Skip to content

Connect a cloud account

Machines are created in your account, not ours. To create them, Deployport assumes a role you write in your own account. Revoking that role cuts Deployport off, and nothing else in your account is touched.

Terminal window
deployport machinery cloud connect aws

The command prints a trust policy and a permissions policy. Create the role with them, then finish the connection with the role’s ARN:

Terminal window
deployport machinery cloud connect aws --role-arn <the role ARN>

The trust policy names Deployport’s principal and an external id, so no other account can assume the role.

Terminal window
deployport machinery cloud connect gcp

The command prints the custom role to create and the service account to grant it to. Finish with the project id:

Terminal window
deployport machinery cloud connect gcp --project <project id>

The permissions are grouped by what they do: create a machine, start and stop one, destroy one, read what is needed to place it, and read its power state. Each group is its own statement, so the role reads as a list of what Deployport may do rather than one wide grant.

You can narrow it further yourself. If you want the role scoped to one region, or to a VPC, add that condition to the policy. Deployport asks for the actions it needs; how you scope them is yours.

One Deployport account can connect several cloud accounts, and a factory names the one its machines are created in. So a team with a production AWS account and a sandbox one can keep them apart at the factory, not at the machine.