mirror of
https://github.com/SquidSec/SquidC5
synced 2026-08-09 12:22:26 +00:00
Resolve HMAC secret from env or data/plugin_signing.secret (generate once, mode 0600). Refuse legacy hardcoded default outside debug.
26 lines
1.0 KiB
Bash
26 lines
1.0 KiB
Bash
# Copy to .env and fill in. Never commit .env.
|
|
SQUIDC5_HOST=0.0.0.0
|
|
SQUIDC5_PORT=8443
|
|
SQUIDC5_DATA_DIR=data
|
|
SQUIDC5_DEBUG=false
|
|
# TLS: unique self-signed cert auto-generated under data/tls/ (ops, API, MCP)
|
|
SQUIDC5_TLS_ENABLED=true
|
|
# Optional overrides (both required if set):
|
|
# SQUIDC5_TLS_CERT_FILE=/path/to/fullchain.pem
|
|
# SQUIDC5_TLS_KEY_FILE=/path/to/privkey.pem
|
|
# SQUIDC5_TLS_FORCE_NEW=false
|
|
# Secure defaults
|
|
SQUIDC5_MCP_ENABLED=false
|
|
SQUIDC5_AI_ENABLED=true
|
|
SQUIDC5_EXPOSE_HEALTH_DETAILS=false
|
|
SQUIDC5_SECURITY_HEADERS=true
|
|
# CORS: leave unset/empty for same-origin only. Example if needed:
|
|
# SQUIDC5_CORS_ORIGINS=["https://ops.example.mil"]
|
|
# Public callback host/IP for stage-2 implants (lab/prod). Example: 203.0.113.10
|
|
SQUIDC5_PUBLIC_HOST=
|
|
SQUIDC5_SHELL_AUTO_STABILIZE=true
|
|
# Optional: set a known bootstrap admin token (otherwise auto-generated)
|
|
# SQUIDC5_ADMIN_TOKEN_BOOTSTRAP=sc5_your_secure_token_here
|
|
# Plugin HMAC signing secret (or auto-generated under data/plugin_signing.secret)
|
|
# SQUIDC5_PLUGIN_SIGNING_SECRET=
|