/** * License-key resolution for the API-posting paths (govern, deploy, journey) * — CI_SERVICE_KEYS ruling D-4: `ES_LICENSE_KEY` wins when set. * * CI is exactly the environment where `license.json` is an accident: before * this, every governor workflow hand-wrote a keys-only file into the runner's * home directory (the shipped template did it too), which works only because * `loadLocal` tolerates a file with no expiry — and a revoked key surfaces as * a confusing 401 at post time. The env var IS the CI-native shape: secrets * already arrive as env, nothing touches disk, nothing impersonates an * activated workstation license. * * A set-but-malformed env var is a hard error, never a silent fallback — if * the file won after all, "env wins when set" would be false in exactly the * case where the operator is debugging their CI secret. */ export interface ResolvedLicenseKey { key: string; source: 'env' | 'local'; } export declare function resolveLicenseKey(env?: NodeJS.ProcessEnv): ResolvedLicenseKey | { error: string; } | null; //# sourceMappingURL=license-key.d.ts.map