Connect a cloud account
Machines are created in your account, not ours. To create them, Deployport assumes a role you write in your own account. Revoking that role cuts Deployport off, and nothing else in your account is touched.
deployport machinery cloud connect awsThe command prints a trust policy and a permissions policy. Create the role with them, then finish the connection with the role’s ARN:
deployport machinery cloud connect aws --role-arn <the role ARN>The trust policy names Deployport’s principal and an external id, so no other account can assume the role.
Google Cloud
Section titled “Google Cloud”deployport machinery cloud connect gcpThe command prints the custom role to create and the service account to grant it to. Finish with the project id:
deployport machinery cloud connect gcp --project <project id>What the role grants
Section titled “What the role grants”The permissions are grouped by what they do: create a machine, start and stop one, destroy one, read what is needed to place it, and read its power state. Each group is its own statement, so the role reads as a list of what Deployport may do rather than one wide grant.
You can narrow it further yourself. If you want the role scoped to one region, or to a VPC, add that condition to the policy. Deployport asks for the actions it needs; how you scope them is yours.
More than one account
Section titled “More than one account”One Deployport account can connect several cloud accounts, and a factory names the one its machines are created in. So a team with a production AWS account and a sandbox one can keep them apart at the factory, not at the machine.