Repository navigation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy VM for paperclip ai | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| jobs: | |
| deploy-paperclip-vm: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| - name: Authenticate to Google Cloud | |
| uses: google-github-actions/auth@v2 | |
| with: | |
| credentials_json: ${{ secrets.GCP_SA_KEY }} | |
| - name: Set up Cloud SDK | |
| uses: google-github-actions/setup-gcloud@v2 | |
| - name: Setup Terraform | |
| uses: hashicorp/setup-terraform@v3 | |
| with: | |
| terraform_version: 1.5.7 | |
| - name: Initialize Terraform | |
| working-directory: terraform | |
| run: terraform init | |
| - name: Import existing resources | |
| working-directory: terraform | |
| run: | | |
| # Check if resources are already in state | |
| if ! terraform state show google_compute_instance.paperclip_vm &>/dev/null; then | |
| if gcloud compute instances describe paperclip-ai-vm --zone=europe-north1-a &>/dev/null; then | |
| echo "VM exists but not in state, importing..." | |
| terraform import google_compute_instance.paperclip_vm projects/workflow-scanner/zones/europe-north1-a/instances/paperclip-ai-vm | |
| fi | |
| else | |
| echo "VM already in Terraform state" | |
| fi | |
| # Import firewalls if they exist and aren't in state | |
| if ! terraform state show google_compute_firewall.allow_ssh_paperclip &>/dev/null; then | |
| if gcloud compute firewall-rules describe allow-ssh-paperclip &>/dev/null; then | |
| echo "SSH firewall exists but not in state, importing..." | |
| terraform import google_compute_firewall.allow_ssh_paperclip projects/workflow-scanner/global/firewalls/allow-ssh-paperclip | |
| fi | |
| fi | |
| if ! terraform state show google_compute_firewall.allow_paperclip_web &>/dev/null; then | |
| if gcloud compute firewall-rules describe allow-paperclip-web &>/dev/null; then | |
| echo "Web firewall exists but not in state, importing..." | |
| terraform import google_compute_firewall.allow_paperclip_web projects/workflow-scanner/global/firewalls/allow-paperclip-web | |
| fi | |
| fi | |
| - name: Deploy Paperclip Infrastructure | |
| working-directory: terraform | |
| run: | | |
| terraform plan | |
| # Force replacement if startup script changed | |
| if git diff --name-only HEAD~1 HEAD | grep -q "scripts/paperclip-startup.sh"; then | |
| echo "Startup script changed, forcing VM replacement..." | |
| terraform apply -replace=google_compute_instance.paperclip_vm -auto-approve | |
| else | |
| terraform apply -auto-approve | |
| fi | |
| - name: Get VM external IP | |
| run: | | |
| VM_IP=$(gcloud compute instances describe paperclip-ai-vm \ | |
| --zone=europe-north1-a \ | |
| --format='get(networkInterfaces[0].accessConfigs[0].natIP)') | |
| echo "Paperclip AI will be available at: http://$VM_IP:3100" |