#!/usr/bin/env bash # Pushes a project's first env file and grants read-only access to one # or more already-registered recipients (typically the VPS boxes that # will deploy it), in one call. # # Usage: # ./bootstrap-project.sh [recipient-id...] # # The pusher (this machine's identity) becomes the vault's first, # read-write recipient automatically — see IMPLEMENTATION.md. Every # recipient-id argument here is granted read-only; run `keep grant` # by hand afterward for anyone who needs write access too. set -euo pipefail vault="${1:?usage: bootstrap-project.sh [recipient-id...]}" file="${2:?usage: bootstrap-project.sh [recipient-id...]}" shift 2 if [ "$#" -eq 0 ]; then echo "error: at least one recipient id is required" >&2 exit 1 fi keep push "$vault" --file "$file" for recipient in "$@"; do keep grant "$vault" "$recipient" --read-only done echo "" echo "done. verify with: KEEP_ADMIN_PASSWORD=... keep overview"