Packages
Packages.
Each package adds one thing to a machine or a workspace. Add one with
devmachine packages add <name>,
then devmachine sync.
Some also carry widgets for the
macOS app's Home and sidebars.
Comes with setup
is on every new machine, through essentials
(setup --no-essentials skips it).
In every workspace
is on every new workspace.
Package list
33 packages
antigravity
Google's Antigravity CLI (agy) for one account. Logging in is a person's job, once, in each account.
devmachine packages add antigravity --workspace acme Settings: home
Needs login: antigravity
base
Comes with setupThe base tools a development machine needs, plus a shared tmux config and a session picker.
devmachine packages add base
New machines already have it, through essentials. This command is for a machine set up without it
(setup --no-essentials).
Settings: timezone, hostname, upgrade, swap
caddy
Comes with setupA reverse proxy that gets its own certificates, and a one-page site that answers 200 to prove the machine is reachable. Every other site is a file another package drops into /etc/caddy/sites.d.
devmachine packages add caddy
New machines already have it, through essentials. This command is for a machine set up without it
(setup --no-essentials).
Settings: email, local_certs, site, site_domain, source, version
claude-code
The Claude Code CLI for one account, its ~/.claude directory and the settings.json the account starts with. Logging in is a person's job, once, in each account.
devmachine packages add claude-code --workspace acme Settings: home, status_line, remote_control_at_startup, session_name_prefix, env, diff_sidebar, expanded_todos
Needs login: claude
Widgets:
-
usage— Claude Code usage windows, how much of each is used and when it resets. (Home, Sidebar, Context sidebar)
claude-plugins
Installs and updates Claude Code plugins in one account. It knows how, never which: the marketplace and the plugin list are the operator's, and with no marketplace configured it does nothing.
devmachine packages add claude-plugins --workspace acme Settings: home, claude, marketplace, plugins, update
claude-remote-control
Keeps one account's Claude Code Remote Control session up: a user systemd unit plus linger on Linux, a launch daemon on macOS, so it survives every logout. It starts only where that account has logged in, because there is nothing to connect without a session.
devmachine packages add claude-remote-control --workspace acme Settings: home, session_name, working_directory, restart_seconds
cline
The Cline CLI for one account, installed with the account's own Node. Logging in is a person's job, once, in each account.
devmachine packages add cline --workspace acme Settings: home
Needs login: cline
cloudflare
DNS zones on Cloudflare.
devmachine packages add cloudflare Needs login: cloudflare
codex
OpenAI's Codex CLI for one account, from its standalone release, so it needs no Node. Logging in is a person's job, once, in each account.
devmachine packages add codex --workspace acme Settings: home
Needs login: codex
Widgets:
-
usage— Codex usage windows, how much of each is used and when it resets. (Home, Sidebar, Context sidebar)
dev
In every workspaceThe four tools a workspace is expected to have: the GitHub CLI, bun, the Node LTS through mise, and unzip. It installs gh and declares the login gh needs; one GitHub account normally serves every workspace on a machine.
Every new workspace has it — nothing to add.
Settings: home, gh_version, node_version
Needs login: gh
devmachine-app
Comes with setup What the Devmachine macOS app asks a machine for, reached through devmachine run --package devmachine-app.
devmachine packages add devmachine-app
New machines already have it, through essentials. This command is for a machine set up without it
(setup --no-essentials).
Settings: github_hosts
Widgets:
-
brand— The Devmachine mark, the first thing in the menu bar. -
clock— The time, the date and the computer the app runs on. (Home, Sidebar, Context sidebar) -
links— The links the selected session mentioned. (Context sidebar) -
machine-stats— How full one machine's disk is, read on the machine every minute. (Home, Sidebar, Context sidebar) -
machines— Each machine, online or not, with its CPU, memory, disk and readiness. (Home, Sidebar, Context sidebar) -
monitors— The monitors running in the selected session. (Context sidebar) -
open-pull-requests— How many of your pull requests are open, hidden when there are none. -
publish-port— A button that publishes a port of the selected workspace on a subdomain, when a machine runs Caddy. (Context sidebar) -
pull-requests— The pull requests of the selected session, with their checks and review state. (Context sidebar) -
pull-requests-panel— Your open pull requests by owner, with their checks and review state. (Home, Sidebar, Context sidebar) -
shells— The background shells of the selected session. (Context sidebar) -
shortcuts— Skill buttons for the machine or workspace of the selected session. (Context sidebar) -
sub-agents— The sub-agents the selected session started, and whether each still runs. (Context sidebar) -
summary— How many sessions, coding-harness sessions and workspaces are open. (Home, Sidebar, Context sidebar) -
todo— The plan of the selected session and its to-do list. (Context sidebar) -
usage— One coding harness's usage windows, how much of each is used and when it resets. (Home, Sidebar, Context sidebar) -
usage-panel— Every coding harness's usage windows side by side, how much is used and when each resets. -
workspaces— Your machines and workspaces with their sessions, in the order you drag them. (Sidebar, Context sidebar)
devmachine-skills
Agent skills for operating Devmachine and editing its app's boards.
devmachine packages add devmachine-skills --workspace acme docker
Docker Engine and the Compose plugin, from Docker's own repository on Debian and Ubuntu and from the system's own on Arch Linux. On macOS, colima and the docker CLI from Homebrew, with a VM for each workspace.
devmachine packages add docker Settings: workspaces, vm_cpus, vm_memory
essentials
Comes with setupWhat almost every machine wants, in one package: base tools, git, a firewall, SSH with passwords kept off, Caddy to publish sites with HTTPS, and what the Devmachine macOS app reads from a machine. Docker is not included; add it with the docker package when you want it.
devmachine packages add essentials
New machines already have it, through essentials. This command is for a machine set up without it
(setup --no-essentials).
fail2ban
fail2ban, with a jail for sshd.
devmachine packages add fail2ban Settings: maxretry, bantime, ignoreip
firewall
Comes with setupufw, with SSH open and HTTP optional. It needs the community.general collection on the machine. On macOS, the Application Firewall, with sshd permitted before it is turned on.
devmachine packages add firewall
New machines already have it, through essentials. This command is for a machine set up without it
(setup --no-essentials).
Settings: http, mosh_interface, mosh_ports
git
Comes with setupInstalls git.
devmachine packages add git
New machines already have it, through essentials. This command is for a machine set up without it
(setup --no-essentials).
git-key
One SSH key the whole machine pushes to a forge with, copied into each workspace.
devmachine packages add git-key --workspace acme Settings: home
Needs login: git-key
glab
The GitLab CLI, installed into one account's own ~/.local/bin. It installs the tool only: the login opens a browser, so a person does it once.
devmachine packages add glab --workspace acme Settings: home, version
Needs login: glab
hostinger
DNS zones on Hostinger.
devmachine packages add hostinger Settings: zones
Needs login: hostinger
kimi-code
Moonshot AI's Kimi Code CLI (kimi) for one account. Logging in is a person's job, once, in each account.
devmachine packages add kimi-code --workspace acme Settings: home
Needs login: kimi
mac-brew
Installs Homebrew taps, formulae and casks from lists. Never removes anything.
devmachine packages add mac-brew Settings: prefix, taps, formulae, casks, trusted_casks, trusted_formulae
mac-mise
Installs mise's global tools from a list.
devmachine packages add mac-mise Settings: bin, tools
mac-ports
Installs MacPorts ports from a list. Never removes anything.
devmachine packages add mac-ports Settings: ports
mise
In every workspacemise, the per-project runtime manager, installed for one account and activated in ~/.devmachine/shellenv so it is on the PATH in every shell, bash, zsh or sh, even without a terminal.
Every new workspace has it — nothing to add.
Settings: home
opencode
The opencode CLI for one account. It runs without a login on opencode's own free models; logging in to another provider is a person's job, once, in each account.
devmachine packages add opencode --workspace acme Settings: home
Needs login: opencode
pi
The Pi coding agent for one account, from its standalone release, so it needs no Node. Logging in is a person's job, once, in each account.
devmachine packages add pi --workspace acme Settings: home
Needs login: pi
sentry
The Sentry CLI, installed into one account's own ~/.local/bin. It installs the tool only: the login opens a browser, so a person does it once in each workspace — the session is not one this CLI will copy.
devmachine packages add sentry --workspace acme Settings: home
Needs login: sentry
session-share
Share one of the account's tmux sessions with someone else for a limited time, in a browser or over SSH, read only or typing along.
devmachine packages add session-share --workspace acme Settings: home, version, port
ssh_hardening
Comes with setup Turns off password authentication for good. setup does this once, at first contact, before Ansible exists; this keeps it that way on every converge.
devmachine packages add ssh_hardening
New machines already have it, through essentials. This command is for a machine set up without it
(setup --no-essentials).
Settings: service
tailscale
Joins the machine to a tailnet, so it is reachable without a public address.
devmachine packages add tailscale Settings: exit_node, login_server
Needs login: tailscale
workspace
In every workspaceThe account a person works in: a home nobody else can read, a git identity, ~/dev, and one environment every shell of the account reads.
Every workspace has it; it creates the account.
Settings: home, admin_home, groups, shell, git_name, git_email, sign_commits, known_hosts, repos
zsh
In every workspacezsh as the account's login shell, Oh My Zsh, a tmux config, and a shell that attaches to a tmux session when the connection is over SSH. A tmux server already running keeps its old configuration until it is told to reload.
Every new workspace has it — nothing to add.
Settings: home, tmux_auto_attach, tmux_config
Contribute
Write your own.
A package is an Ansible role plus a package.yml.
Start with devmachine packages new <name>,
then share it by opening a pull request on
mydevmachine/packages.