#!/usr/bin/env bash # # CB-594 — the only reason this file exists: launchd does not run a login shell. # # WORKER_GITEA_TOKEN and AI_GATEWAY_TOKEN live in ${SHARED_ENV}/tools/secrets.sh, sourced only by a # LOGIN shell (.zprofile/.zshrc etc). launchd execs a job's ProgramArguments directly — no shell, no # profile, nothing sourced (the plist's own PATH comment documents the same gap one variable over). # A daemon started that way boots fine and looks healthy; the failure is invisible until a worker # tries to open a PR (WORKER_GITEA_TOKEN empty) or a gateway profile gets a 401 (AI_GATEWAY_TOKEN # empty) — hours later, with nothing tying the two together (CB-591, CLAUDE.md "Redeploying the # daemon"). Fleetd now also logs which required secret names resolved at startup (see # Fleetd.reportRequiredSecrets), but that log line can only tell the truth if the tokens had a # chance to be sourced in the first place — which is this script's entire job. # # So: launchd execs THIS script instead of java directly. This script execs a login shell # ('zsh -l'), which sources secrets.sh, and that shell execs the real command in its place — one # process throughout (exec, not a subshell fork), so launchd's PID tracking, KeepAlive, and # StandardOut/ErrorPath all still see the one process they expect. # # The plist passes the full command as THIS script's own arguments, e.g.: # ProgramArguments = [ .../fleetd-launchd-wrapper.sh, /path/to/java, -jar, /path/to/fleetd.jar, # fleetd.yaml ] # so the wrapper stays generic and the actual command lives in exactly one place (the plist), not # duplicated here. set -euo pipefail if [ "$#" -eq 0 ]; then echo "fleetd-launchd-wrapper.sh: no command given — check the plist's ProgramArguments" >&2 exit 2 fi exec /bin/zsh -lc 'exec "$@"' -- "$@"