1#!/usr/bin/env node
wrangler dev --config worker/wrangler.json <args>: the jevstrudel Worker,
started by supervise.mjs inside op-env-run, so JEVSTRUDEL_TYPESAFE_API_KEY
arrives from 1Password in this process's environment. dev.mjs passes
--env dev; preview.mjs the production config and the static build.
(Capturing the key with op-env-run -- printenv does not work: op masks
secrets in anything a command prints, and the key becomes
"<concealed by 1Password>".)
wrangler hands the Worker every variable in its environment (CLOUDFLARE_INCLUDE_PROCESS_ENV), and op-env-run's environment holds every secret it knows, so wrangler gets only the key and what it needs to run.
13import { spawn } from 'node:child_process';
15const pass = ['PATH', 'HOME', 'SSL_CERT_FILE', 'NIX_SSL_CERT_FILE', 'JEVSTRUDEL_TYPESAFE_API_KEY']; 16const env = Object.fromEntries(pass.filter((k) => process.env[k]).map((k) => [k, process.env[k]])); 17env.CLOUDFLARE_INCLUDE_PROCESS_ENV = 'true'; 18if (!env.JEVSTRUDEL_TYPESAFE_API_KEY) console.error('worker: no JEVSTRUDEL_TYPESAFE_API_KEY; the Jev relay will refuse calls'); 19 20const args = ['dev', '--config', 'worker/wrangler.json', ...process.argv.slice(2)]; 21const wrangler = spawn('wrangler', args, { env, stdio: 'inherit' }); 22wrangler.on('exit', (code, signal) => process.exit(code ?? (signal ? 1 : 0))); 23for (const signal of ['SIGINT', 'SIGTERM']) process.on(signal, () => wrangler.kill(signal));