Files
orca/cloud/dev/scripts/read-relay-production-capacity-identity.mjs
T
Jinwoo Hong 3eec77c11a chore(cloud): add the relay fence broker, ops console, Terraform root, scripts, and 24 cloud-* workflows (#18413)
Phase 6 of the relay split: the relay's deploy/operate surface moves under cloud/ with 24 cloud-* workflows gated on ORCA_CLOUD_OPERATIONS_ENABLED, the Cloud SQL rollout lease action, the relay Terraform root (dual-accept identities for both repositories), scripts, docs, CODEOWNERS, and a terraform validate job in Cloud Verify.
2026-09-03 06:55:14 -04:00

32 lines
1.1 KiB
JavaScript

import { readFileSync } from 'node:fs'
import { pathToFileURL } from 'node:url'
const CAPACITY_IDENTITY_NAME = 'ORCA_RELAY_CAPACITY_SERVICE_ACCOUNT'
export function readProductionCapacityIdentity(revision) {
const env = revision?.spec?.containers?.[0]?.env
if (!Array.isArray(env)) throw new Error('director revision environment is missing')
const matches = env.filter((entry) => entry?.name === CAPACITY_IDENTITY_NAME)
if (matches.length === 0) return null
if (matches.length !== 1) throw new Error('duplicate capacity identity')
const value = matches[0]?.value
if (typeof value !== 'string' || value.length === 0) {
throw new Error('capacity identity is not a literal string')
}
return value
}
export function main() {
const revision = JSON.parse(readFileSync(0, 'utf8'))
process.stdout.write(`${JSON.stringify(readProductionCapacityIdentity(revision))}\n`)
}
if (import.meta.url === pathToFileURL(process.argv[1]).href) {
try {
main()
} catch (error) {
process.stderr.write(`${error instanceof Error ? error.message : String(error)}\n`)
process.exitCode = 1
}
}