Files
Mr. The Plague 4d109c01ba fix(mcp): surface dual-gate status (settings + feature flag)
MCP needs SQUIDC5_MCP_ENABLED and feature mcp_enabled. Expose mcp.active
on meta/features/deep health; clearer 403 text; Ops Features warns when
feature is on but process env still blocks.
2026-08-03 21:47:58 -04:00

39 lines
1.6 KiB
Bash

# Copy to .env and fill in. Never commit .env.
SQUIDC5_HOST=0.0.0.0
SQUIDC5_PORT=8443
SQUIDC5_DATA_DIR=data
SQUIDC5_DEBUG=false
# TLS: unique self-signed cert auto-generated under data/tls/ (ops, API, MCP)
SQUIDC5_TLS_ENABLED=true
# Optional overrides (both required if set):
# SQUIDC5_TLS_CERT_FILE=/path/to/fullchain.pem
# SQUIDC5_TLS_KEY_FILE=/path/to/privkey.pem
# SQUIDC5_TLS_FORCE_NEW=false
# Secure defaults
# External MCP (/mcp/tools, /mcp/call). BOTH this env AND Admin feature mcp_enabled must be true.
SQUIDC5_MCP_ENABLED=false
SQUIDC5_AI_ENABLED=true
SQUIDC5_EXPOSE_HEALTH_DETAILS=false
SQUIDC5_SECURITY_HEADERS=true
# CORS: leave unset/empty for same-origin only. Example if needed:
# SQUIDC5_CORS_ORIGINS=["https://ops.example.mil"]
# Public callback host/IP for stage-2 implants (lab/prod). Example: 203.0.113.10
SQUIDC5_PUBLIC_HOST=
SQUIDC5_SHELL_AUTO_STABILIZE=false
# Optional: set a known bootstrap admin token (otherwise auto-generated)
# SQUIDC5_ADMIN_TOKEN_BOOTSTRAP=sc5_your_secure_token_here
# Plugin HMAC signing secret (or auto-generated under data/plugin_signing.secret)
# SQUIDC5_PLUGIN_SIGNING_SECRET=
# At-rest encryption master key for LLM API keys (or data/secrets.key)
# SQUIDC5_SECRETS_KEY=
# JSON structured logs to stderr
# SQUIDC5_LOG_JSON=true
# Implant beacon AEAD (default: require auth; PSK auto under data/implant_psk.txt)
# SQUIDC5_IMPLANT_REQUIRE_AUTH=true
# SQUIDC5_IMPLANT_PSK=
# Local Ollama-compatible LLM (opt-in when no cloud LLM rows configured)
# SQUIDC5_LOCAL_LLM_ENABLED=true
# SQUIDC5_LOCAL_LLM_BASE_URL=http://127.0.0.1:11434/v1
# SQUIDC5_LOCAL_LLM_MODEL=llama3.2