jevhooks.git / fnox.toml

:schema https://fnox.jdx.dev/schema.json

The one secret the daemon needs, DECLARED and nothing else: no value and no provider is written here, so there is nothing to leak and nothing to choose for you. fnox is optional. Without it the daemon reads the name from its environment. To use it, put your own provider in fnox.local.toml (gitignored) or in ~/.config/fnox/config.toml, for example age or 1Password.

tools/with-secrets.sh (used by mise run serve) runs a command under fnox exec when fnox is installed and resolves this, and runs it plainly otherwise.

A name nobody has provided is left unset (the daemon then runs, judges nothing, and status says no key), not an error here.

13if_missing = "ignore"
15[secrets.TYPESAFE_API_KEY]
16description = "Jev (TypeSafe) key; without it every verdict is pass"