postjevsql.git / tools / with-secrets.sh
1#!/usr/bin/env bash
2# Run a command with the live Jev key in its environment.
3#
4#     tools/with-secrets.sh <command> [args...]
5#
6# TYPESAFE_API_KEY is declared, without a value, in fnox.toml. With fnox installed and a provider set up
7# for it the command runs under `fnox exec`; otherwise it simply runs, and the variable must already be
8# in the environment. No value is ever read from a file in this repository.
9set -euo pipefail
10cd "$(dirname "$0")/.."
11if command -v fnox >/dev/null 2>&1 && [ -z "${POSTJEVSQL_NO_FNOX:-}" ] && fnox check >/dev/null 2>&1; then
12  exec fnox exec -- "$@"
13fi
14exec "$@"