Conversation
Zero-dependency Node CLI that stands up HARP on Google Cloud from a fork: project, billing, APIs, IAM, GCS bucket with CORS, Secret Manager, Artifact Registry, Cloud Run, migrations, and a deploy-on-push Cloud Build trigger. Idempotent, with --dry-run and an --account guard. Tested end to end against a real project and a fake gcloud in CI.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A zero-dependency Node CLI at
tools/create-harp/that stands up a production HARP deployment on Google Cloud from a fork. It automates everything ourharp-testaudit and setup screenshots did by hand:SENDGRID_API_KEYin Secret Manager with runtime access, and an Artifact Registry repo with a cleanup policy (keeps the newest 5 images).It generates the values nobody should pick by hand (VAPID pair,
AUTH_BASIC_PASS,PUBLIC_API_KEY) and reuses deployed values on re-runs, so nothing rotates silently.It stops and walks the user through the three browser-only steps, offering to open each page:
node tools/create-harp/bin/create-harp.js --dry-run # read-only; prints every change node tools/create-harp/bin/create-harp.jsAlso changed:
ADOPTING.mdandclaude.md.harp.deploy.json(non-secret answers) to.gitignore.create-harp-auditCI job.Why
Adopting HARP meant repeating ~90 console clicks. That's where the original setup went wrong: a
https://https://CORS origin, and a first deploy that failed on a missingsecretAccessorgrant. The CLI makes the setup repeatable and idempotent.Safety
gcloudcall carries--account.--account <email>aborts before any project call if the active account differs. It never changes the user's default gcloud project or config.gcloud run deploycall.Testing
gcloud(test/fake-gcloud.mjs). Covers the account guard, dry run making zero mutations, the GitHub-not-connected pause, a re-run changing nothing, IAM propagation, a taken bucket name, and the trigger-update rejection below. 14/14 passing, no network.harp-cli-test-0926) with a temporary Neon DB and dummy SuperTokens/SendGrid values:IAM_PERMISSION_DENIEDto the owner right after API enablement.gcloud builds triggers update githubrejects triggers with an inline build config (INVALID_ARGUMENT), so substitutions are now changed via describe +triggers import.Reviewer notes
VITE_GOOGLE_AUTH_ENABLEDis passed as a Docker build arg; as a runtime env var it had no effect.create-harpis taken, sopackage.jsonuses@hackutd/create-harp. Publishing needs the npm org.CLIENT_IP_HEADERdefaults toCF-Connecting-IP. On bare Cloud Run without Cloudflare, clients can set that header themselves and get around the per-IP rate limit. This PR leaves it unchanged.🤖 Generated with Claude Code