jevstrudel.git / tools / dev / worker.mjs
1#!/usr/bin/env node
2// `wrangler dev --config worker/wrangler.json <args>`: the jevstrudel Worker,
3// started by supervise.mjs inside `op-env-run`, so JEVSTRUDEL_TYPESAFE_API_KEY
4// arrives from 1Password in this process's environment. dev.mjs passes
5// `--env dev`; preview.mjs the production config and the static build.
6// (Capturing the key with `op-env-run -- printenv` does not work: op masks
7// secrets in anything a command prints, and the key becomes
8// "<concealed by 1Password>".)
9//
10// wrangler hands the Worker every variable in its environment
11// (CLOUDFLARE_INCLUDE_PROCESS_ENV), and op-env-run's environment holds every
12// secret it knows, so wrangler gets only the key and what it needs to run.
13import { spawn } from 'node:child_process';
14
15const pass = ['PATH', 'HOME', 'SSL_CERT_FILE', 'NIX_SSL_CERT_FILE', 'JEVSTRUDEL_TYPESAFE_API_KEY'];
16const env = Object.fromEntries(pass.filter((k) => process.env[k]).map((k) => [k, process.env[k]]));
17env.CLOUDFLARE_INCLUDE_PROCESS_ENV = 'true';
18if (!env.JEVSTRUDEL_TYPESAFE_API_KEY) console.error('worker: no JEVSTRUDEL_TYPESAFE_API_KEY; the Jev relay will refuse calls');
19
20const args = ['dev', '--config', 'worker/wrangler.json', ...process.argv.slice(2)];
21const wrangler = spawn('wrangler', args, { env, stdio: 'inherit' });
22wrangler.on('exit', (code, signal) => process.exit(code ?? (signal ? 1 : 0)));
23for (const signal of ['SIGINT', 'SIGTERM']) process.on(signal, () => wrangler.kill(signal));