#!/usr/bin/env bash # Reads one KEY=VALUE out of a .env-style file WITHOUT ever executing the # file as shell. `source`-ing a .env file breaks the moment a value contains # characters bash treats specially — e.g. a Caddy bcrypt hash # ($2a$14$...) looks like positional-parameter expansions ($2, $14, ...) to # bash and blows up under `set -u`. docker compose's own --env-file parser # already treats these files as literal key=value data; this matches that. env_get() { local file="$1" key="$2" line val line="$(grep -m1 -E "^${key}=" "$file" 2>/dev/null || true)" val="${line#*=}" if [[ "$val" == \"*\" && "$val" == *\" ]]; then val="${val#\"}"; val="${val%\"}" elif [[ "$val" == \'*\' && "$val" == *\' ]]; then val="${val#\'}"; val="${val%\'}" fi printf '%s' "$val" }