Files
SnapOtter/scripts/bake-analytics.mjs
T

40 lines
1.7 KiB
JavaScript
Raw Normal View History

import { writeFileSync } from "node:fs";
import { dirname, resolve } from "node:path";
import { fileURLToPath } from "node:url";
const __dirname = dirname(fileURLToPath(import.meta.url));
const outPath = resolve(__dirname, "../packages/shared/src/analytics/baked.ts");
const mode = process.argv[2] || "on";
const on = mode === "on";
// Real telemetry creds are injected at build time from the environment -- the
// official image's CI supplies them from secrets, so they are NOT committed and
// a build from source stays silent. A Sentry DSN and a PostHog project key are
// public (they ship in the browser bundle), so this is about not making forks /
// source builds phone home by default, not about secrecy.
const posthogApiKey = on
? (process.env.SNAPOTTER_POSTHOG_PROJECT_ID ?? process.env.SNAPOTTER_POSTHOG_KEY ?? "")
: "";
const sentryDsn = on ? (process.env.SNAPOTTER_SENTRY_DSN ?? "") : "";
const posthogHost = posthogApiKey ? "https://us.i.posthog.com" : "";
// Enabled only when turned on AND there is somewhere to report to, so a
// credential-less source build never initializes the SDKs.
const enabled = on && (posthogApiKey !== "" || sentryDsn !== "");
// tracesSampleRate only governs performance transactions; errors are always
// captured. Keep low so fleet-wide tracing does not drain Sentry quota.
const sampleRate = sentryDsn ? 0.1 : 0;
const content = `// AUTO-GENERATED by scripts/bake-analytics.mjs -- do not edit manually
export const ANALYTICS_BAKED = {
enabled: ${enabled},
posthogApiKey: "${posthogApiKey}",
posthogHost: "${posthogHost}",
sentryDsn: "${sentryDsn}",
sampleRate: ${sampleRate},
} as const;
`;
writeFileSync(outPath, content, "utf-8");
console.log(`bake-analytics: wrote ${outPath} (mode=${mode}, enabled=${enabled})`);