forked from mrjcleaver/video-sync
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdeploy-without-iap.sh
More file actions
executable file
·33 lines (30 loc) · 1.25 KB
/
Copy pathdeploy-without-iap.sh
File metadata and controls
executable file
·33 lines (30 loc) · 1.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
#!/usr/bin/env bash
#
# Deploy to Cloud Run WITHOUT IAP enforcement — emergency / dev escape
# hatch (video-sync service, agentics-487016 project).
#
# Production has been on IAP since 2026-04-27 (ADR-036 Accepted). The
# normal deploy is `bash deploy.sh`. Use this wrapper only when:
# - IAP setup needs to be temporarily rolled back
# - You're testing something locally and don't want to authenticate
# - The IAP layer itself is broken and you need to deploy past it
#
# What this gives you:
# --allow-unauthenticated → service URL is publicly reachable
# ALLOW_NO_IAP=1 → /api/auth/me returns the synthetic
# Admin actor; mutating UI works
# no IAP gating → anyone with the URL has Admin
#
# What this LOSES:
# per-user audit trail (everyone is the synthetic admin)
# group-membership access control
#
# Mechanism: explicitly clears IAP_AUDIENCE so deploy.sh's mode
# detector picks Open mode (it defaults to IAP mode when IAP_AUDIENCE
# is unset).
set -euo pipefail
export IAP_AUDIENCE=
export KEY_ADMIN_EMAILS=martin.cleaver@agentics.org
export OPERATOR_EMAILS=agent@agentics.org,mondweep.chakravorty@agentics.org
export VIEWER_EMAILS=board@agentics.org
bash "$(dirname "$0")/deploy.sh"