1#!/usr/bin/env node 2// `wrangler dev --config worker/wrangler.json <args>`: the jevstrudel Worker, 3// started by supervise.mjs inside `op-env-run`, so JEVSTRUDEL_TYPESAFE_API_KEY 4// arrives from 1Password in this process's environment. dev.mjs passes 5// `--env dev`; preview.mjs the production config and the static build. 6// (Capturing the key with `op-env-run -- printenv` does not work: op masks 7// secrets in anything a command prints, and the key becomes 8// "<concealed by 1Password>".) 9// 10// wrangler hands the Worker every variable in its environment 11// (CLOUDFLARE_INCLUDE_PROCESS_ENV), and op-env-run's environment holds every 12// secret it knows, so wrangler gets only the key and what it needs to run. 13import { spawn } from 'node:child_process'; 14 15const pass = ['PATH', 'HOME', 'SSL_CERT_FILE', 'NIX_SSL_CERT_FILE', 'JEVSTRUDEL_TYPESAFE_API_KEY']; 16const env = Object.fromEntries(pass.filter((k) => process.env[k]).map((k) => [k, process.env[k]])); 17env.CLOUDFLARE_INCLUDE_PROCESS_ENV = 'true'; 18if (!env.JEVSTRUDEL_TYPESAFE_API_KEY) console.error('worker: no JEVSTRUDEL_TYPESAFE_API_KEY; the Jev relay will refuse calls'); 19 20const args = ['dev', '--config', 'worker/wrangler.json', ...process.argv.slice(2)]; 21const wrangler = spawn('wrangler', args, { env, stdio: 'inherit' }); 22wrangler.on('exit', (code, signal) => process.exit(code ?? (signal ? 1 : 0))); 23for (const signal of ['SIGINT', 'SIGTERM']) process.on(signal, () => wrangler.kill(signal));