1#!/usr/bin/env bash 2# Run a command with the owner's secrets in its environment. 3# 4# tools/with-secrets.sh <command> [args...] 5# 6# The secrets (CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID, LMJTFY_TYPESAFE_API_KEY, LMJTFY_GITHUB_TOKEN) are 7# declared, without values, in fnox.toml. With fnox installed and a provider set up for them the command runs 8# under `fnox exec`; otherwise it simply runs, and the same variables must already be in the environment. 9# No value is ever read from a file in this repository. 10set -euo pipefail 11cd "$(dirname "$0")/.." 12if command -v fnox >/dev/null 2>&1 && [ -z "${LMJTFY_NO_FNOX:-}" ] && fnox check >/dev/null 2>&1; then 13 exec fnox exec -- "$@" 14fi 15exec "$@"