lmjtfy.git / tools / with-secrets.sh
1#!/usr/bin/env bash
2# Run a command with the owner's secrets in its environment.
3#
4#     tools/with-secrets.sh <command> [args...]
5#
6# The secrets (CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID, LMJTFY_TYPESAFE_API_KEY, LMJTFY_GITHUB_TOKEN) are
7# declared, without values, in fnox.toml. With fnox installed and a provider set up for them the command runs
8# under `fnox exec`; otherwise it simply runs, and the same variables must already be in the environment.
9# No value is ever read from a file in this repository.
10set -euo pipefail
11cd "$(dirname "$0")/.."
12if command -v fnox >/dev/null 2>&1 && [ -z "${LMJTFY_NO_FNOX:-}" ] && fnox check >/dev/null 2>&1; then
13  exec fnox exec -- "$@"
14fi
15exec "$@"