user@remote-host nginx:latestbzy docker image inspect user@remote-host nginx:latestbzy docker image rm user@remote-host nginx:latestImage removal requires confirmation.
Manage Compose projects using their remote project directory.
bzy docker compose up user@remote-host /path/to/projectbzy docker compose up user@remote-host /path/to/project --detachbzy docker compose up user@remote-host /path/to/project --build --detachbzy docker compose down user@remote-host /path/to/projectbzy docker compose restart user@remote-host /path/to/projectbzy docker compose build user@remote-host /path/to/projectbzy docker compose pull user@remote-host /path/to/projectbzy docker compose ps user@remote-host /path/to/projectbzy docker compose logs user@remote-host /path/to/projectbzy can detect common Compose filenames such as:
compose.yaml
compose.yml
docker-compose.yml
Execute a command on a remote host:
bzy exec user@remote-host "docker ps"Example:
bzy exec cloud "systemctl status nginx"Another example:
bzy exec cloud "df -h"All remote executions are recorded in the audit log.
bzy system info cloudbzy system disk cloudbzy system memory cloudbzy system cpu cloudbzy system uptime cloudManage systemd services remotely.
bzy service status cloud nginxbzy service start cloud nginxbzy service stop cloud nginxbzy service restart cloud nginxbzy service enable cloud nginxbzy service disable cloud nginxOperations that modify service state require confirmation.
bzy network interfaces cloudbzy network ip cloudbzy network routes cloudbzy network ping cloud 10.10.0.1bzy network port cloud 10.10.0.10 443bzy process ps cloudbzy process inspect cloud 1234bzy process kill cloud 1234Process termination requires confirmation.
Execute common Git operations inside a remote directory.
bzy git status cloud /srv/projectbzy git pull cloud /srv/projectbzy git push cloud /srv/projectbzy git branch cloud /srv/projectbzy git log cloud /srv/projectOperations that modify the remote repository require confirmation.
bzy provides deployment-oriented commands for remote application directories.
bzy deploy cloud /srv/projectbzy deploy update cloud /srv/projectbzy deploy restart cloud /srv/projectbzy deploy rollback cloud /srv/projectDeployment operations require confirmation.
bzy backup create cloud /srv/application /srv/backups/application.tar.gzbzy backup restore cloud /srv/backups/application.tar.gz /srv/applicationRestore operations require confirmation.
bzy backup list cloud /srv/backupsCheck the general health of a remote host:
bzy health cloudCheck a service or container:
bzy health cloud nginxEvery bzy invocation creates one dedicated log file.
Logs are stored under:
~/.bzy/logs/
Example:
~/.bzy/
└── logs/
├── 20260915-013142-481-docker-ps.log
├── 20260915-013205-902-docker-restart.log
├── 20260915-013411-127-push.log
└── 20260915-013522-774-exec.log
YYYYMMDD-HHMMSS-mmm-command.log
For example:
20260915-013205-902-docker-restart.log
This makes every command execution independently identifiable.
Each execution log records:
- execution date
- execution time
- command
- target host
- dry-run state
- confirmation result
- command output
- command errors
- final status
- exit code
- execution duration
Example:
DATE: 2026-09-15T01:32:05+08:00
COMMAND: bzy docker restart cloud bzync-cloud-server-1
TARGET: cloud
DRY RUN: no
CONFIRMATION: accepted
--- OUTPUT ---
Container bzync-cloud-server-1 restarted
--- END OUTPUT ---
END: 2026-09-15T01:32:07+08:00
STATUS: success
EXIT CODE: 0
DURATION: 2s
The audit engine automatically redacts common sensitive values before they are persisted to logs.
Examples of protected patterns include:
password
passwd
token
api_key
secret
authorization
Bearer tokens
Sensitive values are represented as:
********
The purpose is to make audit logs useful without unnecessarily storing credentials or authentication material.
bzy logs listbzy logs show 20260915-013205-902-docker-restart.logbzy logs show 2026bzy logs tailbzy logs clearClearing logs requires confirmation.
Commands that can modify or destroy state require confirmation by default.
For example:
bzy docker stop cloud nginxwill prompt before execution.
For non-interactive automation, explicitly acknowledge the operation:
bzy --yes docker stop cloud nginxThis makes accidental destructive execution less likely while still supporting CI/CD and automation workflows.
Use --dry-run when supported to inspect an operation before making changes:
bzy --dry-run push cloud ./dist/ /srv/bzync/Dry-run behavior is command-dependent.
Operations provide progress information by default.
Disable progress when integrating with another automation system:
bzy --no-progress push cloud ./dist/ /srv/bzync/Reduce general console output:
bzy --quiet docker compose logs cloud /srv/bzyncAudit logging remains enabled even when --quiet or --no-progress is used.
bzy is designed to work both interactively and inside automation scripts.
Interactive:
bzy docker restart cloud bzync-cloud-server-1Non-interactive:
bzy --yes docker restart cloud bzync-cloud-server-1Dry-run:
bzy --dry-run deploy cloud /srv/bzyncQuiet automation:
bzy --yes --quiet --no-progress deploy cloud /srv/bzyncbzy follows a few simple principles:
Operations capable of changing system state should not silently execute.
Commands provide progress and retain their output.
Every invocation receives its own persistent log.
The runtime is implemented in Bash and uses standard Unix tooling.
Existing SSH connectivity is used instead of requiring a separate remote agent.
Confirmation can be explicitly bypassed with --yes.
Persistent rules live under:
~/.bzy/config
while temporary rules remain local to a single invocation.
Typical user-level installation:
~/.bzy/
├── config
└── logs/
├── 20260915-013142-481-docker-ps.log
├── 20260915-013205-902-docker-restart.log
└── ...
Project source:
bzy/
├── cli.sh
└── README.md
Distributed under the MIT License.
bzy is part of the Bzync open-source tooling ecosystem.