Documentation
¶
Overview ¶
Package config loads runtime configuration from the environment.
Index ¶
- type Config
- func (c Config) AssessmentCycleDualWriteForTenant(tenantID string) bool
- func (c Config) AssessmentLifecycleReadForTenant(tenantID string) bool
- func (c Config) AssessmentLifecycleUIForTenant(tenantID string) bool
- func (c Config) AssessmentShadowForTenant(tenantID string) bool
- func (c Config) AssessmentSnapshotCompletionForTenant(tenantID string) bool
- func (c Config) IsProduction() bool
- func (Config) JVMTier2PointsToEnabled() bool
- func (c Config) MigrationDSN() string
- func (c Config) ResolveScanCacheDir() string
- func (c Config) ResolveToolExecution(role ProcessRole) (ToolExecution, error)
- func (c Config) ValidateAssessmentLifecycleRollout() error
- func (c Config) ValidateCorrelationPosture() error
- func (c Config) ValidateEgressGrantPosture(role ProcessRole) error
- func (c Config) ValidateFleetTransportPosture() error
- func (c Config) ValidateMigrationPosture() error
- func (c Config) ValidateNetworkExecutionPosture(role ProcessRole) error
- func (c Config) ValidateOIDCPosture() error
- func (c Config) ValidateResponseExecutionPosture() error
- func (c Config) ValidateSandboxPosture() error
- func (c Config) ValidateSecretVerification() error
- func (c Config) ValidateVulnerabilityMaintenance() error
- func (c Config) ValidateVulnerabilitySchedulerOwnership() error
- func (c Config) ValidateWorkerConcurrency() error
- func (c Config) ValidateWorkerProfile() error
- func (c Config) ValidateWorkerSandboxPosture() error
- type ProcessRole
- type ToolExecution
- type WorkerProfile
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Config ¶
type Config struct {
HTTPAddr string
// MetricsEnabled turns on the Prometheus /metrics endpoint on a SEPARATE,
// uninstrumented, non-bearer-protected listener. Off by default.
MetricsEnabled bool
// MetricsAddr is the loopback-by-default listen address for the metrics endpoint.
MetricsAddr string
// AccessLogEnabled turns on the single structured access-log event per HTTP
// request (method, matched route, status, latency, request id). On by default.
AccessLogEnabled bool
Environment string
LogLevel string
SingleTenant bool
// APIToken protects all API + UI routes; required (no anonymous access).
APIToken string
// OIDCEnabled enables the browser-based OIDC authorization-code BFF flow.
OIDCEnabled bool
OIDCIssuer string
OIDCClientID string
OIDCClientSecret string
OIDCRedirectURL string
OIDCFrontendURL string
OIDCTenantID string
OIDCGroupRoleMapping []string
OIDCTransactionTTL time.Duration
OIDCSessionTTL time.Duration
// AUPVersion is the current Acceptable-Use Policy version.
AUPVersion string
// AUPFile is where first-run AUP acceptance is recorded (file-backed until Postgres).
AUPFile string
// AuditFile is the append-only audit log (file-backed until Postgres).
AuditFile string
// DBDSN, when set, enables PostgreSQL persistence; empty = in-memory (dev).
DBDSN string
// DBMigrationDSN, when set, is used only for schema migrations and runtime-role grants.
// It must be a DDL owner credential; DBDSN remains the least-privilege application credential.
DBMigrationDSN string
// DBHaltWriterDSN is the separate, narrowly privileged identity permitted to manufacture
// response halt fences and immutable halt dispatches.
DBHaltWriterDSN string
// DBAutoMigrate controls embedded migrations for long-running services. A dedicated
// synapse-migrate job may own migrations while services rely on readiness instead.
DBAutoMigrate bool
// AlpineSecdbURL is the base URL of the apk secdb mirror `sync-advisories --remote-secdb` ingests. It is
// configurable so an air-gapped estate can point it at an internal mirror of the same layout.
AlpineSecdbURL string
// SyftBin is the Syft executable used for SBOM generation (shell-out).
SyftBin string
// SBOMProducer selects the SBOM-generation producer: "ownsbom" (default – the detection-independent
// owned per-ecosystem parsers across 23 ecosystems, emitting dependency-graph edges, so a production
// deployment needs no third-party scanner binary) or "syft" (the pinned Syft binary, retained as an
// opt-in cross-check). The owned producer's ecosystem breadth and Syft edge parity are gated by the
// scabench oracle and the per-ecosystem parity tests (EPIC #1034, #1036); the default flip was gated on
// those passing (#1037). Set SYNAPSE_SBOM_PRODUCER=syft to roll back.
SBOMProducer string
// GrypeBin is the Grype executable for the second detection source;
// missing binary degrades gracefully to OSV-only.
GrypeBin string
// GrypeDBDir pins Grype's vulnerability DB to a pre-synced cache directory and
// disables auto-update (E7/CRA): offline + reproducible scans against a fixed DB
// build. Empty = Grype's default (online).
GrypeDBDir string
// DetectionSources selects and orders the scan-time vulnerability detection sources as a comma
// list from {grype, osv, advisory-store}. Empty selects the owned-only default: live OSV (unless
// SYNAPSE_OFFLINE) then the owned advisory-store (when SYNAPSE_OWNED_ADVISORY, the default), with Grype
// dropped to an opt-in cross-check. Dropping Grype does not silently lower OS-package recall: the SCA
// pipeline's OS-distro coverage guard marks a scan not-confident when an OS-package's distro is not
// covered by the owned advisory store and Grype is absent. When set this var is authoritative, so an
// operator restores Grype with "osv,grype,advisory-store". Unknown names fail closed.
DetectionSources string
// StrictSources, when true, restores fail-closed detection: any source error aborts the scan.
// Default false: a source that errors (a transient OSV.dev outage, an advisory-store read blip)
// is skipped with a SourceWarning and the scan continues on the remaining sources, matching how
// Grype already self-degrades to a no-op when its binary/DB is absent.
StrictSources bool
// OSVBaseURL overrides the OSV.dev API base (mainly for tests); empty = OSV.dev.
OSVBaseURL string
// OSVBulkURL overrides the OSV bulk-data bucket base for the owned-advisory ingester;
// empty = the public OSV bucket. Mainly for tests/mirrors.
OSVBulkURL string
// DepsDevURL overrides the deps.dev API base for license enrichment (tests).
DepsDevURL string
// KEVURL / EPSSURL override the CISA KEV feed + FIRST EPSS API (tests); empty = defaults.
KEVURL string
EPSSURL string
// NVDAPIURL overrides the NVD CVE API base for severity backfill (tests/mirrors); empty =
// the public NVD API. NVDAPIKey is the optional NVD API key (raises the rate limit so more
// unknown-severity CVEs are backfilled per scan); NEVER logged. NVDBudget
// caps the per-scan time the backfill may spend (best-effort); raise it (with a key) to
// resolve more of a large unknown set.
NVDAPIURL string
NVDAPIKey string
NVDBudget time.Duration
// ScanTimeout bounds a single SCA scan; 0 disables.
ScanTimeout time.Duration
// ProjectAnalysisCompletionTimeout bounds immutable Project snapshot persistence
// after a scan completes. It must remain positive even when scan timeout is disabled.
ProjectAnalysisCompletionTimeout time.Duration
// FindingMinSeverity is the lowest vuln severity promoted to a finding.
FindingMinSeverity string
// IgnoreUnfixed, when true, does NOT promote vulnerabilities that have no available fix
// (FixedVersion empty – not-fixed / wont-fix / deferred) to findings, matching Trivy's
// --ignore-unfixed. Default false (show everything); they remain in the vuln inventory.
IgnoreUnfixed bool
// Offline, when true, forbids network egress for a scan. It omits detection sources that require it
// (the live OSV.dev source), running only offline sources – the owned advisory store, plus Grype's
// pre-synced DB when SYNAPSE_DETECTION_SOURCES names it (scacompose.resolveDetectionSourceNames owns
// the selection and never adds Grype by default) – AND switches off every registry resolver (npm, composer, poetry, Bundler, Maven,
// Gradle), the Maven Central JAR SHA-1 lookup, the KEV/EPSS and online NVD enrichers, the deps.dev
// and PyPI license metadata, and AI triage. Trades some recall for an air-gapped scan (no HTTP at
// all). Default false.
Offline bool
// MaxWorkspaceBytes caps the total size of a prepared SCA workspace: the
// acquirer rejects a target whose files exceed it. <=0 keeps the 2 GiB default.
MaxWorkspaceBytes int64
// ProjectUploadDir retains uploaded Project source archives for repeat analysis.
ProjectUploadDir string
// EngagementSourceDir is the durable operator-owned upload object root used
// when MinIO/S3 is not configured. API and workers must share the same root.
EngagementSourceDir string
// ProjectSourceArtifactDir retains immutable, analysis-owned Code source snapshots.
// It must be operator-owned; source contents are never fetched again at read time.
ProjectSourceArtifactDir string
ProjectSourceRetention time.Duration
ProjectAnalysisShortLivedKeep int
ProjectSourceMaxFileBytes int64
ProjectSourceMaxFiles int
ProjectSourceMaxBytes int64
// SASTSourceBudgetBytes is the source the pattern SAST analyzer retains for cross-file context. The
// default bounds memory on an untrusted tree and never binds on an ordinary repository; it DOES bind on a
// monorepo, where the unretained part of the tree is scanned by no rule at all. 0 keeps the built-in
// default.
SASTSourceBudgetBytes int64
// ProjectGitComparisonDepth bounds history fetched to resolve an immutable
// Code comparison base; comparison degrades gracefully when insufficient.
ProjectGitComparisonDepth int
// Evidence artifact blob store: when BlobEndpoint is set, artifacts go to
// MinIO/S3; empty = in-memory (dev). Bucket defaults to synapse-evidence.
BlobEndpoint string
BlobAccessKey string
BlobSecretKey string
BlobBucket string
BlobUseSSL bool
// Recon: bounds for the argv ToolRunner + worker pool. Timeout
// kills a run; MaxOutput caps captured stdout/stderr; Concurrency/QueueSize size
// the bounded pool that replaces the P1 bare goroutine.
ReconTimeout time.Duration
ReconMaxOutput int
ReconConcurrency int
ReconQueueSize int
// ReconAllowCapabilitySensitive permits capability-sensitive tools (naabu – raw
// sockets) to run. Default false: they stay behind the sandbox.
ReconAllowCapabilitySensitive bool
// EvidenceSigningSeed is the ed25519 seed (64 hex chars or base64 of 32 bytes)
// used to attest evidence chain heads (non-repudiation). Empty = an ephemeral
// key is generated per start (attestations still self-verify, but the key id is not
// stable across restarts). Never logged.
EvidenceSigningSeed string
// TSAURL is an RFC-3161 timestamp authority. When set, verified evidence +
// audit chain heads are externally anchored (tamper-PROOF), out-of-band so report
// bytes are unchanged. Empty = signed-but-not-externally-anchored (tamper-evident).
TSAURL string
// SandboxEnabled selects the bubblewrap SandboxRunner for tool execution. When
// true on a host without bubblewrap, startup FAILS CLOSED (never silently runs
// unsandboxed). Default false. NOTE: the sandbox is egress default-deny until the
// scope-derived allowlist lands, so network recon tools won't reach targets
// until then. SandboxMemMax/PidsMax are the per-run cgroup limits (via systemd-run).
SandboxEnabled bool
SandboxMemMax int64
SandboxPidsMax int
// ToolHashes are operator-supplied authoritative sha256 pins for tool binaries,
// format "name=hex,/abs/path=hex,…". When set, the SandboxRunner refuses to execute a
// binary whose hash does not match its pin – closing the initial-supply-chain gap that
// trust-on-first-use alone cannot (TOFU only detects post-first-run replacement). Empty
// = TOFU only. Parsed from SYNAPSE_TOOL_HASHES.
ToolHashes map[string]string
// DAST authenticated scan execution ceilings. Per-run values may only lower these.
DASTHelperBin string
DASTMaxReauth int
DASTRatePerSec int
DASTConcurrency int
DASTMaxDepth int
DASTMaxPages int
DASTMaxRequests int
DASTMaxWallClock time.Duration
// VaultMasterKey is the AES-256 master key for the credential vault: 64 hex
// chars or base64 of 32 bytes. Empty = an ephemeral key (dev only; stored secrets do
// not survive restart). Required in production. Never logged.
VaultMasterKey string
// NotificationEnabled enables tenant-managed durable notification delivery.
// It requires PostgreSQL and a stable VaultMasterKey shared by API and worker.
NotificationEnabled bool
OwnershipMode string // off (default), observe, enforce; PostgreSQL only
NotificationSMTPHost string
NotificationSMTPPort int
NotificationSMTPFrom string
NotificationSMTPUsername string
NotificationSMTPPassword string
NotificationSMTPRequireTLS bool
// ReconViaWorker routes recon runs through the durable queue: the API enqueues
// and the non-root synapse-worker claims and executes them. Scoped egress is
// configured by a separate root-owned broker. Requires Postgres. Default false
// = the API runs recon in-process (dev).
ReconViaWorker bool
// EgressBrokerSocket is the root-owned scoped-egress broker Unix socket. The
// non-root worker is only a protocol client and receives no network-admin capabilities.
EgressBrokerSocket string
// EgressGrantAuthorityAddr is the private control-plane listener used only for
// machine-authenticated egress grant issuance. It is separate from human API/AUP auth.
EgressGrantAuthorityAddr string
// EgressGrantAuthorityURL and EgressGrantAuthorityToken configure the worker's
// machine-only grant client. The token must not reuse the human bootstrap API token.
EgressGrantAuthorityURL string
EgressGrantAuthorityToken string
// EgressGrantIssuerToken authenticates workers to the private issuer listener.
// EgressGrantSigningSeed is a dedicated Ed25519 seed and must not reuse evidence signing.
EgressGrantIssuerToken string
EgressGrantSigningSeed string
// ToolExecutionMode is the explicit process execution posture. Empty selects a
// role- and environment-safe default in ResolveToolExecution.
ToolExecutionMode string
// AgentEnabled turns on the AI orchestrator. Default false (fail-safe): no
// LLM is contacted and no agent endpoints are active unless explicitly enabled.
AgentEnabled bool
// LLM provider: OpenAI-compatible Chat Completions. BaseURL defaults to
// the LLM gateway; APIKey is a Bearer token (NEVER logged);
// Model is the provider model id. Empty BaseURL + AgentEnabled fails closed at wiring.
LLMBaseURL string
LLMAPIKey string
LLMModel string
// LLMProvider is an explicit audit identity, not a value inferred from the URL. A gateway may
// route several providers and distinct URLs may still address the same provider.
LLMProvider string
LLMTimeout time.Duration
// FPTriageEnabled turns on opt-in LLM false-positive analysis. A proposer may mark a finding
// suspected-FP, but it remains advisory unless a distinct verifier agrees and the deterministic
// human-review floor permits a gate exemption. High/critical, secrets, and dangerous CWEs always gate.
// Off by default; needs an LLM.
// FPTriageModel is the model to critique with (defaults to LLMModel).
FPTriageEnabled bool
FPTriageModel string
// FPTriageProvider defaults to LLMProvider but may identify a provider routed specifically for
// the triage proposer model.
FPTriageProvider string
// FPTriageMode is shadow|enforce. Shadow is the fail-closed default: decisions are persisted for
// evaluation but can never set gate_exempt. Enforce requires a deliberate operator choice.
FPTriageMode string
FPTriageMaxFindings int
FPTriageConcurrency int
FPTriageMaxTokens int64
FPTriageMaxCostMicroUSD int64
FPTriageProposerInputRate int64
FPTriageProposerOutputRate int64
FPTriageVerifierInputRate int64
FPTriageVerifierOutputRate int64
FPTriageCircuitFailures int
FPTriageCircuitCooldown time.Duration
FPTriageAlertMinSamples int
FPTriageDisagreeBaseBPS int
FPTriageExemptBaseBPS int
FPTriageParseFailBaseBPS int
FPTriageAlertDeltaBPS int
// FPTriageIndependence is model_family (default) or provider. Provider mode additionally
// requires a different explicit provider identity; invalid values disable verifier authority.
FPTriageIndependence string
// Agent orchestration policy. ApprovalMode: manual|filter|auto (manual is
// the safe default – a human approves every action). The rest bound a run.
AgentApprovalMode string
AgentApprovalTimeout time.Duration
AgentMaxSteps int
AgentTokenBudget int
AgentMaxDuration time.Duration
// Agent runtime/ops. DB pool sizing (the durable agent path
// holds a connection-bearing advisory lock per active run, so the pool must be sized).
DBMaxConns int
DBMinConns int
DBMaxConnLifetime time.Duration
DBMaxConnIdleTime time.Duration
// AgentViaWorker routes agent runs to synapse-worker durably (requires ReconViaWorker +
// Postgres); else the API runs them inline-bounded. Concurrency/QueueDepth bound admission
// (backpressure → 503). ApprovalSweepInterval drives the prod timeout sweeper. MaxParallel
// caps in-flight plan nodes (P5). ReconConcurrency sizes the agent's dedicated recon pool.
// PromotionReconcileInterval schedules server-only recovery of confirmed promotions and audits.
// FleetDetectionReconcileInterval schedules tenant-scoped repair of pending attributed detections.
AgentViaWorker bool
AgentConcurrency int
AgentQueueDepth int
AgentMaxParallel int
AgentReconConcurrency int
ApprovalSweepInterval time.Duration
PromotionReconcileInterval time.Duration
FleetDetectionReconcileInterval time.Duration
// JudgmentsEnabled turns on the AI judgment lifecycle HTTP routes; on by default.
JudgmentsEnabled bool
// FleetAssetsEnabled turns on the multi-tenant fleet asset model (assets, edges, business
// services) and its HTTP routes; off by default. When on with Postgres, startup refuses to
// serve unless the DB role can enforce Row Level Security (not SUPERUSER/BYPASSRLS).
FleetAssetsEnabled bool
// CSPM enables read-only live cloud posture connectors. Providers is an allowlist;
// Rate is requests per second, with zero selecting provider defaults.
CSPMEnabled bool
CSPMProviders []string
CSPMRate int
CSPMEgressHosts []string
CSPMHelperBin string
// Attack-path traversal is bounded by length, retained paths per target, and wall clock.
AttackPathMaxLen int
AttackPathMaxPaths int
AttackPathWallClock time.Duration
// FleetEnabled turns on the agent-facing transport (#409: enrol/heartbeat/work) plus the
// operator agent-admin routes; off by default. When on with Postgres, startup fails closed
// unless the DB role can enforce RLS.
FleetEnabled bool
// FleetClusterIngestEnabled turns on the cluster-inventory ingest endpoint (#446), where an agent
// POSTs a Kubernetes snapshot that is persisted into the asset model. Off by default. It requires
// both FleetEnabled (transport) and FleetAssetsEnabled (persistence); it is a no-op otherwise.
FleetClusterIngestEnabled bool
// FleetHostIngestEnabled turns on the host-inventory ingest endpoint (#446), where a VM agent POSTs
// its collected host inventory (facts + packages + coverage) to be persisted as a Kind=host asset.
// Off by default; requires FleetEnabled + FleetAssetsEnabled.
FleetHostIngestEnabled bool
// FleetTelemetryIngestEnabled turns on the agent→control-plane telemetry batch ingest endpoint
// (A3, #624): an enrolled agent ships a signed TelemetryBatchManifest which the control plane verifies
// (identity + signing key + schema, fail-closed), sequences idempotently, and acks. Off by default;
// requires FleetEnabled.
FleetTelemetryIngestEnabled bool
// FleetDetectionIngestEnabled turns on the agent→control-plane detection batch ingest endpoint (A4,
// #625): an enrolled agent ships a signed AgentBatch which the control plane verifies (identity +
// signing key + per-detection content digest, fail-closed) and seals once into the evidence chain.
// Off by default; requires FleetEnabled.
FleetDetectionIngestEnabled bool
// FleetKeyRegistrationEnabled turns on the agent-plane signing-key registration endpoint plus the
// operator key management routes (A4, #625, A0.2): an agent registers its Ed25519 signing key with a
// proof-of-possession. Off by default; requires FleetEnabled.
FleetKeyRegistrationEnabled bool
// FleetAgentStaleAfter is how long since an agent's last heartbeat before it is reported stale in
// the coverage/agent-health views (#413, SYNAPSE_FLEET_STALE_AFTER). <=0 disables the staleness
// check. Default 10m, per the issue spec.
FleetAgentStaleAfter time.Duration
// FleetCoverageFreshnessTarget is the default per-capability freshness target (#413): an assessment
// older than this is reported stale, not covered. <=0 means no freshness requirement. Default 24h.
FleetCoverageFreshnessTarget time.Duration
// FleetMinAgentVersion is the minimum supported agent version (#412 version skew). An agent whose
// reported version is below it is refused work with an instruction to update. Empty = no floor. A
// malformed value is treated as no floor (a config typo must not brick the fleet). Parsed loosely
// as major.minor.patch (see domain/fleetversion).
FleetMinAgentVersion string
// FleetSignerKey is the HMAC key that signs agent work orders. Required and at least 32 bytes
// when FleetEnabled; a missing/short key fails startup closed rather than boot a forgeable signer.
FleetSignerKey string
// ResponseExecutionEnabled replaces the simulation executor with the signed fleet response lane.
// It requires fleet identity, telemetry, and key registration so execution fails closed.
ResponseExecutionEnabled bool
ResponseCommandSigningKeyFile string
ResponseCommandTTL time.Duration
ResponseExecutionPollInterval time.Duration
// FleetCACertPEM / FleetCAKeyPEM are the control-plane CA that issues agent client certificates
// (#408). When both are set and FleetEnabled, enrolment with a CSR returns a client certificate.
FleetCACertPEM string
FleetCAKeyPEM string
// FleetCertTTL is the issued client certificate lifetime (default 720h).
FleetCertTTL time.Duration
// FleetClientCertHeader, when set, is the header a trusted mutual-TLS-terminating proxy uses to
// pass the verified client certificate to the agent plane. Empty = certificate auth disabled
// (bearer token only). Trust it ONLY behind a proxy that strips any client-supplied value.
FleetClientCertHeader string
// FleetClientCertHost and FleetEnrollmentHost isolate mTLS agent traffic from the one-time
// bearer enrollment exchange. Both are mandatory and distinct for production fleet transport.
FleetClientCertHost string
FleetEnrollmentHost string
// LeaderElectionEnabled runs the fenced-lease leader elector (#406). Off by default. Postgres
// only (a single in-memory process is trivially the leader). Renewing < Term/2 is enforced.
LeaderElectionEnabled bool
// LeaderResource is the lease key elected over (default "scheduler").
LeaderResource string
// LeaderTerm is the lease term; LeaderRenew is the renewal interval (must be < Term/2).
LeaderTerm time.Duration
LeaderRenew time.Duration
// WorkerConcurrency is the number of durable-queue claim loops in one synapse-worker process.
WorkerConcurrency int
// WorkerProfile narrows synapse-worker composition and queue claims. "all" keeps the
// hardened scanner worker; "integrations" runs only provider polling jobs and needs no
// executable-tool sandbox.
WorkerProfile WorkerProfile
// VulnerabilitySchedulerEnabled dispatches due vulnerability-source syncs and recovers stale
// runs. Postgres deployments must also enable fenced leader election to prevent duplicate work.
VulnerabilitySchedulerEnabled bool
VulnerabilitySchedulerPollInterval time.Duration
VulnerabilitySchedulerStaleAfter time.Duration
VulnerabilitySchedulerJitter int
VulnerabilitySchedulerDispatch int
VulnerabilitySchedulerQueueDepth int
VulnerabilitySchedulerRecovery int
// IntegrationSchedulerEnabled dispatches polling operations for enabled external CI/CD
// integrations. The maintenance task is leader-gated by synapse-worker.
IntegrationSchedulerEnabled bool
IntegrationSchedulerInterval time.Duration
IntegrationSchedulerDispatch int
IntegrationSchedulerQueueDepth int
// AccuracyEvalInterval is how often the leader worker runs the detection-accuracy regression over
// the golden corpus and persists a run for the console trend (EPIC #860 D8.6). Zero disables it.
AccuracyEvalInterval time.Duration
// IntegrationAllowPrivateNetwork is an operator-controlled exception that permits
// tenant administrators to configure integrations targeting private address space.
// It is intentionally off by default because the API flag alone must not weaken SSRF controls.
IntegrationAllowPrivateNetwork bool
// Vulnerability rollout gates default off. Tenant-scoped mutations additionally require
// an explicit tenant allowlist entry; "*" enables all tenants. Dry-run records correlation
// differences without mutating occurrences, findings, actions, or notification outbox rows.
VulnerabilityProviderSyncEnabled bool
// VulnerabilityInlineWorkerEnabled lets synapse-api consume only vulnerability sync and reconciliation
// jobs when PostgreSQL is configured. It is an explicit local/single-process topology option; the default
// remains a separately deployed worker. Unlike scan workers, these handlers execute no target code and do
// not require the external-tool sandbox.
VulnerabilityInlineWorkerEnabled bool
// VulnerabilitySyncSchedulerInterval turns on the leader-gated cadence-driven sync scheduler when set
// above zero: every interval a single worker enqueues each enabled source whose last successful sync is
// older than its Cadence, and reclaims runs stranded past VulnerabilitySyncStaleAfter. Zero (the default)
// leaves syncing manual, so the corpus is only as fresh as the last explicit trigger. It has no effect
// unless SYNAPSE_VULNERABILITY_PROVIDER_SYNC_ENABLED is on.
VulnerabilitySyncSchedulerInterval time.Duration
VulnerabilitySyncStaleAfter time.Duration
VulnerabilitySyncSchedulerDispatch int
// VulnerabilitySourceAllowPrivateNetwork lets a vulnerability source reach RFC1918
// addresses. Off by default: a source is a URL the control plane fetches on a schedule,
// so private-range egress turns whoever can write a source into a probe of the
// operator's own network.
VulnerabilitySourceAllowPrivateNetwork bool
VulnerabilityOccurrenceWritesEnabled bool
VulnerabilityFindingProjectionEnabled bool
VulnerabilityActionsEnabled bool
VulnerabilityNotificationsEnabled bool
VulnerabilityDryRunEnabled bool
VulnerabilityTenantAllowlist []string
// Vulnerability maintenance is disabled until an interval is configured.
// Even then it remains audit-only unless DeleteEnabled is explicitly set.
VulnerabilityMaintenanceInterval time.Duration
VulnerabilityMaintenanceDeleteEnabled bool
VulnerabilityRawPayloadRetention time.Duration
VulnerabilitySyncRunRetention time.Duration
VulnerabilityResolvedOccurrenceRetention time.Duration
VulnerabilityUnreferencedAdvisoryRetention time.Duration
VulnerabilityMaintenanceBatchSize int
// SLAEnabled turns on durable risk-based remediation deadlines, versioned tenant policy, and
// human lifecycle APIs. Default false until an operator explicitly opts into the new schema/path.
SLAEnabled bool
// Assessment lifecycle gates default off and use explicit tenant allowlists for staged rollout.
AssessmentCycleAPIEnabled bool
AssessmentCycleDualWriteEnabled bool
AssessmentCycleDualWriteTenants []string
AssessmentSnapshotEnabled bool
AssessmentSnapshotCompletionEnabled bool
AssessmentSnapshotCompletionTenants []string
AssessmentShadowEnabled bool
AssessmentShadowTenants []string
AssessmentLifecycleReadEnabled bool
AssessmentLifecycleReadTenants []string
AssessmentLifecycleUIDefault bool
AssessmentLifecycleUITenants []string
AssessmentClosureEnabled bool
AssessmentBatchSize int
AssessmentTenantJobs int
AssessmentBacklogWarning int
AssessmentBacklogHardLimit int
// SASTEnabled turns on the deterministic pattern-SAST analyzer in the scan pipeline; off by default.
SASTEnabled bool
// SecretScanEnabled turns on the deterministic secret scanner in the scan pipeline; off by default.
// It reads workspace files and redacts every match, so nothing sensitive reaches logs or the report.
SecretScanEnabled bool
// SecretHistoryEnabled additionally scans the git history (every blob reachable from all refs) for a
// secret committed and later removed, which the working-tree scan cannot see. Off by default: it is
// heavier and reports credentials no longer in the tree. Requires the workspace to be a git repository;
// otherwise it is a best-effort no-op with a warning. Redacts every match like the working-tree scan.
SecretHistoryEnabled bool
// SecretVerifyEnabled turns on OPT-IN active secret verification (D6.3): for a detected credential whose
// provider is supported (GitHub, GitLab, OpenAI, configured Vault, or an unambiguously paired AWS
// credential set), the scanner makes ONE minimal read-only API call to confirm it is live and stamps the
// finding verified/unverified.
// OFF by default and SECURITY-SENSITIVE: it sends the raw leaked secret to its issuing provider over the
// network (SSRF-hardened client, rate-limited, secret never logged). Enable only for an authorized
// assessment. A verified credential is raised above needs-verify; an unverified/unknown verdict never
// suppresses a finding.
SecretVerifyEnabled bool
// SecretVerifyRPS caps the verifier's outbound provider requests per second (default 5). Only meaningful
// when SecretVerifyEnabled is true.
SecretVerifyRPS int
// SecretVerifyVaultAddr is the optional absolute HTTPS base address used to verify Vault tokens. It may
// resolve to private network space, but loopback/link-local/special ranges remain blocked. Empty disables
// Vault verification while leaving the public providers available.
SecretVerifyVaultAddr string
// MisconfigEnabled turns on the deterministic IaC/config misconfig scanner (Dockerfile, Kubernetes
// manifests) in the scan pipeline; off by default. Read-only, first-party checks, no policy engine.
MisconfigEnabled bool
// SuppressionEnabled turns on the repo-committed .synapseignore accepted-risk policy; off by default.
// Suppressed findings are always retained + surfaced in the result, never silently dropped.
SuppressionEnabled bool
// VEXEnabled turns on consuming an in-repo OpenVEX doc (.synapse.vex.json) at scan time; off by default.
// A not_affected/fixed statement gate-exempts the matched finding (still reported + sealed), never removes it.
VEXEnabled bool
// ComplianceEnabled attaches the owned AppSec-baseline benchmark (per-control PASS/FAIL over the scan's
// findings, LLM-free) to each scan result; off by default.
ComplianceEnabled bool
// DetectionPriority is the default vulnerability detection priority: "comprehensive" (default; every
// detected vuln is actionable) or "precise" (single-source, non-KEV vulns are quarantined into a
// needs-verify queue – reported + sealed, exempt from the --fail-on gate). Empty = comprehensive.
DetectionPriority string
// DBMaxAgeDays warns (non-fatal, SourceWarning) when a dated reference DB (CISA KEV / EPSS catalog, or a
// pinned vuln DB) is older than this many days – so a scan on stale advisory data can't silently
// under-report (Trivy uses a stale DB silently). 0 disables the check.
DBMaxAgeDays int
// ScanCacheEnabled turns on the content-addressed generated-SBOM and AI-triage caches. An SBOM hit
// skips cataloging; an AI hit reuses only typed claims and still reapplies policy + seals new evidence.
ScanCacheEnabled bool
// ScanCacheDir is where cached scan artifacts live when ScanCacheEnabled. Empty preserves the existing
// "synapse-sbom" per-user default; AI claims use its own owner-only subdirectory. It MUST be
// operator-owned and not writable by untrusted users: cache poisoning could create a false negative.
ScanCacheDir string
// ImageRootFSEnabled materializes a container image's assembled root filesystem from the pulled OCI
// layout (applying layers + whiteouts), so the owned parsers can read on-disk OS-package DBs and
// /etc/os-release. ON by default; extraction is hardened but adds disk + time to an image scan. The owned
// SBOM producer (the default) can only catalog an image target through this materialized rootfs, so
// turning it off darkens image scans under the owned producer (a startup warning names the combination).
ImageRootFSEnabled bool
// OwnedAdvisoryEnabled wires the owned advisory DetectionSource: match the SBOM
// against the owned normalized-advisory store (offline, reproducible). ON by default (it is the default
// primary vulnerability source, with live OSV as online enrichment and Grype an opt-in cross-check). An
// empty store yields no findings (a harmless no-op) until the advisory ingester populates it; the
// OS-distro coverage guard flags an OS package whose distro the store does not cover, so an unsynced
// distro feed is a surfaced not-confident gap rather than a silent clean posture.
OwnedAdvisoryEnabled bool
// SymbolOverlayDir points at a directory of curated advisory-id -> affected-symbol JSON files. The owned
// advisory matcher merges these symbols onto findings so advisories whose feed carries none (non-Go,
// NVD/CSAF-only) can still drive symbol-level reachability. Empty (default) disables it; a load error is
// a warning, never a scan failure.
SymbolOverlayDir string
// ReachabilityEnabled turns on deterministic Tier-2 call-graph reachability proof: post-scan,
// it proves which findings' affected symbols are actually called and mints Tier-2 judgments that
// supersede weaker LLM claims. Off by default; opt-in + best-effort (a no-coverage/un-buildable target
// leaves the prior tier standing). GovulncheckBin is the pinned builder binary.
ReachabilityEnabled bool
GovulncheckBin string
// ReachabilityBuilder selects the Go Tier-2 call-graph producer: "owned" (default) runs Synapse's own
// go/ssa builder through the sandboxed synapse-callgraph binary (TaintCallgraphBin); "govulncheck" runs
// the third-party govulncheck (GovulncheckBin). The owned CHA graph over-approximates the call set, which
// is sound for reachability (it never reports a genuinely-reachable symbol as not-reachable), so it is the
// default and drops the last third-party engine from the default scan.
ReachabilityBuilder string
// PyReachabilityEnabled turns on deterministic Tier-1 Python import-reachability: post-scan, it mints a
// not_reachable judgment for a declared PyPI package that first-party code never imports (a dead
// dependency) → an OpenVEX not_affected justification. Weaker than the Go Tier-2 call-graph proof
// (import-level, not a reached call path). Off by default; opt-in + best-effort (a non-Python /
// dynamic-import / no-coverage target leaves the prior tier standing, never a false "not reachable").
// Also requires the judgment lifecycle (SYNAPSE_JUDGMENTS_ENABLED).
PyReachabilityEnabled bool
// PySemanticReachabilityEnabled turns on the Tier-2 Python affected-symbol call graph. It requires
// Tier-1 Python reachability so any semantic refusal has a weaker judgment to leave standing.
// ASTBin is the sandboxable synapse-ast sidecar; empty enables bundled/PATH discovery.
PySemanticReachabilityEnabled bool
ASTBin string
// PythonTaintEnabled turns on source-only Python semantic value-flow analysis. The same synapse-ast
// sidecar extracts bounded facts, but unlike Go taint this pass never compiles or imports target code.
// Positive paths become gated CapSAST proposals; incomplete coverage never produces a clean verdict.
PythonTaintEnabled bool
// TaintRulesFile is an optional operator-provided YAML file of CUSTOM Python and JavaScript taint rules
// (Semgrep-style user sources and sinks, under `python.*` and `js.*`) merged additively into the built-in
// catalogs at startup. Empty (the default) uses only the built-in catalogs. Custom rules can only ADD
// detection, never suppress a built-in flow.
TaintRulesFile string
// JsTaintEnabled turns on source-only JavaScript/TypeScript semantic value-flow analysis. Like Python
// taint it uses the synapse-ast sidecar to extract bounded facts and never compiles or executes target
// code. OFF by default while the catalog breadth grows; positive paths become gated CapSAST proposals and
// incomplete coverage never produces a clean verdict.
JsTaintEnabled bool
// JavaTaintEnabled turns on source-only Java semantic value-flow analysis (Spring/Servlet/JDBC). Like the
// JS/Python engines it uses the synapse-ast sidecar to extract bounded facts and never compiles or
// executes target code. OFF by default while the catalog breadth grows; positive paths become gated
// CapSAST proposals and incomplete coverage never produces a clean verdict.
JavaTaintEnabled bool
// TriScoreReassessEnabled turns on the tri-score risk reassessment surface (#594 C3/D/X5): an operator
// route that re-scores an incident's RiskAssessment from its factors (Threat now; Exposure/Behavior/
// Coverage as their producers are wired) via the deterministic Scorer. Off by default while the
// Exposure/Behavior/Coverage producers are still being integrated.
TriScoreReassessEnabled bool
// FleetCorrelationEnabled turns on the correlation orchestration (#594 C2/C3): an operator route that
// folds an engagement's sealed detections into incidents and (when tri-score is enabled) auto-scores
// each. Off by default.
FleetCorrelationEnabled bool
// FleetCorrelationWindow is the session gap for correlation: detections on one (asset, host) more than
// this apart start a new incident.
FleetCorrelationWindow time.Duration
// FleetCorrelationAllowedLateness controls how far the event-time watermark trails the newest detection.
FleetCorrelationAllowedLateness time.Duration
// FleetCorrelationMaxPerIncident caps how many detections one incident reflects individually before a
// storm is suppressed to a single note.
FleetCorrelationMaxPerIncident int
FleetCorrelationPageSize int
FleetCorrelationMaxActiveSessions int
FleetCorrelationMaxTimelineRefsPerDetection int
FleetCorrelationMaxTimelineRefsPerPage int
// AlertWebhookURL, when set, enables operator alerting: every incident correlation opens (and any
// other alert-producing event) is posted as signed JSON to this URL. Empty disables alerting.
AlertWebhookURL string
// AlertWebhookSecret signs each webhook body (HMAC-SHA256 over "<timestamp>.<body>", header
// X-Synapse-Signature). Optional; at least 16 bytes when set.
AlertWebhookSecret string
// AlertMinSeverity is the inclusive severity floor an alert must reach to be delivered.
AlertMinSeverity string
// AlertWebhookAllowPrivate lets the webhook client dial private and link-local addresses (an
// in-network receiver). Off by default; the SSRF guard otherwise refuses them.
AlertWebhookAllowPrivate bool
// AlertWebhookAllowUnsigned opts into UNSIGNED alert delivery when no secret is set. Default false:
// a configured webhook requires a signing secret so a receiver can trust the alert is genuine.
AlertWebhookAllowUnsigned bool
// JSReachabilityEnabled turns on deterministic Tier-1 JavaScript/TypeScript import-reachability: a
// declared npm dependency that first-party source never imports becomes not_reachable, which the
// export path turns into an OpenVEX not_affected justification. Source-only (nothing is executed or
// installed), best-effort and opt-in, and it answers only for DIRECT dependencies because a
// first-party import graph cannot prove a transitive package unused. Also requires the judgment
// lifecycle (SYNAPSE_JUDGMENTS_ENABLED).
JSReachabilityEnabled bool
// JSSymbolReachabilityEnabled turns on the TIER-2 JavaScript/TypeScript pass: not "is this package
// imported" but "is the affected EXPORT reached". It is a strictly stronger and strictly more
// dangerous claim — a wrong negative suppresses a real vulnerability — so it is separately gated and
// refuses to answer whenever a binding escapes observation.
JSSymbolReachabilityEnabled bool
// JSInterprocSuppressionEnabled turns on the SUPPRESSING direction of the interprocedural JavaScript
// Tier-2 call graph (#1139): a proven-unreached affected npm export becomes not_reachable, which the
// export path turns into an OpenVEX not_affected. The interprocedural recorder is otherwise raise-only
// (it only ever adds a reachable verdict, #1058). Suppression is sound-gated: the analyzer emits a
// negative only on a COMPLETE resolver graph (any dynamic construct or escaping callable taints every
// negative), and the coordinator refuses a Tier-2 not_reachable with no entry points. Off by default,
// so the shipped behavior stays raise-only; a wrong negative would hide a real vulnerability.
JSInterprocSuppressionEnabled bool
// RustReachabilityEnabled, PHPReachabilityEnabled and RubyReachabilityEnabled turn on deterministic
// Tier-1 import-reachability for those ecosystems: a declared dependency that first-party source
// never references becomes not_reachable, which the export path turns into an OpenVEX not_affected
// justification. All are source-only (nothing is executed, installed or resolved over the network),
// best-effort and opt-in, and each refuses a verdict whenever a dynamic construct could hide a
// reference. All require the judgment lifecycle (SYNAPSE_JUDGMENTS_ENABLED).
RustReachabilityEnabled bool
PHPReachabilityEnabled bool
RubyReachabilityEnabled bool
DotNetReachabilityEnabled bool
// CppReachabilityEnabled turns on the source-only, RAISE-ONLY C/C++ (conan) affected-symbol reachability:
// first-party source that references a curated vulnerable function raises the finding's urgency. It never
// mints not_reachable (macros, function pointers, dlopen, LTO/inlining and mangling hide calls), so it can
// only ever raise, never suppress.
CppReachabilityEnabled bool
// GoBinaryReachabilityEnabled turns on RAISE-ONLY Go-binary reachability: a supported Linux/amd64 binary
// must expose a PCLNTAB-backed direct call path, including linker-recorded inline frames, from main.main to
// the vulnerable function before raising urgency. Unsupported formats, indirect calls, malformed metadata, or
// any absence are no coverage, never not_reachable.
GoBinaryReachabilityEnabled bool
// TaintCallgraphBin is the pinned synapse-callgraph binary: the sandboxed go/ssa call-graph builder
// the taint analyzer shells out to. In-repo cmd (built by `make build` into bin/); pin its hash via
// SYNAPSE_TOOL_HASHES, like any other tool binary.
TaintCallgraphBin string
// TaintEnabled turns on deterministic taint-analysis CapSAST proposals: post-scan, build the
// workspace call graph, assemble the taint FlowGraph over the injection catalog, and PROPOSE gated
// CapSAST judgments for a distinct verifier to gate. Off by default; opt-in + best-effort. Requires
// JudgmentsEnabled (it mints judgments) AND the SCA sandbox (it compiles untrusted target source).
TaintEnabled bool
// GoModGraphEnabled turns on transitive Go dependency-edge resolution via `go mod graph`:
// post-SBOM, add pkg:golang edges between existing components (go.mod alone has no edge graph). Off by
// default; opt-in + best-effort (a non-Go target / no module cache adds no edges, never fails the scan).
// GoBin is the go executable. Low-risk (go mod graph only reads go.mod files, never compiles the target).
GoModGraphEnabled bool
GoBin string
// MavenResolveEnabled turns on full Maven dependency-tree resolution via `mvn dependency:list`
// (best-effort + opt-in): a from-source Maven scan otherwise sees only direct deps with UNKNOWN
// (parent-BOM-managed) versions and no transitive tree, under-reporting vs a build-artifact scan.
// Off by default – it runs the Maven toolchain over untrusted project config + reaches the Maven
// repo, so production MUST run it sandbox-confined. MvnBin is the mvn executable.
MavenResolveEnabled bool
MvnBin string
// MavenRepoHosts are extra Maven-repository hosts (comma-separated) the sandboxed resolver may reach
// beyond Maven Central – e.g. a corporate mirror or the Apache plugin repo. Empty = Central only.
MavenRepoHosts []string
// MavenLocalRepo pins Maven's local repository to a PERSISTENT dir so the resolved tree is cached
// across scans instead of re-downloaded. Empty = ephemeral (under the sandbox tmpfs HOME).
MavenLocalRepo string
// GradleResolveEnabled turns on full Gradle dependency-tree resolution via `gradle dependencies`
// (best-effort + opt-in). HIGHER risk than Maven – evaluating build.gradle runs arbitrary build
// logic – so production MUST run it sandbox-confined and it never invokes the project's./gradlew.
// GradleBin is the pinned gradle executable; GradleHome is an optional persistent GRADLE_USER_HOME
// cache. MavenRepoHosts (above) extends the egress allow-list for both resolvers (shared JVM repos).
GradleResolveEnabled bool
GradleBin string
GradleHome string
// NPMResolveEnabled turns on npm dependency resolution via `npm install --package-lock-only` for a
// package.json with no committed lockfile (best-effort + opt-in). It runs --ignore-scripts (no project
// code executes) against a throwaway copy, but reaches the registry, so production MUST run it
// sandbox-confined. NPMBin is the pinned npm executable; NPMRegistryHosts extends the egress allow-list.
NPMResolveEnabled bool
NPMBin string
NPMRegistryHosts []string
// ManifestResolveEnabled turns on lockfile-less manifest resolution for composer.json / Gemfile /
// pyproject.toml via each ecosystem's own lock tool (no scripts). Reaches the registry, so production
// MUST run it sandbox-confined. Bins default to composer/bundle/poetry; ManifestRegistryHosts extends
// the egress allow-list (private mirror).
ManifestResolveEnabled bool
ComposerBin string
BundleBin string
PoetryBin string
ManifestRegistryHosts []string
// BundlerResolveEnabled turns on the Ruby Bundler resolver (`bundle lock` over a lockfile-less
// Gemfile). Unlike the composer/poetry/npm resolvers — which run lock-only with no project scripts —
// `bundle lock` EVALUATES the Gemfile, which IS a Ruby program, so it executes arbitrary project code
// on the host. It is therefore OPT-IN everywhere (default false), including the CLI, and production
// MUST run it sandbox-confined.
BundlerResolveEnabled bool
// JVMReachabilityEnabled turns on coarse JVM class-reachability tagging: after resolving the
// dependency tree, tag each component with whether the app's own compiled classes (transitively)
// reference its classes, so a finding on an unreferenced dependency can be deprioritized. Read-only
// bytecode parsing (no exec); best-effort + opt-in; never emits "unreferenced" for a not-built target.
JVMReachabilityEnabled bool
// JarHashOnlineEnabled turns on SHA-1 coordinate recovery for shaded/metadata-less JARs
// via an EGRESS call to Maven Central's SHA-1 search API. Recovers CVEs for JARs whose in-file
// identity was stripped. Off by default (it reaches the network); best-effort + rate-limit disciplined.
// JarHashBaseURL overrides the search endpoint (tests/mirrors); empty = search.maven.org.
// JarHashDBPath points at a local trivy-java-db-format SQLite index: OFFLINE SHA-1
// coordinate recovery, no rate limit, air-gap friendly. When BOTH are set, the offline DB is tried
// first and the online API is the fallback for its misses. Empty = no offline DB.
JarHashOnlineEnabled bool
JarHashBaseURL string
JarHashDBPath string
// CrossCheckEnabled turns on cross-check disagreement judgments: post-scan, where the run
// detection sources disagree on a vuln, mint an ungated CapCorrelation judgment for human review. On by
// default (effective-by-default policy, TestAnalysisDefaultsOn); best-effort — it degrades to a no-op when
// a second detection source is unavailable — set SYNAPSE_CROSSCHECK_ENABLED=false to opt out. Requires
// JudgmentsEnabled (it mints judgments).
CrossCheckEnabled bool
// SBOMCrossCheckEnabled turns on SBOM-PRODUCER cross-check judgments: a 2nd SBOM producer runs
// alongside the primary and components only one producer emits are minted as ungated CapCorrelation
// judgments (subject = component) for human review.
//
// OFF by default, unlike the other best-effort analysis capabilities. The owned parsers are the
// primary producer, so the only second producer is Syft, and defaulting this on made a stock
// deployment reach for a third-party binary Synapse does not otherwise need. The cross-check keeps
// its value as an opt-in independence check; it is not a condition of scanning.
// Requires JudgmentsEnabled (it mints judgments) and a Syft binary on PATH.
SBOMCrossCheckEnabled bool
// WriteupDraftsEnabled turns on the propose_writeup_draft agent tool: the agent can DRAFT a
// finding's write-up prose as a proposal; a human edits/signs off out of band. Off by default; opt-in.
// Requires AgentEnabled (the tool is advertised only on the agent catalog).
WriteupDraftsEnabled bool
// The verifier may use an independent endpoint, credential, provider, and model. Endpoint/key
// default to the proposer transport for backwards compatibility; the key is never logged.
VerifierBaseURL string
VerifierAPIKey string
VerifierProvider string
VerifierModel string
// MeasureCursorSecret is the HMAC-SHA256 key used to sign pagination cursors for
// the Measures API. Must be at least 32 bytes (hex or raw). Never logged.
// Required in production; in development an ephemeral key is generated.
MeasureCursorSecret string
// MCP server: exposes the agent tool catalog to external MCP clients,
// bearer-locked (role "mcp") and pinned to one engagement. Token is never logged.
MCPToken string
MCPAddr string
MCPEngagementID string
}
Config holds runtime configuration.
func Load ¶
func Load() Config
Load reads configuration from environment variables with sane defaults.
func (Config) AssessmentCycleDualWriteForTenant ¶ added in v0.2.0
func (Config) AssessmentLifecycleReadForTenant ¶ added in v0.2.0
func (Config) AssessmentLifecycleUIForTenant ¶ added in v0.2.0
func (Config) AssessmentShadowForTenant ¶ added in v0.2.0
func (Config) AssessmentSnapshotCompletionForTenant ¶ added in v0.2.0
func (Config) IsProduction ¶
IsProduction reports whether this is a production-grade deployment, in which the security gates (credential-vault master key, evidence/audit chain-head signing, sandbox requirement) MUST fail closed. It is the single authority for that decision – never compare cfg.Environment to a string literal directly.
It fails CLOSED: only an explicitly recognized non-production environment is treated as non-production; any other value (a typo like "prod"/"prodution", "staging", an empty/unset-then-overridden value, trailing whitespace) is treated as production, so a misconfigured environment lands in the STRICT gates rather than silently in lax, ephemeral-key dev behavior. The value is also normalized (trim + lowercase) here so the guarantee holds even if the field was not normalized at Load.
func (Config) JVMTier2PointsToEnabled ¶ added in v0.2.0
JVMTier2PointsToEnabled reports whether the optional Andersen-style receiver points-to refinement is enabled for the owned JVM Tier-2 call graph. It is deliberately OFF by default: CHA is the recall-first production posture, while points-to can only narrow virtual targets when its receiver facts are complete.
func (Config) MigrationDSN ¶ added in v0.2.0
MigrationDSN returns the DDL credential when configured, falling back to the runtime credential only for development convenience.
func (Config) ResolveScanCacheDir ¶
ResolveScanCacheDir returns the shared scan-cache root, defaulting to the backward-compatible "synapse-sbom" subdir of the OS user cache dir. Empty only when no cache dir can be determined.
func (Config) ResolveToolExecution ¶ added in v0.2.0
func (c Config) ResolveToolExecution(role ProcessRole) (ToolExecution, error)
ResolveToolExecution decides how role may execute tools, failing closed on any combination that would let a production API run an untrusted tool locally.
Production API pods are dispatch-only: they must not build a sandbox runner, and a missing queue is a startup failure rather than a silent fall back to local execution. The worker is always execution-capable, and the CLI always runs in process because it is the operator's own single-process scanner.
func (Config) ValidateAssessmentLifecycleRollout ¶ added in v0.2.0
ValidateAssessmentLifecycleRollout rejects rollout settings that can create unbounded migration work or expose UI/closure paths before their read inputs.
func (Config) ValidateCorrelationPosture ¶ added in v0.2.0
ValidateCorrelationPosture rejects unbounded correlation settings at startup.
func (Config) ValidateEgressGrantPosture ¶ added in v0.2.0
func (c Config) ValidateEgressGrantPosture(role ProcessRole) error
ValidateEgressGrantPosture fails closed unless production APIs and workers use a distinct machine credential and a dedicated signing authority.
func (Config) ValidateFleetTransportPosture ¶ added in v0.2.0
ValidateFleetTransportPosture rejects a production fleet transport that shares its client-certificate and bearer enrollment virtual hosts, or has no trusted certificate forwarding boundary.
func (Config) ValidateMigrationPosture ¶ added in v0.2.0
ValidateMigrationPosture keeps DDL credentials out of long-running production services. Production migrations are owned by the dedicated synapse-migrate command.
func (Config) ValidateNetworkExecutionPosture ¶ added in v0.2.0
func (c Config) ValidateNetworkExecutionPosture(role ProcessRole) error
ValidateNetworkExecutionPosture rejects production network execution kinds that do not yet have a trusted control-plane issuer branch. Development may use the local test egress applier.
func (Config) ValidateOIDCPosture ¶ added in v0.2.0
ValidateOIDCPosture fails closed when the browser OIDC BFF cannot bind identity/session state to a fixed tenant.
func (Config) ValidateResponseExecutionPosture ¶ added in v0.2.0
ValidateResponseExecutionPosture rejects a partially wired live response boundary.
func (Config) ValidateSandboxPosture ¶ added in v0.2.0
ValidateSandboxPosture rejects a production configuration that would execute tools without containment.
func (Config) ValidateSecretVerification ¶ added in v0.2.0
ValidateSecretVerification rejects a malformed optional Vault endpoint before a server begins serving scans. An empty endpoint is valid: GitHub and AWS checks do not require an operator-supplied URL.
func (Config) ValidateVulnerabilityMaintenance ¶ added in v0.2.0
func (Config) ValidateVulnerabilitySchedulerOwnership ¶ added in v0.2.0
ValidateVulnerabilitySchedulerOwnership rejects the two historical scheduler switches being enabled together. Both composition roots use the same scheduler implementation, but exactly one process may own source due-time dispatch.
func (Config) ValidateWorkerConcurrency ¶ added in v0.2.0
ValidateWorkerConcurrency bounds in-process queue claim loops so a configuration typo cannot create an unbounded number of privileged executions.
func (Config) ValidateWorkerProfile ¶ added in v0.2.0
func (Config) ValidateWorkerSandboxPosture ¶ added in v0.2.0
ValidateWorkerSandboxPosture preserves the scanner worker's production fail-closed sandbox gate while allowing data-only workers, which never construct or claim an executable-tool handler.
type ProcessRole ¶ added in v0.2.0
type ProcessRole string
ProcessRole names the composition root resolving its execution posture. The role is a property of the binary, not of the environment, so it is passed in rather than guessed.
const ( ProcessRoleAPI ProcessRole = "api" ProcessRoleWorker ProcessRole = "worker" ProcessRoleCLI ProcessRole = "cli" )
type ToolExecution ¶ added in v0.2.0
type ToolExecution string
ToolExecution is the resolved authority over whether a process may execute external tools against untrusted input itself, or must hand that work to the durable queue. It replaces inferring the boundary from a growing family of per-feature "via worker" booleans, which could not express "this process must never exec a tool".
const ( // ToolExecutionDispatchOnly forbids constructing tool runners in this process: work is // validated, authorized, and enqueued for an execution-capable worker to claim. ToolExecutionDispatchOnly ToolExecution = "dispatch-only" // ToolExecutionWorker executes queued work inside the hardened sandbox. ToolExecutionWorker ToolExecution = "worker" // ToolExecutionInProcess runs tools in the serving process. Development and CLI only. ToolExecutionInProcess ToolExecution = "in-process" )
type WorkerProfile ¶ added in v0.2.0
type WorkerProfile string
WorkerProfile selects the smallest safe composition for a durable worker.
const ( WorkerProfileAll WorkerProfile = "all" WorkerProfileIntegrations WorkerProfile = "integrations" WorkerProfileLifecycle WorkerProfile = "lifecycle" )