devmachine

Packages

Packages.

Each package adds one thing to a machine or a workspace. Add one with devmachine packages add <name>, then devmachine sync. Some also carry widgets for the macOS app's Home and sidebars.

Comes with setup is on every new machine, through essentials (setup --no-essentials skips it). In every workspace is on every new workspace.

Package list

33 packages

antigravity

Coding agents · workspace

Google's Antigravity CLI (agy) for one account. Logging in is a person's job, once, in each account.

devmachine packages add antigravity --workspace acme

Settings: home

Needs login: antigravity

Source of antigravity (opens in a new tab) →

base

Comes with setup
Foundation · machine

The base tools a development machine needs, plus a shared tmux config and a session picker.

devmachine packages add base

New machines already have it, through essentials. This command is for a machine set up without it (setup --no-essentials).

Settings: timezone, hostname, upgrade, swap

Source of base (opens in a new tab) →

caddy

Comes with setup
Web · machine

A reverse proxy that gets its own certificates, and a one-page site that answers 200 to prove the machine is reachable. Every other site is a file another package drops into /etc/caddy/sites.d.

devmachine packages add caddy

New machines already have it, through essentials. This command is for a machine set up without it (setup --no-essentials).

Settings: email, local_certs, site, site_domain, source, version

Source of caddy (opens in a new tab) →

claude-code

Coding agents · workspace

The Claude Code CLI for one account, its ~/.claude directory and the settings.json the account starts with. Logging in is a person's job, once, in each account.

devmachine packages add claude-code --workspace acme

Settings: home, status_line, remote_control_at_startup, session_name_prefix, env, diff_sidebar, expanded_todos

Needs login: claude

Widgets:

  • usage — Claude Code usage windows, how much of each is used and when it resets. (Home, Sidebar, Context sidebar)
Source of claude-code (opens in a new tab) →

claude-plugins

Coding agents · workspace

Installs and updates Claude Code plugins in one account. It knows how, never which: the marketplace and the plugin list are the operator's, and with no marketplace configured it does nothing.

devmachine packages add claude-plugins --workspace acme

Settings: home, claude, marketplace, plugins, update

Source of claude-plugins (opens in a new tab) →

claude-remote-control

Coding agents · workspace

Keeps one account's Claude Code Remote Control session up: a user systemd unit plus linger on Linux, a launch daemon on macOS, so it survives every logout. It starts only where that account has logged in, because there is nothing to connect without a session.

devmachine packages add claude-remote-control --workspace acme

Settings: home, session_name, working_directory, restart_seconds

Source of claude-remote-control (opens in a new tab) →

cline

Coding agents · workspace

The Cline CLI for one account, installed with the account's own Node. Logging in is a person's job, once, in each account.

devmachine packages add cline --workspace acme

Settings: home

Needs login: cline

Source of cline (opens in a new tab) →

cloudflare

DNS · machine · dns

DNS zones on Cloudflare.

devmachine packages add cloudflare

Needs login: cloudflare

Source of cloudflare (opens in a new tab) →

codex

Coding agents · workspace

OpenAI's Codex CLI for one account, from its standalone release, so it needs no Node. Logging in is a person's job, once, in each account.

devmachine packages add codex --workspace acme

Settings: home

Needs login: codex

Widgets:

  • usage — Codex usage windows, how much of each is used and when it resets. (Home, Sidebar, Context sidebar)
Source of codex (opens in a new tab) →

dev

In every workspace
Foundation · workspace

The four tools a workspace is expected to have: the GitHub CLI, bun, the Node LTS through mise, and unzip. It installs gh and declares the login gh needs; one GitHub account normally serves every workspace on a machine.

Every new workspace has it — nothing to add.

Settings: home, gh_version, node_version

Needs login: gh

Source of dev (opens in a new tab) →

devmachine-app

Comes with setup
macOS · machine

What the Devmachine macOS app asks a machine for, reached through devmachine run --package devmachine-app.

devmachine packages add devmachine-app

New machines already have it, through essentials. This command is for a machine set up without it (setup --no-essentials).

Settings: github_hosts

Widgets:

  • brand — The Devmachine mark, the first thing in the menu bar.
  • clock — The time, the date and the computer the app runs on. (Home, Sidebar, Context sidebar)
  • links — The links the selected session mentioned. (Context sidebar)
  • machine-stats — How full one machine's disk is, read on the machine every minute. (Home, Sidebar, Context sidebar)
  • machines — Each machine, online or not, with its CPU, memory, disk and readiness. (Home, Sidebar, Context sidebar)
  • monitors — The monitors running in the selected session. (Context sidebar)
  • open-pull-requests — How many of your pull requests are open, hidden when there are none.
  • publish-port — A button that publishes a port of the selected workspace on a subdomain, when a machine runs Caddy. (Context sidebar)
  • pull-requests — The pull requests of the selected session, with their checks and review state. (Context sidebar)
  • pull-requests-panel — Your open pull requests by owner, with their checks and review state. (Home, Sidebar, Context sidebar)
  • shells — The background shells of the selected session. (Context sidebar)
  • shortcuts — Skill buttons for the machine or workspace of the selected session. (Context sidebar)
  • sub-agents — The sub-agents the selected session started, and whether each still runs. (Context sidebar)
  • summary — How many sessions, coding-harness sessions and workspaces are open. (Home, Sidebar, Context sidebar)
  • todo — The plan of the selected session and its to-do list. (Context sidebar)
  • usage — One coding harness's usage windows, how much of each is used and when it resets. (Home, Sidebar, Context sidebar)
  • usage-panel — Every coding harness's usage windows side by side, how much is used and when each resets.
  • workspaces — Your machines and workspaces with their sessions, in the order you drag them. (Sidebar, Context sidebar)
Source of devmachine-app (opens in a new tab) →

devmachine-skills

Coding agents · workspace

Agent skills for operating Devmachine and editing its app's boards.

devmachine packages add devmachine-skills --workspace acme
Source of devmachine-skills (opens in a new tab) →

docker

Containers · machine

Docker Engine and the Compose plugin, from Docker's own repository on Debian and Ubuntu and from the system's own on Arch Linux. On macOS, colima and the docker CLI from Homebrew, with a VM for each workspace.

devmachine packages add docker

Settings: workspaces, vm_cpus, vm_memory

Source of docker (opens in a new tab) →

essentials

Comes with setup
Foundation · machine

What almost every machine wants, in one package: base tools, git, a firewall, SSH with passwords kept off, Caddy to publish sites with HTTPS, and what the Devmachine macOS app reads from a machine. Docker is not included; add it with the docker package when you want it.

devmachine packages add essentials

New machines already have it, through essentials. This command is for a machine set up without it (setup --no-essentials).

Source of essentials (opens in a new tab) →

fail2ban

Security · machine

fail2ban, with a jail for sshd.

devmachine packages add fail2ban

Settings: maxretry, bantime, ignoreip

Source of fail2ban (opens in a new tab) →

firewall

Comes with setup
Security · machine

ufw, with SSH open and HTTP optional. It needs the community.general collection on the machine. On macOS, the Application Firewall, with sshd permitted before it is turned on.

devmachine packages add firewall

New machines already have it, through essentials. This command is for a machine set up without it (setup --no-essentials).

Settings: http, mosh_interface, mosh_ports

Source of firewall (opens in a new tab) →

git

Comes with setup
Foundation · machine

Installs git.

devmachine packages add git

New machines already have it, through essentials. This command is for a machine set up without it (setup --no-essentials).

Source of git (opens in a new tab) →

git-key

Developer tools · workspace

One SSH key the whole machine pushes to a forge with, copied into each workspace.

devmachine packages add git-key --workspace acme

Settings: home

Needs login: git-key

Source of git-key (opens in a new tab) →

glab

Developer tools · workspace

The GitLab CLI, installed into one account's own ~/.local/bin. It installs the tool only: the login opens a browser, so a person does it once.

devmachine packages add glab --workspace acme

Settings: home, version

Needs login: glab

Source of glab (opens in a new tab) →

hostinger

DNS · machine · dns

DNS zones on Hostinger.

devmachine packages add hostinger

Settings: zones

Needs login: hostinger

Source of hostinger (opens in a new tab) →

kimi-code

Coding agents · workspace

Moonshot AI's Kimi Code CLI (kimi) for one account. Logging in is a person's job, once, in each account.

devmachine packages add kimi-code --workspace acme

Settings: home

Needs login: kimi

Source of kimi-code (opens in a new tab) →

mac-brew

macOS · machine

Installs Homebrew taps, formulae and casks from lists. Never removes anything.

devmachine packages add mac-brew

Settings: prefix, taps, formulae, casks, trusted_casks, trusted_formulae

Source of mac-brew (opens in a new tab) →

mac-mise

macOS · machine

Installs mise's global tools from a list.

devmachine packages add mac-mise

Settings: bin, tools

Source of mac-mise (opens in a new tab) →

mac-ports

macOS · machine

Installs MacPorts ports from a list. Never removes anything.

devmachine packages add mac-ports

Settings: ports

Source of mac-ports (opens in a new tab) →

mise

In every workspace
Foundation · workspace

mise, the per-project runtime manager, installed for one account and activated in ~/.devmachine/shellenv so it is on the PATH in every shell, bash, zsh or sh, even without a terminal.

Every new workspace has it — nothing to add.

Settings: home

Source of mise (opens in a new tab) →

opencode

Coding agents · workspace

The opencode CLI for one account. It runs without a login on opencode's own free models; logging in to another provider is a person's job, once, in each account.

devmachine packages add opencode --workspace acme

Settings: home

Needs login: opencode

Source of opencode (opens in a new tab) →

pi

Coding agents · workspace

The Pi coding agent for one account, from its standalone release, so it needs no Node. Logging in is a person's job, once, in each account.

devmachine packages add pi --workspace acme

Settings: home

Needs login: pi

Source of pi (opens in a new tab) →

sentry

Developer tools · workspace

The Sentry CLI, installed into one account's own ~/.local/bin. It installs the tool only: the login opens a browser, so a person does it once in each workspace — the session is not one this CLI will copy.

devmachine packages add sentry --workspace acme

Settings: home

Needs login: sentry

Source of sentry (opens in a new tab) →

session-share

Developer tools · workspace

Share one of the account's tmux sessions with someone else for a limited time, in a browser or over SSH, read only or typing along.

devmachine packages add session-share --workspace acme

Settings: home, version, port

Source of session-share (opens in a new tab) →

ssh_hardening

Comes with setup
Security · machine

Turns off password authentication for good. setup does this once, at first contact, before Ansible exists; this keeps it that way on every converge.

devmachine packages add ssh_hardening

New machines already have it, through essentials. This command is for a machine set up without it (setup --no-essentials).

Settings: service

Source of ssh_hardening (opens in a new tab) →

tailscale

Network · machine · vpn

Joins the machine to a tailnet, so it is reachable without a public address.

devmachine packages add tailscale

Settings: exit_node, login_server

Needs login: tailscale

Source of tailscale (opens in a new tab) →

workspace

In every workspace
Foundation · workspace

The account a person works in: a home nobody else can read, a git identity, ~/dev, and one environment every shell of the account reads.

Every workspace has it; it creates the account.

Settings: home, admin_home, groups, shell, git_name, git_email, sign_commits, known_hosts, repos

Source of workspace (opens in a new tab) →

zsh

In every workspace
Foundation · workspace

zsh as the account's login shell, Oh My Zsh, a tmux config, and a shell that attaches to a tmux session when the connection is over SSH. A tmux server already running keeps its old configuration until it is told to reload.

Every new workspace has it — nothing to add.

Settings: home, tmux_auto_attach, tmux_config

Source of zsh (opens in a new tab) →

Contribute

Write your own.

A package is an Ansible role plus a package.yml. Start with devmachine packages new <name>, then share it by opening a pull request on mydevmachine/packages.

How to write a package →

mydevmachine/packages on GitHub → (opens in a new tab)