Skip to main content

sapphire-infra

Infrastructure-as-code — GCP Terraform, Pi deployment configs, Docker

설치로 이동

소스 정보

저장소
arigatoexpress/Sapphire
최근 소스 활동
2026년 8월 9일 08:23
감지된 SKILL.md 언어
영어
스타
1
포크
0

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
100 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
sapphire-infra
description
Infrastructure-as-code — GCP Terraform, Pi deployment configs, Docker
type
infra
runtime
terraform
deploy_target
cloud
dependencies
[]
entry_point
infra/terraform/main.tf
test_command
terraform validate
# infra/ All infrastructure definitions. Never edit production Pi configs without backing up first. ## Structure ``` infra/ ├── terraform/ # GCP: Cloud Run, Firestore, Secret Manager, DNS ├── pi/ # rari1 (controller) + rari2 (trading) systemd configs └── docker/ # Local dev docker-compose overrides ``` ## Terraform (GCP: sapphire-479610) ```bash cd infra/terraform terraform init terraform plan terraform apply ``` Services managed: Cloud Run (alpha, dashboard, control-plane, webhook), Firestore, Secret Manager, Cloud DNS. ## Pi Configs (infra/pi/) - `rari1/` — systemd units for control-plane + Kimi agent + Telegram bot - `rari2/` — systemd unit for lighter-trading.service + ProtonVPN config Deploy to Pi: ```bash rsync -av infra/pi/rari2/ rari@100.x.x.y:/etc/systemd/system/ ssh rari@100.x.x.y sudo systemctl daemon-reload ``` ## Pi SSH Access Use key-based SSH only. Do not use `sshpass`, password prompts, or inline passwords in agent workflows. Dedicated Mac commander key: ```bash ~/.ssh/sapphire_rari_ed25519 ``` Install the public key from a trusted interactive shell when the Pi is reachable: ```bash ssh-copy-id -i ~/.ssh/sapphire_rari_ed25519.pub rari@100.x.x.y ssh -i ~/.ssh/sapphire_rari_ed25519 -o BatchMode=yes rari@100.x.x.y 'printf key-ok' ``` If SSH is unreachable over Tailscale and LAN, leave the Pi out of the production path and keep Mac/Windows operation healthy; Sapphire must not depend on Pi availability. ## Devices | Device | Tailscale IP | Role | |--------|-------------|------| | mac | 100.x.x.w | Commander | | windows-pc | 100.x.x.z | NemoClaw inference | | rari1 | 100.x.x.x | Controller + Telegram | | rari2 | 100.x.x.y | Trading (Lighter + ProtonVPN) |
GitHub에서 보기