GCR deployment testing in progress - content type issue still remaining.
This commit is contained in:
@@ -1,126 +1,71 @@
|
||||
# =============================================================================
|
||||
# 02-setup-project.ps1 (Windows)
|
||||
# One-time GCP project setup:
|
||||
# - Links a billing account to the project
|
||||
# - Enables required APIs (Cloud Run, Artifact Registry, Secret Manager)
|
||||
# - Creates an Artifact Registry Docker repository
|
||||
# - Grants the current user the minimum required IAM roles
|
||||
#
|
||||
# Safe to re-run — most operations are idempotent.
|
||||
# Linux users: run GCR/scripts/02-setup-project.sh instead.
|
||||
# =============================================================================
|
||||
#Requires -Version 5.1
|
||||
#Requires -Version 5.1
|
||||
param()
|
||||
Set-StrictMode -Version Latest
|
||||
$ErrorActionPreference = 'Stop'
|
||||
$ErrorActionPreference = 'Continue'
|
||||
|
||||
$ScriptDir = Split-Path -Parent $MyInvocation.MyCommand.Path
|
||||
$EnvFile = Join-Path $ScriptDir "..\\.env"
|
||||
|
||||
# ── Load .env ─────────────────────────────────────────────────────────────────
|
||||
if (-not (Test-Path $EnvFile)) {
|
||||
Write-Error "ERROR: $EnvFile not found.`nCopy GCR\.env.example to GCR\.env and fill in your values first."
|
||||
exit 1
|
||||
}
|
||||
if (-not (Test-Path $EnvFile)) { Write-Error "ERROR: $EnvFile not found."; exit 1 }
|
||||
|
||||
$config = @{}
|
||||
foreach ($line in Get-Content $EnvFile) {
|
||||
if ($line -match '^\s*$' -or $line -match '^\s*#') { continue }
|
||||
if ($line -match '^([^=]+)=(.*)$') {
|
||||
$config[$Matches[1].Trim()] = $Matches[2].Trim()
|
||||
}
|
||||
if ($line -match '^([^=]+)=(.*)$') { $config[$Matches[1].Trim()] = $Matches[2].Trim() }
|
||||
}
|
||||
|
||||
$GCP_PROJECT_ID = $config['GCP_PROJECT_ID'] ?? ''
|
||||
$GCP_REGION = $config['GCP_REGION'] ?? ''
|
||||
$GCP_REPOSITORY = $config['GCP_REPOSITORY'] ?? ''
|
||||
|
||||
if (-not $GCP_PROJECT_ID) { Write-Error "GCP_PROJECT_ID is not set in .env"; exit 1 }
|
||||
if (-not $GCP_REGION) { Write-Error "GCP_REGION is not set in .env"; exit 1 }
|
||||
if (-not $GCP_REPOSITORY) { Write-Error "GCP_REPOSITORY is not set in .env"; exit 1 }
|
||||
$GCP_PROJECT_ID = if ($config['GCP_PROJECT_ID']) { $config['GCP_PROJECT_ID'] } else { '' }
|
||||
$GCP_REGION = if ($config['GCP_REGION']) { $config['GCP_REGION'] } else { '' }
|
||||
$GCP_REPOSITORY = if ($config['GCP_REPOSITORY']) { $config['GCP_REPOSITORY'] } else { '' }
|
||||
if (-not $GCP_PROJECT_ID) { Write-Error "GCP_PROJECT_ID not set"; exit 1 }
|
||||
if (-not $GCP_REGION) { Write-Error "GCP_REGION not set"; exit 1 }
|
||||
if (-not $GCP_REPOSITORY) { Write-Error "GCP_REPOSITORY not set"; exit 1 }
|
||||
|
||||
Write-Host ">>> Active project: $GCP_PROJECT_ID"
|
||||
Write-Host ">>> Region: $GCP_REGION"
|
||||
Write-Host ">>> AR repository: $GCP_REPOSITORY"
|
||||
|
||||
Write-Host ""
|
||||
|
||||
# ── Step 1: Link billing account ──────────────────────────────────────────────
|
||||
Write-Host ">>> Checking billing status..."
|
||||
$billingOutput = gcloud billing projects describe $GCP_PROJECT_ID --format="value(billingEnabled)" 2>$null
|
||||
$billingEnabled = ($billingOutput -eq "True")
|
||||
|
||||
if ($billingEnabled) {
|
||||
Write-Host " Billing is already enabled — skipping."
|
||||
Write-Host ">>> Checking billing..."
|
||||
$billing = gcloud billing projects describe $GCP_PROJECT_ID --format='value(billingEnabled)' 2>$null
|
||||
if ($billing -eq 'True') {
|
||||
Write-Host " Billing already enabled."
|
||||
} else {
|
||||
Write-Host ""
|
||||
Write-Host " Billing is NOT enabled on this project."
|
||||
Write-Host " Listing available billing accounts..."
|
||||
Write-Host ""
|
||||
gcloud billing accounts list --format="table(name,displayName,open)"
|
||||
Write-Host ""
|
||||
$BILLING_ACCOUNT_ID = Read-Host " Enter the BILLING_ACCOUNT_ID from the list above (format: XXXXXX-XXXXXX-XXXXXX)"
|
||||
gcloud billing projects link $GCP_PROJECT_ID --billing-account=$BILLING_ACCOUNT_ID
|
||||
Write-Host " Billing NOT enabled. Listing accounts..."
|
||||
gcloud billing accounts list --format='table(name,displayName,open)' 2>$null
|
||||
$BILLING_ACCOUNT_ID = Read-Host " Enter BILLING_ACCOUNT_ID"
|
||||
gcloud billing projects link $GCP_PROJECT_ID --billing-account=$BILLING_ACCOUNT_ID 2>$null
|
||||
if ($LASTEXITCODE -ne 0) { Write-Error "Failed to link billing."; exit 1 }
|
||||
Write-Host " Billing linked."
|
||||
}
|
||||
|
||||
# ── Step 2: Enable required APIs ─────────────────────────────────────────────
|
||||
Write-Host ""
|
||||
Write-Host ">>> Enabling required Google Cloud APIs (this may take a minute)..."
|
||||
gcloud services enable `
|
||||
run.googleapis.com `
|
||||
artifactregistry.googleapis.com `
|
||||
secretmanager.googleapis.com `
|
||||
cloudresourcemanager.googleapis.com `
|
||||
--project=$GCP_PROJECT_ID
|
||||
Write-Host ">>> Enabling required APIs..."
|
||||
gcloud services enable run.googleapis.com artifactregistry.googleapis.com secretmanager.googleapis.com cloudresourcemanager.googleapis.com --project=$GCP_PROJECT_ID 2>$null
|
||||
if ($LASTEXITCODE -ne 0) { Write-Error "Failed to enable APIs."; exit 1 }
|
||||
Write-Host " APIs enabled."
|
||||
|
||||
# ── Step 3: Create Artifact Registry Docker repository ───────────────────────
|
||||
Write-Host ""
|
||||
Write-Host ">>> Creating Artifact Registry repository: $GCP_REPOSITORY ..."
|
||||
$repoExists = $false
|
||||
try {
|
||||
gcloud artifacts repositories describe $GCP_REPOSITORY `
|
||||
--location=$GCP_REGION `
|
||||
--project=$GCP_PROJECT_ID 2>$null | Out-Null
|
||||
$repoExists = $true
|
||||
} catch { }
|
||||
|
||||
if ($repoExists) {
|
||||
Write-Host " Repository already exists — skipping."
|
||||
Write-Host ">>> Checking Artifact Registry repository: $GCP_REPOSITORY ..."
|
||||
gcloud artifacts repositories describe $GCP_REPOSITORY --location=$GCP_REGION --project=$GCP_PROJECT_ID 2>$null | Out-Null
|
||||
if ($LASTEXITCODE -eq 0) {
|
||||
Write-Host " Repository already exists."
|
||||
} else {
|
||||
gcloud artifacts repositories create $GCP_REPOSITORY `
|
||||
--repository-format=docker `
|
||||
--location=$GCP_REGION `
|
||||
--description="Container images for Htmx app" `
|
||||
--project=$GCP_PROJECT_ID
|
||||
Write-Host " Creating repository..."
|
||||
gcloud artifacts repositories create $GCP_REPOSITORY --repository-format=docker --location=$GCP_REGION --description="Container images for Htmx app" --project=$GCP_PROJECT_ID 2>$null
|
||||
if ($LASTEXITCODE -ne 0) { Write-Error "Failed to create repository."; exit 1 }
|
||||
Write-Host " Repository created."
|
||||
}
|
||||
|
||||
# ── Step 4: Grant current user the minimum required IAM roles ─────────────────
|
||||
$CURRENT_USER = (gcloud config get-value account).Trim()
|
||||
$CURRENT_USER = (gcloud config get-value account 2>$null).Trim()
|
||||
Write-Host ""
|
||||
Write-Host ">>> Granting IAM roles to $CURRENT_USER ..."
|
||||
|
||||
foreach ($role in @(
|
||||
"roles/run.developer",
|
||||
"roles/artifactregistry.writer",
|
||||
"roles/iam.serviceAccountUser",
|
||||
"roles/secretmanager.admin",
|
||||
"roles/secretmanager.secretAccessor",
|
||||
"roles/secretmanager.secretVersionAdder"
|
||||
)) {
|
||||
Write-Host " Adding role: $role"
|
||||
gcloud projects add-iam-policy-binding $GCP_PROJECT_ID `
|
||||
--member="user:$CURRENT_USER" `
|
||||
--role=$role `
|
||||
--quiet
|
||||
foreach ($role in @("roles/run.developer","roles/artifactregistry.writer","roles/iam.serviceAccountUser","roles/secretmanager.admin","roles/secretmanager.secretAccessor","roles/secretmanager.secretVersionAdder")) {
|
||||
Write-Host " $role"
|
||||
gcloud projects add-iam-policy-binding $GCP_PROJECT_ID --member="user:$CURRENT_USER" --role=$role --quiet 2>$null | Out-Null
|
||||
}
|
||||
|
||||
Write-Host ""
|
||||
Write-Host ">>> Project setup complete."
|
||||
Write-Host ""
|
||||
Write-Host ">>> Summary:"
|
||||
Write-Host " Project ID: $GCP_PROJECT_ID"
|
||||
Write-Host " Region: $GCP_REGION"
|
||||
Write-Host " Artifact Registry: $GCP_REGION-docker.pkg.dev/$GCP_PROJECT_ID/$GCP_REPOSITORY"
|
||||
Write-Host ""
|
||||
Write-Host ">>> Next step: run GCR\scripts\03-create-secrets.ps1"
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user