# MongoDB MONGODB_URI=mongodb://root:example@localhost:27017/compliance_scanner?authSource=admin MONGODB_DATABASE=compliance_scanner # LiteLLM LITELLM_URL=http://localhost:4000 LITELLM_API_KEY= LITELLM_MODEL=gpt-4o # GitHub GITHUB_TOKEN= GITHUB_WEBHOOK_SECRET= # GitLab GITLAB_URL=https://gitlab.com GITLAB_TOKEN= GITLAB_WEBHOOK_SECRET= # Jira JIRA_URL=https://your-org.atlassian.net JIRA_EMAIL= JIRA_API_TOKEN= JIRA_PROJECT_KEY= # SearXNG SEARXNG_URL=http://localhost:8888 # NVD NVD_API_KEY= # Agent AGENT_PORT=3001 SCAN_SCHEDULE=0 0 */6 * * * CVE_MONITOR_SCHEDULE=0 0 0 * * * GIT_CLONE_BASE_PATH=/tmp/compliance-scanner/repos # Dynamic PLC testing — ephemeral soft-PLC provisioning (#183). Off unless # enabled; requires the agent container to have Docker access (socket mount). # When on, a PLC/SPS target with control logic but no reachable device gets its # logic instantiated on a throwaway OpenPLC, probed, then torn down. PLC_RUNTIME_ENABLED=0 PLC_RUNTIME_IMAGE=registry.meghsakha.com/openplc:latest PLC_RUNTIME_NETWORK=certifai PLC_RUNTIME_MEMORY=512m PLC_RUNTIME_CPUS=0.5 PLC_RUNTIME_MAX_LIFETIME_SECS=180 PLC_RUNTIME_OPENPLC_USER=openplc PLC_RUNTIME_OPENPLC_PASSWORD=openplc # Dashboard DASHBOARD_PORT=8080 AGENT_API_URL=http://localhost:3001 # MCP Server MCP_ENDPOINT_URL=http://localhost:8090 # Keycloak (required for authentication) KEYCLOAK_URL=http://localhost:8080 KEYCLOAK_REALM=compliance KEYCLOAK_CLIENT_ID=compliance-dashboard REDIRECT_URI=http://localhost:8080/auth/callback APP_URL=http://localhost:8080 # OpenTelemetry (optional - omit to disable) # OTEL_EXPORTER_OTLP_ENDPOINT=http://localhost:4317 # OTEL_SERVICE_NAME=compliance-agent