Build a factory
A factory is what a machine is built from. It names the cloud account, the sizes a developer may pick from, the firewall rules every machine starts with, the setup steps they run once, and the profiles they may use.
One factory per kind of machine is usually enough. A “Dev” factory and a “GPU” factory is a better split than one factory that permits everything, because the factory is where you bound what a developer can spend.
Create one
Section titled “Create one”deployport machinery machine-factories create --title "Dev" --cloud-account <cloud-account-id>The title is what people read. The name is derived from it, and you can supply your own instead.
A factory restricts the sizes it will produce. Leave the limits off and everything the cloud account offers is permitted, except the metal and accelerated sizes, which stay out until you allow them.
A developer who does not care about the size gets the smallest one the factory permits, so the default is the cheap answer rather than the expensive one.
Firewall rules
Section titled “Firewall rules”A rule opens a port for a direct connection to the machines this factory makes. Machines start with no rules unless the factory seeds them.
Setup steps
Section titled “Setup steps”A setup step runs a script once, when a machine is created, in the order you list them. An entry with no revision tracks the script’s latest version, so a fix reaches the next machine without editing the factory.
Profiles
Section titled “Profiles”A profile is the policy a machine runs under: when it counts as idle, whether it stops itself, how its disk is watched and grown, and whether snapshots are taken on a schedule.
A factory names a default profile and the set of profiles it permits. A machine created without a profile takes the factory’s default, and a machine that names one must name a permitted one.
⚠️ This is where the delegation lives. Most profile settings carry both the value every machine gets and whether a machine may depart from it. The platform engineer sets the bound; the developer moves inside it. A setting written without its bound clears the bound, so machine-profiles set writes both halves together.
Profiles are edited separately from factories, because several factories can share one:
deployport machinery machine-profiles set <profile> <domain>.<slot>.<setting>The path is the same coordinate the machine’s own settings page prints, for example storage.autoscale.maxSizeGiB. Let a machine stop itself names the paths for idle detection and auto-stop.