lmjtfy.git / tools / with-secrets.sh
1#!/usr/bin/env bash

Run a command with the owner's secrets in its environment.

tools/with-secrets.sh <command> [args...]

The secrets (CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID, LMJTFY_TYPESAFE_API_KEY, LMJTFY_GITHUB_TOKEN) are declared, without values, in fnox.toml. With fnox installed and a provider set up for them the command runs under fnox exec; otherwise it simply runs, and the same variables must already be in the environment. No value is ever read from a file in this repository.

10set -euo pipefail
11cd "$(dirname "$0")/.."
12if command -v fnox >/dev/null 2>&1 && [ -z "${LMJTFY_NO_FNOX:-}" ] && fnox check >/dev/null 2>&1; then
13  exec fnox exec -- "$@"
14fi
15exec "$@"