Deploy All Services #2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Deploy All Services | |
| on: | |
| workflow_dispatch: | |
| env: | |
| PROJECT_ID: ${{ secrets.GCP_PROJECT_ID }} | |
| REGION: "us-central1" | |
| REPO_NAME: "structurify-repo" | |
| jobs: | |
| deploy-backend: | |
| name: Deploy Backend to Cloud Run | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout Repository | |
| uses: actions/checkout@v4 | |
| - name: Authenticate to Google Cloud | |
| uses: google-github-actions/auth@v2 | |
| with: | |
| credentials_json: '${{ secrets.GCP_CREDENTIALS }}' | |
| - name: Set up Cloud SDK | |
| uses: google-github-actions/setup-gcloud@v2 | |
| - name: Build and Deploy Backend | |
| run: | | |
| BACKEND_IMAGE="${REGION}-docker.pkg.dev/${PROJECT_ID}/${REPO_NAME}/backend" | |
| SA_EMAIL="etl-backend-sa@${PROJECT_ID}.iam.gserviceaccount.com" | |
| cd backend | |
| gcloud builds submit --tag ${BACKEND_IMAGE} . | |
| gcloud run deploy structurify-backend \ | |
| --image ${BACKEND_IMAGE} \ | |
| --platform managed \ | |
| --region ${REGION} \ | |
| --allow-unauthenticated \ | |
| --service-account ${SA_EMAIL} \ | |
| --set-env-vars GOOGLE_CLOUD_PROJECT=${PROJECT_ID},RAW_BUCKET_NAME=raw-uploads-${PROJECT_ID},PUBSUB_TOPIC_ID=schema-transformation-jobs | |
| deploy-worker: | |
| name: Deploy Worker to Cloud Run | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout Repository | |
| uses: actions/checkout@v4 | |
| - name: Authenticate to Google Cloud | |
| uses: google-github-actions/auth@v2 | |
| with: | |
| credentials_json: '${{ secrets.GCP_CREDENTIALS }}' | |
| - name: Set up Cloud SDK | |
| uses: google-github-actions/setup-gcloud@v2 | |
| - name: Build and Deploy Worker | |
| run: | | |
| WORKER_IMAGE="${REGION}-docker.pkg.dev/${PROJECT_ID}/${REPO_NAME}/worker" | |
| SA_EMAIL="etl-backend-sa@${PROJECT_ID}.iam.gserviceaccount.com" | |
| cd worker | |
| gcloud builds submit --tag ${WORKER_IMAGE} . | |
| gcloud run deploy structurify-worker \ | |
| --image ${WORKER_IMAGE} \ | |
| --platform managed \ | |
| --region ${REGION} \ | |
| --no-allow-unauthenticated \ | |
| --service-account ${SA_EMAIL} \ | |
| --set-env-vars GOOGLE_CLOUD_PROJECT=${PROJECT_ID},RAW_BUCKET_NAME=raw-uploads-${PROJECT_ID},PROCESSED_BUCKET_NAME=processed-outputs-${PROJECT_ID},FRONTEND_URL=https://structurify.web.app,SMTP_SERVER=${{ secrets.SMTP_SERVER }},SMTP_PORT=${{ secrets.SMTP_PORT }},SMTP_USERNAME=${{ secrets.SMTP_USERNAME }},SMTP_PASSWORD=${{ secrets.SMTP_PASSWORD }},SMTP_FROM_EMAIL=${{ secrets.SMTP_FROM_EMAIL }} \ | |
| --set-secrets=GEMINI_API_KEY=gemini-api-key:latest \ | |
| --memory=2Gi \ | |
| --timeout=3600s | |
| - name: Update Pub/Sub Subscriptions | |
| run: | | |
| WORKER_URL=$(gcloud run services describe structurify-worker --platform managed --region ${REGION} --format 'value(status.url)') | |
| PUBSUB_SA="pubsub-invoker-sa" | |
| PUBSUB_SA_EMAIL="${PUBSUB_SA}@${PROJECT_ID}.iam.gserviceaccount.com" | |
| gcloud pubsub subscriptions update schema-transformation-sub-push \ | |
| --push-endpoint="${WORKER_URL}/process-job" \ | |
| --push-auth-service-account="${PUBSUB_SA_EMAIL}" | |
| gcloud pubsub subscriptions update chunk-processing-sub-push \ | |
| --push-endpoint="${WORKER_URL}/process-chunk" \ | |
| --push-auth-service-account="${PUBSUB_SA_EMAIL}" | |
| deploy-frontend: | |
| name: Deploy Frontend to Firebase | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout Repository | |
| uses: actions/checkout@v4 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '20' | |
| cache: 'npm' | |
| cache-dependency-path: frontend/package-lock.json | |
| - name: Authenticate to Google Cloud | |
| uses: google-github-actions/auth@v2 | |
| with: | |
| credentials_json: '${{ secrets.GCP_CREDENTIALS }}' | |
| - name: Build and Deploy Frontend | |
| env: | |
| NEXT_PUBLIC_FIREBASE_API_KEY: ${{ secrets.NEXT_PUBLIC_FIREBASE_API_KEY }} | |
| NEXT_PUBLIC_FIREBASE_AUTH_DOMAIN: ${{ secrets.NEXT_PUBLIC_FIREBASE_AUTH_DOMAIN }} | |
| NEXT_PUBLIC_FIREBASE_PROJECT_ID: ${{ secrets.NEXT_PUBLIC_FIREBASE_PROJECT_ID }} | |
| NEXT_PUBLIC_FIREBASE_STORAGE_BUCKET: ${{ secrets.NEXT_PUBLIC_FIREBASE_STORAGE_BUCKET }} | |
| NEXT_PUBLIC_FIREBASE_MESSAGING_SENDER_ID: ${{ secrets.NEXT_PUBLIC_FIREBASE_MESSAGING_SENDER_ID }} | |
| NEXT_PUBLIC_FIREBASE_APP_ID: ${{ secrets.NEXT_PUBLIC_FIREBASE_APP_ID }} | |
| NEXT_PUBLIC_BACKEND_URL: ${{ secrets.NEXT_PUBLIC_BACKEND_URL }} | |
| run: | | |
| cd frontend | |
| npm ci | |
| npm run build | |
| npx firebase deploy --only hosting --project ${PROJECT_ID} |