whiskers.git / tools / with-secrets.sh
1#!/usr/bin/env bash
2# Run a command with whiskersd's secrets in its environment.
3#
4#     tools/with-secrets.sh <command> [args...]
5#
6# The secrets (TYPESAFE_API_KEY, ELEVENLABS_API_KEY, ELEVENLABS_VOICE_ID) and WHISKERS_MODEL_URL are declared,
7# without values, in fnox.toml. With fnox installed and a provider set up for them (see tools/README.md) the
8# command runs under `fnox exec`; otherwise it simply runs, and the same variables must already be in the
9# environment. No value is ever read from a file in this repository.
10set -euo pipefail
11cd "$(dirname "$0")/.."
12if command -v fnox >/dev/null 2>&1 && [ -z "${WHISKERS_NO_FNOX:-}" ] && fnox check >/dev/null 2>&1; then
13  exec fnox exec -- "$@"
14fi
15exec "$@"