# Copy to .env and fill in. Never commit .env. SQUIDC5_HOST=0.0.0.0 SQUIDC5_PORT=8443 SQUIDC5_DATA_DIR=data SQUIDC5_DEBUG=false # TLS: unique self-signed cert auto-generated under data/tls/ (ops, API, MCP) SQUIDC5_TLS_ENABLED=true # Optional overrides (both required if set): # SQUIDC5_TLS_CERT_FILE=/path/to/fullchain.pem # SQUIDC5_TLS_KEY_FILE=/path/to/privkey.pem # SQUIDC5_TLS_FORCE_NEW=false # Secure defaults # External MCP (/mcp/tools, /mcp/call). BOTH this env AND Admin feature mcp_enabled must be true. SQUIDC5_MCP_ENABLED=false SQUIDC5_AI_ENABLED=true SQUIDC5_EXPOSE_HEALTH_DETAILS=false SQUIDC5_SECURITY_HEADERS=true # CORS: leave unset/empty for same-origin only. Example if needed: # SQUIDC5_CORS_ORIGINS=["https://ops.example.mil"] # Public callback host/IP for stage-2 implants (lab/prod). Example: 203.0.113.10 SQUIDC5_PUBLIC_HOST= SQUIDC5_SHELL_AUTO_STABILIZE=false # Optional: set a known bootstrap admin token (otherwise auto-generated) # SQUIDC5_ADMIN_TOKEN_BOOTSTRAP=sc5_your_secure_token_here # Plugin HMAC signing secret (or auto-generated under data/plugin_signing.secret) # SQUIDC5_PLUGIN_SIGNING_SECRET= # At-rest encryption master key for LLM API keys (or data/secrets.key) # SQUIDC5_SECRETS_KEY= # JSON structured logs to stderr # SQUIDC5_LOG_JSON=true # Implant beacon AEAD (default: require auth; PSK auto under data/implant_psk.txt) # SQUIDC5_IMPLANT_REQUIRE_AUTH=true # SQUIDC5_IMPLANT_PSK= # Local Ollama-compatible LLM (opt-in when no cloud LLM rows configured) # SQUIDC5_LOCAL_LLM_ENABLED=true # SQUIDC5_LOCAL_LLM_BASE_URL=http://127.0.0.1:11434/v1 # SQUIDC5_LOCAL_LLM_MODEL=llama3.2