Files
SquidSec-SquidC5/.env.example
T
Mr. The Plague 8aaeffe1ba fix(plugins): require non-default signing secret
Resolve HMAC secret from env or data/plugin_signing.secret (generate
once, mode 0600). Refuse legacy hardcoded default outside debug.
2026-08-01 07:56:33 -04:00

26 lines
1.0 KiB
Bash

# Copy to .env and fill in. Never commit .env.
SQUIDC5_HOST=0.0.0.0
SQUIDC5_PORT=8443
SQUIDC5_DATA_DIR=data
SQUIDC5_DEBUG=false
# TLS: unique self-signed cert auto-generated under data/tls/ (ops, API, MCP)
SQUIDC5_TLS_ENABLED=true
# Optional overrides (both required if set):
# SQUIDC5_TLS_CERT_FILE=/path/to/fullchain.pem
# SQUIDC5_TLS_KEY_FILE=/path/to/privkey.pem
# SQUIDC5_TLS_FORCE_NEW=false
# Secure defaults
SQUIDC5_MCP_ENABLED=false
SQUIDC5_AI_ENABLED=true
SQUIDC5_EXPOSE_HEALTH_DETAILS=false
SQUIDC5_SECURITY_HEADERS=true
# CORS: leave unset/empty for same-origin only. Example if needed:
# SQUIDC5_CORS_ORIGINS=["https://ops.example.mil"]
# Public callback host/IP for stage-2 implants (lab/prod). Example: 203.0.113.10
SQUIDC5_PUBLIC_HOST=
SQUIDC5_SHELL_AUTO_STABILIZE=true
# Optional: set a known bootstrap admin token (otherwise auto-generated)
# SQUIDC5_ADMIN_TOKEN_BOOTSTRAP=sc5_your_secure_token_here
# Plugin HMAC signing secret (or auto-generated under data/plugin_signing.secret)
# SQUIDC5_PLUGIN_SIGNING_SECRET=