Recently Written · git

subplz-web

git clone https://github.com/equwal/subplz-web

Log | Files | Refs


tools/set-secret.sh (861 bytes)

1 #!/usr/bin/env bash
2 # Put one secret into .env without it touching shell history, the process list
3 # or the screen.
4 #
5 #   tools/set-secret.sh SUBPLZ_WEB_STRIPE_SECRET_KEY
6 set -euo pipefail
7 
8 key="${1:?usage: set-secret.sh VARIABLE_NAME}"
9 root="$(cd "$(dirname "$0")/.." && pwd)"
10 env_file="$root/.env"
11 
12 read -r -s -p "Value for $key (input hidden): " value
13 echo
14 [ -n "$value" ] || { echo "Empty value - nothing changed." >&2; exit 1; }
15 
16 touch "$env_file"
17 tmp="$(mktemp)"
18 grep -v "^${key}=" "$env_file" > "$tmp" || true
19 printf '%s=%s\n' "$key" "$value" >> "$tmp"
20 cat "$tmp" > "$env_file"
21 rm -f "$tmp"
22 
23 # The service does not run as root; keep the file readable by whoever owns the
24 # checkout, and by nobody else.
25 chown "$(stat -c %U:%G "$root")" "$env_file" 2>/dev/null || true
26 chmod 600 "$env_file"
27 
28 echo "$key saved. Apply it with: systemctl restart subplz-web"