Reference

Environment variables

Every environment variable DefenseClaw reads, grouped by category, with defaults, accepted values, and the file:line that consumes each one.

This is the canonical list of every environment variable DefenseClaw reads. The list is generated from internal/envvars/registry.json; CI fails if any callsite references a DEFENSECLAW_* var not declared in the registry.

Config v8 observability policy lives in YAML

V8 does not use ambient DEFENSECLAW_OTEL_*, standard OTEL_EXPORTER_OTLP_*, or DEFENSECLAW_DISABLE_REDACTION values as live collection/routing/redaction policy. Destinations refer to credential environment variables explicitly through fields such as token_env, bearer_env, or {env: NAME}. Entries below described as legacy observability inputs are read only by the automatic v7-to-v8 upgrade converter and are retired after their effective value is materialized. The generated table names that compatibility scope at each such row.

See live what's active

defenseclaw doctor surfaces any active security override in real time. Operators with no overrides set see a single "none active" pass row; if you've left a debug toggle on, doctor flags it loudly.

Security opt-outs

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_ALLOW_CGNATHIGHunset (CGNAT blocked)1, unsetAllow RFC 6598 carrier-grade NAT addresses (100.64.0.0/10, used by Tailscale and similar overlays) through the SSRF / private-IP guards.CGNAT egress guard — prevents SSRF into shared carrier-grade NAT / overlay-network address space (e.g. another tenant's Tailscale node).internal/netguard/netguard.go — cgnatAllowed() omits 100.64.0.0/10 from the reserved-CIDR list when set
cli/defenseclaw/webhooks/writer.py — _cgnat_allowed() gates webhook URL validation for CGNAT IPs
cli/defenseclaw/registries/ssrf.py — _cgnat_allowed() gates registry/manifest SSRF resolution for CGNAT
DEFENSECLAW_ALLOW_HOOK_CONTRACT_DRIFTHIGHunset (fail-closed in action mode)1, unsetBypass the action-mode fail-closed checks for unverified hook contracts and hook-contract lock drift during connector setup, allowing enforcing hooks to be installed against agent versions outside the verified contract matrix.Hook contract verification — prevents installing an enforcing hook whose request/response contract has drifted from the verified matrix (a silent guardrail bypass).internal/gateway/sidecar.go — Blocks connector setup on an unverified hook contract in action mode unless set
internal/gateway/sidecar.go — Blocks connector setup on hook-contract lock drift in action mode unless set
cli/defenseclaw/commands/cmd_setup.py — Python setup path mirrors the gateway drift/contract enforcement
DEFENSECLAW_ALLOW_LOCAL_MCP_TARGETSHIGHunset (SSRF guard enforced)1, unsetSkip SSRF validation for MCP scan target URLs, permitting loopback, private, link-local, and cloud-metadata destinations.MCP scan-target SSRF guard — prevents a scan request from reaching IMDS / loopback / private hosts.internal/scanner/mcp.go — validateMCPScanTargetURL() returns early without SSRF checks when set
DEFENSECLAW_ALLOW_PRIVATE_UPSTREAMSHIGHunset (all private IPs blocked)comma-separated IPs (e.g. 10.50.2.100,172.16.0.5), unsetComma-separated list of specific IP addresses exempt from the SSRF private-address block for LLM upstream forwarding.Private-upstream SSRF guard exemption — allows operator-specified on-prem LLM gateways on RFC 1918 addresses to bypass the private-IP block. Each IP must be explicitly listed (no CIDR).internal/netguard/allowlist.go — ParseAllowedPrivateUpstreams() reads this env var and merges with config.yaml entries
cli/defenseclaw/registries/ssrf.py — _allowed_private_ips() reads this env var for Python-side SSRF guard exemption
DEFENSECLAW_CODEX_LOOPBACK_TRUSTHIGHunset (fail-closed)1, unsetRestore legacy loopback-trusts-any-bearer behavior for the Codex connector.Per-bearer Codex authentication on loopback — prevents same-host user-to-user impersonation when multiple users share an OS account.internal/gateway/connector/codex.go — Authenticate() falls back to legacy behavior when set; emits a [SECURITY] log line
DEFENSECLAW_DEVlowunset1, true, unsetMark the process as a developer build.—internal/redaction/credentials.go — isCredentialScrubDevMode reads this var
DEFENSECLAW_DISABLE_AWS_HTTP1_SHIMmediumunset (shim active for Bedrock)1, unsetDisable the AWS Bedrock HTTP/1 monkey-patch the OpenClaw plugin installs to make Bedrock traffic visible to the guardrail proxy.—extensions/defenseclaw/src/aws-sdk-http1-for-guardrail.ts — JS shim bails out when set
DEFENSECLAW_DISABLE_REDACTIONHIGHunset (ignored by the v8 runtime)1, true, unsetUpgrade-only v7 migration input.
Fix: Configure observability.defaults, bucket, or destination redaction_profile in config v8.
—cli/defenseclaw/observability/v8_migration.py — Reads the captured v7 upgrade environment and materializes the equivalent v8 redaction profile
DEFENSECLAW_DUMP_RAW_SECRETSHIGHunset1, unsetE2E test toggle ONLY.—scripts/test-e2e-full-stack.sh — Dumps raw secrets in diagnostic output for test debugging
DEFENSECLAW_FAIL_MODEmedium(value from guardrail.hook_fail_mode in config.yaml)open, closed, unsetPer-process override of guardrail.hook_fail_mode for hook delivery, missing-token/authentication, and invalid-response failures.—internal/gateway/connector/hooks/inspect-tool.sh — Representative shared template; every generated hook reads the same override
DEFENSECLAW_FORCE_AWS_HTTP1_SHIMlowunset (shim only on Bedrock)1, unsetForce the AWS HTTP/1 shim to install even on non-Bedrock setups.—extensions/defenseclaw/src/aws-sdk-http1-for-guardrail.ts — JS shim forces install when set
DEFENSECLAW_JSONL_DISABLElowunset (ignored by the v8 runtime)1, true, unsetUpgrade-only v7 migration input.
Fix: Add, disable, or remove an explicit kind: jsonl destination in config v8.
—cli/defenseclaw/observability/v8_migration.py — Reads the captured v7 upgrade environment when converting implicit JSONL behavior
DEFENSECLAW_NO_SANDBOXmediumunset1, unsetSet to 1 to run a harness natively for one command when defenseclaw sandbox enable <harness> has wrapped it in your shell (for example DEFENSECLAW_NO_SANDBOX=1 claude).—internal/openshell/wrapper/wrapper.go — Shell wrapper block bypass
internal/openshell/sandboxcli/wrappers.go — sandbox enable/disable wrapper management
internal/openshell/sandboxcli/doctor.go — Doctor reports an active bypass
DEFENSECLAW_OTEL_TLS_INSECUREHIGHunsettrue, false, 1, 0, unsetUpgrade-only v7 migration input for the former flat OTLP TLS-insecure toggle.
Fix: Configure observability.destinations[].tls in config v8.
Enabling this variable disables OTLP server-certificate verification after legacy configuration is migrated into a named destination.cli/defenseclaw/observability/v8_migration.py — Converts the captured v7 TLS policy into a canonical v8 destination
internal/config/config.go — Reads the TLS decision only inside the legacy configuration loader
DEFENSECLAW_POLICY_VALIDATE_ALLOW_NO_OPAmediumunset (validation requires OPA)1, unsetAccept a policy file as 'validated' even when OPA / Rego is not installed.—cli/defenseclaw/commands/cmd_policy.py — Policy validate command bypass
DEFENSECLAW_REVEAL_PIImediumunset (PII redacted everywhere)1, true, unsetReveal PII in operator-facing logs only (CLI stdout, TUI).—internal/redaction/redaction.go — Reveal() reads this env var
DEFENSECLAW_STRICT_AVAILABILITY—unset (no additional force-closed override)1, true, TRUE, yes, YES, unsetForce transport and missing-token hook failures closed even when the effective fail mode is open.—internal/gateway/connector/hooks/_hardening.sh — Hook hardening sourced by every *-hook.sh
DEFENSECLAW_TESTlowunset1, true, unsetMark the process as running under tests.—internal/redaction/credentials.go — isCredentialScrubDevMode reads this var
DEFENSECLAW_TOOL_INSPECT_FAIL_OPENHIGHunset (fail-closed)1, true, unsetMake the plugin-side tool-inspect hook fail-open (allow tool) when the gateway is unreachable.—extensions/defenseclaw/src/index.ts — OpenClaw plugin tool-inspect handler
DEFENSECLAW_TRUSTED_PROXY_CIDRSmediumunset (X-Forwarded-For ignored)comma-separated CIDRs or IPs, unsetComma-separated CIDRs (or bare IPs) of reverse-proxy peers whose X-Forwarded-For header is trusted for client-IP attribution in logs.Client-IP attribution — trusting forwarded headers from an untrusted peer lets a caller spoof the source IP recorded in auth-failure and audit logs.internal/gateway/requestctx.go — isTrustedProxyPeer() trusts X-Forwarded-For only from these peers
DEFENSECLAW_UNGUARDED_CHATGPT_CODEX_RESPONSESHIGHunset (guardrail proxy enforced)1, unsetAllow ChatGPT Codex response-backend requests to bypass the guardrail proxy.
Fix: Leave unset for normal guarded operation; use only while diagnosing proxy incompatibility.
Codex response guardrail enforcement — prevents model prompt/response traffic from silently bypassing observe/action policies unless the operator explicitly opts into an unguarded fallback.extensions/defenseclaw/src/fetch-interceptor.ts — Env-var name exported for the OpenClaw interceptor and tests
extensions/defenseclaw/src/fetch-interceptor.ts — isCodexResponsesPassthroughEnabled gates the explicit unguarded passthrough path
extensions/defenseclaw/src/fetch-interceptor.ts — Interceptor warning names the active unguarded bypass
DEFENSECLAW_UPGRADE_ALLOW_UNVERIFIED—unset (no effect)1, unsetRetired 0.x upgrade override with no effect in 1.x.
Fix: Remove it; 1.x checks every release asset against checksums.txt and has no unverified mode.
—internal/cli/root.go — Refuses the retired name when loading .env
cli/defenseclaw/file_permissions.py — Refuses the retired name when loading .env
DEFENSECLAW_WEBHOOK_ALLOW_LOCALHOSTmediumunset (SSRF guard blocks private IPs)1, unsetRelax the webhook SSRF guard to permit RFC1918 / loopback / link-local destinations.—internal/gateway/webhook.go — Webhook sender SSRF gate
internal/gateway/webhook.go — Webhook validate-on-add SSRF gate
cli/defenseclaw/webhooks/writer.py — Python writer validate-on-add

Credentials & secrets

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_CMID_BROKER_AUTH_KEYHIGHunset (legacy in-process provider path)absolute installer-owned broker-auth.key path, unsetSelect the protected 32-byte key used by the Windows gateway to authenticate credential broker responses.Authentication material path — the key bytes never belong in an environment variable, log, event, or diagnostic; the environment contains only its protected path.internal/managed/cmidbroker/broker.go — Loads the key through the exact Windows ACL and stable-handle validator
DEFENSECLAW_GATEWAY_TOKENHIGHunsetbearer-token, unsetBearer token hooks present to the gateway API.—internal/gateway/connector/hooks/inspect-tool.sh — Hooks present this header
internal/cli/sidecar.go — Sidecar references in setup messages
DEFENSECLAW_LLM_KEYHIGHunsetLLM API key string, unsetCanonical env-var name for the unified LLM key.—cli/defenseclaw/credentials.py — Credentials registry default for llm.api_key_env
DEFENSECLAW_LLM_KEY_ENVlowDEFENSECLAW_LLM_KEYany env-var nameIndirection: name of the env var to read the LLM key from.—cli/defenseclaw/credentials.py — Credentials registry indirection
DEFENSECLAW_LLM_MODELlow(value from llm.model in config.yaml)provider/model-id, unsetOverride the configured LLM model id at runtime.—cli/tests/test_config.py — Tested override path
DEFENSECLAW_LLM_MODEL_ENVlowDEFENSECLAW_LLM_MODELany env-var nameIndirection: name of the env var to read the LLM model from.—cli/defenseclaw/credentials.py — Credentials registry indirection
DEFENSECLAW_LOCAL_PASSWORDHIGHunsetany-string, unsetPassword for the local Splunk daemon basic-auth surface.—internal/cli/daemon.go — Daemon reads from .env
DEFENSECLAW_LOCAL_SPLUNK_HEC_TOKENHIGHunsetcryptographically random HEC token, unsetGenerated HEC token for the owned bundled Local Splunk sink.—cli/defenseclaw/observability/local_splunk.py — Native Local Splunk credential contract
cli/defenseclaw/commands/cmd_setup.py — Owned local-splunk audit sink wiring
DEFENSECLAW_LOCAL_USERNAMEmediumunsetany-string, unsetUsername for the local Splunk daemon basic-auth surface.—internal/cli/daemon.go — Daemon reads from .env
DEFENSECLAW_MASTER_KEYHIGH(derived at boot from device.key)sk-dc-<hex>Bearer derived from device.key (PBKDF2).—internal/gateway/proxy.go — deriveMasterKey
DEFENSECLAW_PD_KEYmediumunsetpagerduty-key, unsetAlias for DEFENSECLAW_PD_ROUTING_KEY.—cli/defenseclaw/commands/cmd_setup_webhook.py — Alternative PD key var
DEFENSECLAW_PD_ROUTING_KEYmediumunsetpagerduty-routing-key, unsetPagerDuty routing key default for webhook entries.—cli/defenseclaw/commands/cmd_setup_webhook.py — Webhook setup default
DEFENSECLAW_REGISTRY_TOKENmediumunsetregistry-token, unsetDefault registry auth env var (e.g.—cli/defenseclaw/commands/cmd_registry.py — Registry default auth_env
DEFENSECLAW_SANDBOX_TOKENHIGH(set by DefenseClaw in the sandbox)OpenShell credential placeholder, binding token (token_delivery: env), unsetPer-sandbox binding token the sandbox hooks present to the DefenseClaw hook ingress.Never log or persist the value. Sandbox hooks must read it from the environment at request time; a placeholder baked into static config does not resolve.internal/openshell/sandbox_env.go — Go constant naming the provider credential and sandbox env var
internal/gateway/connector/hooks/_sandbox.sh — defenseclaw_sandbox_require_token fails every sandbox hook closed when it is missing or malformed
internal/gateway/connector/hooks/claude-code-hook.sh — Sandbox variant sends it as the ingress Authorization bearer
internal/gateway/connector/hooks/codex-hook.sh — Sandbox variant sends it as the ingress Authorization bearer
internal/gateway/connector/claudecode_sandbox.go — Rendered otelHeadersHelper prints it as the OTLP Authorization header
internal/gateway/connector/codex_sandbox.go — Rendered Codex notify bridge authenticates with it
internal/openshell/harness/codex.go — Codex launcher adds it as the OTLP exporter Authorization with -c flags
DEFENSECLAW_SETUP_OBSERVABILITY_TOKENHIGHunsetprovider-token, unsetShort-lived secret transport for 'defenseclaw setup observability add'.—cli/defenseclaw/commands/cmd_setup_observability.py — Click reads the setup token from the child process environment instead of argv
DEFENSECLAW_SIEM_SECRETmediumunsetany-string, unsetSIEM webhook secret default.—cli/defenseclaw/commands/cmd_setup_webhook.py — Webhook setup default
DEFENSECLAW_SKILLSSH_TOKENmediumunsetregistry-token, unsetExample registry-specific token env var.—cli/defenseclaw/commands/cmd_registry.py — Registry example token
DEFENSECLAW_SKILL_SCANNER_LLM_KEYHIGHunsetLLM API key string, unsetOverride the LLM key used by the skill scanner only.—cli/defenseclaw/credentials.py — Credentials registry
DEFENSECLAW_SPLUNK_HEC_TOKENHIGHunsetHEC token, unsetAlternative HEC token consulted by the Python sink wiring when the canonical splunk_hec.token_env points to a different var.—cli/defenseclaw/commands/cmd_setup.py — Python Splunk wiring fallback
DEFENSECLAW_WEBEX_TOKENmediumunsetwebex-bot-token, unsetWebex bot token default for webhook entries.—cli/defenseclaw/commands/cmd_setup_webhook.py — Webhook setup default
DEFENSECLAW_WEBHOOK_SECRETmediumunsetany-string, unsetGeneric webhook HMAC secret default.—cli/defenseclaw/commands/cmd_setup_webhook.py — Webhook setup default

Paths & runtime layout

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_API_ADDRlow(templated value from gateway.api_port at hook install time)host:port, unsetSidecar API address that hooks dial.—internal/gateway/connector/hooks/inspect-tool.sh — Hooks dial this
DEFENSECLAW_APP_PATH—/Applications/DefenseClawMac.app when presentany-absolute-path, nonemacOS app bundle that install.sh replaces with the release's app; none skips the app.—scripts/install.sh — Finds the DefenseClawMac.app bundle to update
DEFENSECLAW_BINlow(discovered via PATH lookup)any-absolute-pathOverride path to the defenseclaw CLI binary.—internal/scanner/plugin_test.go — Plugin test harness
scripts/setup-llm.sh — LLM setup script
DEFENSECLAW_BUILDID—unsetdefenseclaw-enterprise-setup-<40-char-lowercase-sha>, unsetReproducible-build id for the Windows managed-enterprise AVC assembly step.—packaging/scripts/lib/repro-flags.sh — Sourced by assemble.sh; passes to go build -buildid
packaging/scripts/lib/repro-flags.ps1 — Sourced by assemble.ps1; passes to go build -buildid
.github/workflows/windows-deterministic-build.yml — Set in the reproducibility CI fan-out for the emitter build
DEFENSECLAW_CMID_BROKER_PIPEHIGHunset (legacy in-process provider path)\\.\pipe\DefenseClawCMIDBroker, installer-owned certification pipe, unsetIdentify the exact local named pipe used by the restricted Windows gateway to reach the isolated managed credential provider broker.Local IPC identity boundary — the installer pins this value in the protected gateway service registry environment; partial configuration fails closed.internal/managed/cmidbroker/broker.go — Selects the broker client only when the complete protected service environment is present
DEFENSECLAW_CMID_BROKER_SERVICE_NAMEHIGHunset (legacy in-process provider path)DefenseClawCMIDBroker, installer-owned certification broker service, unsetBind the gateway broker client to the exact installer-owned LocalSystem credential broker service.SCM identity boundary — changing this value cannot redirect the client because only exact production and certification tuples are accepted.internal/managed/cmidbroker/broker.go — Cross-checks the broker service, gateway service, and pipe identity tuple
DEFENSECLAW_CONFIGmedium${DEFENSECLAW_HOME}/config.yamlany-absolute-path, unsetOverride the config.yaml path independently from DEFENSECLAW_HOME.Managed config path separation — lets system services read admin-owned policy without making the runtime data directory admin-writable.internal/config/defaults.go — Go config path resolver
cli/defenseclaw/config.py — Python config path resolver
cli/defenseclaw/migrations.py — Migration config path resolver
DEFENSECLAW_CUSTOM_PROVIDERS_PATHlowunsetany-absolute-path, unsetPath to a custom providers YAML file consulted before the embedded catalog.—internal/configs/embed.go — Go embedded-providers loader
DEFENSECLAW_DEPLOYMENT_MODEHIGHunset (use config.yaml deployment_mode)managed_enterprise, unmanaged_byod, unsetPin the process deployment mode independently from config.yaml.Immutable managed-mode boundary — prevents config replacement from disabling administrator-owned path and ownership checks. Spec 003 additionally uses this pin as the deploy-mode probe BEFORE config.yaml loads, so a mis-set value would incorrectly hard-exit (OSS drift) or spin the wait loop (managed_enterprise drift) — the finite value set in accepted_values guards both cases.internal/config/config.go — Pins deployment mode before parsing or trusting config.yaml
internal/cli/config_v8_wait.go — Spec 003 daemon wait loop gates on managed_enterprise before config.yaml has loaded
internal/cli/enterprise_hooks.go — Spec 003 hook-guardian late-manifest wait gates on managed_enterprise for --deferred-config installs
packaging/systemd/defenseclaw-gateway.service — Managed Linux service pin
packaging/launchd/com.cisco.secureclient.defenseclaw.plist — Managed macOS service pin
packaging/windows/DefenseClawEnterprise.psm1 — Windows SCM service env pin (both DefenseClawGateway + DefenseClawHookGuardian); already the source of the managed_enterprise value the spec 003 wait loops key off
DEFENSECLAW_ENTERPRISE_PROFILEHIGHunset (use config.yaml enterprise.profile; then secure_client on Windows/macOS, standalone on Linux)secure_client, standalone, unsetPin the managed_enterprise profile (secure_client or standalone) in every managed service environment, next to DEFENSECLAW_DEPLOYMENT_MODE, so a config replacement cannot switch the decision and identity stack.Immutable profile boundary. Must agree with config.yaml enterprise.profile; a mismatch refuses to start. Only meaningful with DEFENSECLAW_DEPLOYMENT_MODE=managed_enterprise; setting it on an unmanaged process is an error. Refused from .env files: only the service definition may set it.internal/config/config.go — Resolves and validates the enterprise profile against config.yaml before any managed trust check
internal/managed/profile.go — Profile resolution rules and the per-OS default
internal/cli/root.go — Refuses the pin from .env files so only the service definition sets it
DEFENSECLAW_GATEWAY_BINlow(discovered via PATH lookup)any-absolute-pathOverride path to the defenseclaw-gateway binary.—cli/defenseclaw/gateway.py — Python gateway-process spawner
DEFENSECLAW_HOME—~/.defenseclawany-absolute-pathOverride the canonical data dir (default ~/.defenseclaw).—internal/config/defaults.go — Go default-resolver
cli/defenseclaw/config.py — Python config loader
cli/defenseclaw/connector_paths.py — Connector path resolver
scripts/install.sh — Installer reads this
internal/gateway/connector/hooks/inspect-tool.sh — Hooks read this
DEFENSECLAW_HOOK_GUARDIAN_AUTH_DIRHIGH${DEFENSECLAW_HOME}-hook-guardianany-absolute-admin-owned-path, unsetSelect the administrator-owned directory containing the hook guardian protected-target authorization ledger.Privileged repair authorization — must remain root/admin-owned and non-writable by the DefenseClaw service account.internal/managed/managed.go — Resolves the protected-target authorization path
internal/cli/enterprise_hooks.go — Privileged guardian writes successful protected targets
internal/gateway/sidecar.go — Managed health verifies connector coverage before advertising enforcement
DEFENSECLAW_INSTALL_DIRlow$HOME/.local/binany-absolute-pathDirectory where CLI symlinks are placed by install.sh / setup-llm.sh.—scripts/setup-llm.sh — Install location for setup-llm
DEFENSECLAW_INSTALL_ROOTmediumunset (set by DefenseClawSetup-x64.exe launcher)any-absolute-path, unsetNative Windows installer root injected by the stable defenseclaw.exe launcher so the managed Python CLI can locate the owning packaged install for installer-based upgrade handoff.Installer root selection — upgrade code must treat this inherited value as untrusted and verify it is a canonical, product-owned Windows install before handing off to the setup executable.cmd/defenseclaw-launcher/main.go — Launcher appends the verified install root to the managed Python process environment
DEFENSECLAW_IPC_SOCKETlowunset (managed_enterprise: Windows Secure Client uses <TrustedProgramFiles>\Cisco\Cisco Secure Client\DefenseClaw\ipc\defenseclaw_ipc.sock and Windows standalone uses <TrustedProgramFiles>\Cisco\DefenseClaw\ipc\defenseclaw_ipc.sock; Linux/macOS use <dirname(data_dir)>/ipc/defenseclaw_ipc.sock. Other modes use <data_dir>/ipc/defenseclaw_ipc.sock)any-absolute-path, unsetOverride the local UDS gRPC socket path used by the internal/ipc server in unmanaged and test deployments.Local-only socket path override — managed_enterprise ignores the environment override, creates the resolved socket with a 0660 ceiling (0600 otherwise), and authenticates peers against the effective code-signing team, signing, and bundle-ID allowlists. Managed Windows also fixes the parent to the trusted Program Files DefenseClaw IPC directory.internal/ipc/paths.go — ResolveSocketPath consults this before falling back to the deployment-mode default
internal/ipc/paths_windows.go — Managed Windows resolves the fixed Cisco Secure Client socket path from TrustedProgramFiles
DEFENSECLAW_LIFECYCLE_UNITlowunset (an administrator or MDM run quiesces every DefenseClaw unit)defenseclaw-enterprise-apply.service, com.cisco.defenseclaw.apply, unsetSet by the standalone config-apply unit (systemd) or launchd job to its own name, so the lifecycle it runs never stops or restarts the unit executing the transaction.Only exempts the config-apply entry point from being stopped; any other value is ignored. The units that set it are root-owned.internal/enterpriseunix/env.go — Accepts only the config-apply entry point and skips it when quiescing, rolling back and activating
DEFENSECLAW_OBSERVABILITY_BINlowdefenseclaw-observability (resolved via PATH)executable name or absolute path, unsetOverride the executable used by the backward-compatible POSIX local-observability bridge.Executable selection — a non-default value changes which local program the compatibility bridge launches.bundles/local_observability_stack/bin/openclaw-observability-bridge — POSIX compatibility bridge selects the lifecycle-controller executable
DEFENSECLAW_OVERLAY_ROOTlowunsetany-absolute-path, unsetExtra provider-catalog overlay dir merged on top of the built-in catalog.—cli/defenseclaw/commands/cmd_setup_provider.py — Provider setup overlay loader
DEFENSECLAW_PLIST_SRClowunset (installer picks plist alongside install.sh)any-absolute-path-to-plist, unsetOverride the LaunchDaemon plist source file the macOS installer copies to /Library/LaunchDaemons.Installer-only override — treated as untrusted operator input, so the referenced plist must be root-owned and never group/world-writable. The bundled default plist next to install.sh is accepted regardless of extraction owner (content originates from the trusted bundle) but group/world-writable is still refused.packaging/macos/install.sh — macOS bundle installer plist resolution
DEFENSECLAW_SCRUB_BINlowunset (auto-discover in order: /opt/cisco/secureclient/defenseclaw/bin/defenseclaw-gateway, then a defenseclaw or defenseclaw-gateway executable next to uninstall.sh)any-absolute-path-to-executable, unsetOverride the DefenseClaw gateway binary used by the macOS uninstaller for the per-user agent-config scrub step (defenseclaw-gateway enterprise hooks scrub).Uninstaller-only executable override — uninstall.sh runs under sudo, so the referenced binary is exec'd as root. _scrub_bin() validates every override before use via the shared _scrub_bin_trusted helper: must be an absolute path, must be a regular file (not a symlink or directory), must be executable, must be root-owned, must not be group/other writable. Any check failing prints a WARN and falls through to auto-discovery. Intended for bundle-fixture and dev-tree tests; production installs should never set this. First shipped in the macOS 26.7.3 Cisco Secure Client bundle (DefenseClaw 0.8.5).packaging/macos/uninstall.sh — _scrub_bin() prefers this override before falling back to the managed install path
DEFENSECLAW_SENSOR_HELPER_SOCKETlowunset (managed_enterprise: Windows Secure Client uses <TrustedProgramFiles>\Cisco\Cisco Secure Client\DefenseClaw\ipc\sensor-helper.sock and Windows standalone uses <TrustedProgramFiles>\Cisco\DefenseClaw\ipc\sensor-helper.sock; Linux uses /run/defenseclaw-sensor/sensor-helper.sock; macOS standalone uses /var/run/defenseclaw-sensor/sensor-helper.sock; macOS Secure Client keeps /var/run/defenseclaw/sensor-helper.sock. Other modes use <data_dir>/ipc/sensor-helper.sock)any-absolute-path, unsetOverride the local UDS path the AI Discovery sensor helper listens on and the gateway dials.Local-only socket path override, ignored under managed_enterprise. The helper creates the socket at mode 0660 owned by the gateway's group and re-checks the kernel-supplied peer uid at accept on Linux and macOS; Windows anchors the path to the trusted Program Files IPC directory and gates access with the socket DACL. The protocol is closed: a client can ask for the process table, the connection table, the event stream or DNS and cannot describe any of them, so a compromised gateway gains no reach it did not already have.internal/sensor/acquire/paths.go — DefaultSocketPath consults this outside managed deployments before falling back to the deployment-mode default
DEFENSECLAW_SIDECAR_URLlowhttp://127.0.0.1:18790any-http-urlTarget URL for the bundled CodeGuard skill (skills/codeguard/main.py) to call into the sidecar.—skills/codeguard/main.py — Skill sidecar URL
DEFENSECLAW_UNIX_SERVICE_ACCOUNTHIGHunset (falls back to "defenseclaw")<local unix username>, unsetOverride the unix service-account username the managed runtime trust check accepts as a legitimate leaf-owner alongside root.Unix managed-runtime writer identity — a misconfigured value silently drops trust for the real service account. Change only in coordinated custom-packaging setups; never expose to per-user shells.internal/managed/managed.go — Defines the optional unix service-account override environment variable
internal/managed/trust_unix.go — Reads the override inside trustedRuntimeOwner when the packaged service username diverges from the default
DEFENSECLAW_WINDOWS_ENTERPRISE_INSTALLERHIGHunset (resolve the trusted installer adjacent to the native binary)absolute path to a trusted install-enterprise.ps1, unsetSelect the signed Windows enterprise PowerShell installer used by the native lifecycle CLI when --installer is omitted.Privileged code-selection boundary — the resolved installer and adjacent module must pass the native trust checks before elevation.internal/cli/windows_enterprise_service.go — Resolves and trust-validates the installer delegated to by enterprise windows lifecycle commands
DEFENSECLAW_WINDOWS_GATEWAY_SERVICE_NAMEHIGHDefenseClawGatewayinstaller-owned Windows gateway service nameIdentify the exact enterprise gateway SCM service used for service-SID ACLs and managed hook peer verification.Service-identity boundary — changing this value changes which virtual service SID is authorized to read managed runtime secrets.internal/cli/windows_codex_requirements.go — Binds managed Codex runtime metadata to the gateway service identity
internal/cli/enterprise_hooks_token_windows.go — Derives the gateway virtual-service SID for protected token ACLs
DEFENSECLAW_WINDOWS_SERVICE_ACCOUNTHIGHNT SERVICE\${DEFENSECLAW_WINDOWS_GATEWAY_SERVICE_NAME}NT SERVICE\<installer-owned-service-name>Identify the exact virtual Windows service account permitted to write the managed runtime tree.Managed-runtime writer identity — only the installer-pinned virtual service account may receive the corresponding write grants.internal/managed/managed.go — Defines the protected service-account environment contract
internal/managed/trust_windows.go — Resolves and validates the virtual-service SID
internal/gateway/connector/hook_api_token_windows.go — Authorizes the service SID on managed hook token files
DEFENSECLAW_WINDOWS_SERVICE_LOGmediumunset (retain the inherited service output handles)absolute administrator-approved log path, unsetSelect the absolute append-only log path used when the native binary is hosted by the Windows SCM.Service output path — the enterprise installer pins this in protected SCM configuration and hardens its parent directory.cmd/defenseclaw/service_windows.go — Redirects native Windows service stdout and stderr to the configured file
cmd/defenseclaw-sensor-helper/log_windows.go — Appends the sensor helper's service log to the configured file
DEFENSECLAW_WINDOWS_SERVICE_NAMEHIGHunset (run as an ordinary CLI process)installer-owned Windows service name, unsetSelect the SCM service role hosted by the signed native defenseclaw binary.Installer-owned service switch — production values belong in the protected per-service registry Environment value, not an interactive user environment.cmd/defenseclaw/service_windows.go — Opts the native binary into SCM hosting for the named enterprise service

Telemetry (OTel)

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_JUDGE_PERSIST_QUEUE_SIZE—unset (config guardrail.judge_persist_queue_depth, default 1024)positive integer, unsetEmergency boot-time override for the async judge-persistence queue depth.—internal/gateway/sidecar.go — Overrides cfg.Guardrail.JudgePersistQueueDepth at sidecar boot
DEFENSECLAW_OTEL_ENABLED—unset (ignored by the v8 runtime)true, false, 1, 0, unsetUpgrade-only v7 migration input for the former otel.enabled master toggle.
Fix: Enable or disable named observability.destinations entries in config v8.
—cli/defenseclaw/observability/v8_migration.py — Preserves the effective v7 OTel master-toggle decision during upgrade
internal/config/config.go — Binds the variable only inside the legacy configuration loader used before v8 activation
DEFENSECLAW_OTEL_ENDPOINT—unsetany-otlp-endpoint, unsetUpgrade-only v7 migration input for the former flat OTLP exporter endpoint.
Fix: Configure observability.destinations[].endpoint in config v8.
—cli/defenseclaw/observability/v8_migration.py — Converts the captured v7 endpoint into a canonical v8 destination
internal/config/config.go — Reads the endpoint only inside the legacy configuration loader
DEFENSECLAW_OTEL_LOGS_ENDPOINT—unsetany-otlp-endpoint, unsetUpgrade-only v7 migration input for the former log-specific OTLP endpoint.
Fix: Configure a v8 destination endpoint or signal_overrides.logs.endpoint.
—cli/defenseclaw/observability/v8_migration.py — Converts captured v7 signal-specific endpoints into canonical v8 destinations
internal/config/config.go — Reads signal-specific endpoints only inside the legacy configuration loader
DEFENSECLAW_OTEL_LOGS_PROTOCOL—unsetgrpc, grpc/protobuf, http, http/protobuf, http/json, unsetUpgrade-only v7 migration input for the former log-specific OTLP protocol.
Fix: Configure the protocol on the canonical v8 destination.
—cli/defenseclaw/observability/v8_migration.py — Converts captured v7 signal-specific protocols into canonical v8 destinations
internal/config/config.go — Reads signal-specific protocols only inside the legacy configuration loader
DEFENSECLAW_OTEL_METRICS_ENDPOINT—unsetany-otlp-endpoint, unsetUpgrade-only v7 migration input for the former metric-specific OTLP endpoint.
Fix: Configure a v8 destination endpoint or signal_overrides.metrics.endpoint.
—cli/defenseclaw/observability/v8_migration.py — Converts captured v7 signal-specific endpoints into canonical v8 destinations
internal/config/config.go — Reads signal-specific endpoints only inside the legacy configuration loader
DEFENSECLAW_OTEL_METRICS_PROTOCOL—unsetgrpc, grpc/protobuf, http, http/protobuf, http/json, unsetUpgrade-only v7 migration input for the former metric-specific OTLP protocol.
Fix: Configure the protocol on the canonical v8 destination.
—cli/defenseclaw/observability/v8_migration.py — Converts captured v7 signal-specific protocols into canonical v8 destinations
internal/config/config.go — Reads signal-specific protocols only inside the legacy configuration loader
DEFENSECLAW_OTEL_PROTOCOL—unsetgrpc, grpc/protobuf, http, http/protobuf, http/json, unsetUpgrade-only v7 migration input for the former flat OTLP exporter protocol.
Fix: Configure observability.destinations[].protocol in config v8.
—cli/defenseclaw/observability/v8_migration.py — Converts the captured v7 protocol into a canonical v8 destination
internal/config/config.go — Reads the protocol only inside the legacy configuration loader
DEFENSECLAW_OTEL_TRACES_ENDPOINT—unsetany-otlp-endpoint, unsetUpgrade-only v7 migration input for the former trace-specific OTLP endpoint.
Fix: Configure a v8 destination endpoint or signal_overrides.traces.endpoint.
—cli/defenseclaw/observability/v8_migration.py — Converts captured v7 signal-specific endpoints into canonical v8 destinations
internal/config/config.go — Reads signal-specific endpoints only inside the legacy configuration loader
DEFENSECLAW_OTEL_TRACES_PROTOCOL—unsetgrpc, grpc/protobuf, http, http/protobuf, http/json, unsetUpgrade-only v7 migration input for the former trace-specific OTLP protocol.
Fix: Configure the protocol on the canonical v8 destination.
—cli/defenseclaw/observability/v8_migration.py — Converts captured v7 signal-specific protocols into canonical v8 destinations
internal/config/config.go — Reads signal-specific protocols only inside the legacy configuration loader
DEFENSECLAW_RUN_ID—auto-generated UUID at gateway bootany-string, unsetCorrelation ID stamped on every event for cross-sink joins.—internal/gatewaylog/runid.go — Go reader
internal/audit/store.go — Audit store reader
internal/gateway/sidecar.go — Sidecar boot
cli/defenseclaw/logger.py — Python logger reader
cli/defenseclaw/db.py — Python DB reader
scripts/test-e2e-full-stack.sh — E2E test runner default
DEFENSECLAW_TELEMETRY_ENABLED—unset1, 0, unsetLocal-observability-stack-only toggle.—bundles/local_observability_stack/docker-compose.yml — Compose-file env reference
DEFENSECLAW_TRACEPARENT—unset (no traceparent forwarded)W3C traceparent string, unsetW3C traceparent header value propagated from the agent/hook environment into outbound hook HTTP requests and the Codex telemetry bridge, enabling distributed-trace correlation.—internal/cli/hook.go — Native hook reads it (precedence over TRACEPARENT / OTEL_TRACEPARENT)
internal/gateway/connector/hooks/_hardening.sh — Bash hook trace-context extraction
internal/gateway/connector/codex.go — Codex telemetry bridge forwards it on outbound curls
DEFENSECLAW_TRACESTATE—unset (no tracestate forwarded)W3C tracestate string, unsetW3C tracestate header value propagated alongside traceparent for vendor-specific trace baggage on hook and Codex telemetry outbound requests.—internal/cli/hook.go — Native hook reads it alongside traceparent
internal/gateway/connector/hooks/_hardening.sh — Bash hook trace-context extraction
internal/gateway/connector/codex.go — Codex telemetry bridge forwards it on outbound curls

Debug / verbose logging

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_DEBUGlowunset1, unsetGateway client logs every request/response frame to stderr.—internal/gateway/client.go — Client struct gates verbose logging on this var
DEFENSECLAW_JUDGE_TRACEmediumunset1, true, unsetLLM judge logs every prompt + response.—internal/gateway/llm_judge.go — Judge debug toggle
DEFENSECLAW_LLM_DEBUGmediumunset1, true, unsetPython LLM bridge logs per-request prompt + response bodies.—cli/defenseclaw/llm.py — LLM bridge _DEBUG flag
DEFENSECLAW_NO_UPDATE_CHECK—unset1, unsetTurns off the once-a-day 'new release available' notice in the CLI and TUI.—cli/defenseclaw/update_notice.py — Skips the latest-release lookup and notice
DEFENSECLAW_PERSIST_JUDGEmediumunset1, true, unsetPersist every judge prompt + response to disk under data_dir.—internal/gateway/sidecar.go — Gateway boot enables judge persistence
DEFENSECLAW_SIDECAR_DIAGlowunset1, true, unsetExtra sidecar boot-time diagnostics (config dump, env presence).—internal/cli/sidecar.go — sidecarDiagEnabled helper
DEFENSECLAW_TUI_SKIP_FIRST_RUN_PROMPT—unset (prompt shown on a TTY)1, true, yes, unsetSkip the interactive first-run setup wizard prompt when launching the TUI, proceeding directly without asking whether to run setup.—cli/defenseclaw/tui/__init__.py — Gates the interactive first-run setup prompt
DEFENSECLAW_WEBHOOK_DEBUGmediumunset1, unsetWebhook dispatcher dumps full request bodies (including secrets) to stderr.—internal/gateway/webhook.go — Webhook sender debug field

Discovery & probes

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_ANTHROPIC_PROBE_MODEL—claude-3-5-haiku-latestany-anthropic-model-idOverride the model used by 'defenseclaw doctor' to probe Anthropic API key validity.—cli/defenseclaw/commands/cmd_doctor.py — Doctor's Anthropic probe
DEFENSECLAW_TRUSTED_BIN_PREFIXESmediumunset (built-in defaults only)os.pathsep-separated absolute paths (':' POSIX, ';' Windows), unsetExtra trusted binary prefixes for AI Discovery's binary probing, separated by os.pathsep (':' on POSIX, ';' on Windows).Tight binary-discovery trust list — prevents PATH-shadow elevation where a malicious binary in a user-writable dir gets probed and treated as a real agent runtime. 'trusted-paths add' refuses world-writable and non-absolute directories unless --force.cli/defenseclaw/inventory/agent_discovery.py — Agent discovery binary probe
cli/defenseclaw/commands/cmd_setup.py — setup trusted-paths CLI and inline trust prompt persistence

Hook-internal (do not override)

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_AGENT_ID—(set by plugin / hooks)any-stringAgent identity propagated through correlation headers and OTel attributes.—internal/cli/scan_v7.go — Go reader
extensions/defenseclaw/src/__tests__/agent_identity.test.ts — JS plugin reader (tested)
DEFENSECLAW_AGENT_INSTANCE_ID—(set by plugin / hooks)any-stringPer-instance agent identifier; used to disambiguate concurrent runs of the same agent.—internal/cli/scan_v7.go — Go reader
DEFENSECLAW_AGENT_NAME—(set by plugin / hooks)any-stringHuman-readable agent name propagated via correlation headers.—extensions/defenseclaw/src/index.ts — JS plugin header emit
DEFENSECLAW_BAKED_HOOK_PATHmediumempty (default PATH=/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin)colon-separated absolute paths, unsetBaked into the installed _hardening.sh helper at hook-generation time.Hook PATH lockdown — a mis-baked value that widens PATH could re-admit attacker-writable directories to hook execution.internal/gateway/connector/hooks/_hardening.sh — defenseclaw_harden_env() uses it to set the locked-down hook PATH
DEFENSECLAW_CLAWHUB_CWD—unset (set by the ClawHub launcher adapter on Windows)absolute directory pathWorking directory used by the temporary Windows ClawHub command adapter.—cli/defenseclaw/commands/cmd_skill.py — Windows ClawHub command adapter publishes the selected launch directory to its generated batch file
DEFENSECLAW_CLAWHUB_LAUNCHER—unset (set by the ClawHub launcher adapter on Windows)absolute path to a .cmd or .bat launcherAbsolute path to the trusted ClawHub .cmd or .bat launcher passed to the temporary Windows command adapter.—cli/defenseclaw/commands/cmd_skill.py — Windows ClawHub command adapter publishes the selected trusted launcher to its generated batch file
DEFENSECLAW_CLEANUP_ACK—unset (set and overwritten by native Setup)absolute installer-cache acknowledgement path, unsetCanonical InstallerCache cleanup acknowledgement path used by the bounded post-exit finalizer.—cmd/defenseclaw-setup/deferred_uninstall_cleanup_windows.go — Post-exit finalizer locks and validates the exact cleanup acknowledgement before removing authenticated installer residue
DEFENSECLAW_CLEANUP_JOURNAL—unset (set and overwritten by native Setup)absolute setup-journal path, unsetProtected native Setup transaction journal used to bind delayed directory cleanup to the uninstall transaction that scheduled it.—cmd/defenseclaw-setup/platform_windows.go — Delayed cleanup helper re-reads and locks the journal before deleting its owned target
DEFENSECLAW_CLEANUP_PARENT_PID—unset (set and overwritten by native Setup)decimal process id, unsetParent process identifier awaited by the bounded delayed InstallerCache cleanup helper.—cmd/defenseclaw-setup/platform_windows.go — Delayed cleanup helper waits for the originating Setup process before acquiring the setup mutex
DEFENSECLAW_CLEANUP_TARGET—unset (set and overwritten by native Setup)absolute installer-cache path, unsetCanonical InstallerCache directory considered for delayed removal.—cmd/defenseclaw-setup/platform_windows.go — Delayed cleanup helper receives the exact cache target
DEFENSECLAW_CLEANUP_TRANSACTION_ID—unset (set and overwritten by native Setup)setup transaction identifier, unsetExact native Setup uninstall transaction identifier expected by the delayed directory cleanup helper.—cmd/defenseclaw-setup/platform_windows.go — Delayed cleanup helper refuses deletion when the protected journal belongs to another transaction
DEFENSECLAW_CLEANUP_WAIT_MS—unset (set and overwritten by native Setup)non-negative decimal milliseconds, unsetBounded parent-process wait duration for the native Setup delayed directory cleanup helper.—cmd/defenseclaw-setup/platform_windows.go — Delayed cleanup helper exits without deletion if the originating Setup process does not stop within this bound
DEFENSECLAW_CLIENT—(set by plugin)any-stringClient name (e.g. openclaw-plugin) stamped on the X-DefenseClaw-Client correlation header.—extensions/defenseclaw/src/policy/enforcer.ts — Enforcer header
DEFENSECLAW_CONNECTOR—unsetnormalized connector identifier, unsetRuntime selector for the connector that owns an invocation of the shared hook scripts.—internal/gateway/connector/hooks/_hardening.sh — Selects one unambiguous connector runtime record for shared hooks
internal/gateway/connector/subprocess.go — Writes and validates the connector-scoped runtime sidecar
DEFENSECLAW_DAEMON—(set by daemon launcher; child only)1Sentinel set by the daemon launcher in the child process so it knows it's the daemon.—internal/daemon/daemon.go — EnvDaemon constant
DEFENSECLAW_DATA_DIR—unset (set by the daemon on child processes)absolute data-directory pathMarker injected by the daemon launcher into the spawned gateway child process environment, recording which data directory that child belongs to.—internal/daemon/daemon.go — Written into the gateway child env to tag the owning data directory
DEFENSECLAW_EGRESS_BYPASS—(set by DefenseClaw in the sandbox)comma-separated host list, unsetComma-separated hosts that bypass the DefenseClaw egress proxy inside a sandbox (the hook ingress and credentialed provider hosts, where OpenShell injects credentials).—internal/openshell/sandbox_env.go — Go constant used when building the sandbox environment
internal/openshell/harness/harness.go — SetNoProxy sets it with NO_PROXY; the harness launchers export NO_PROXY from it
DEFENSECLAW_EGRESS_URLlow(set by DefenseClaw in the sandbox)http:// proxy URL, unsetDefenseClaw egress proxy URL (http://<per-sandbox credential>@host.openshell.internal:<egress_port>) set inside every open or balanced sandbox.Carries the sandbox's egress proxy credential. Never log or persist the value.internal/openshell/sandbox_env.go — Go constant used when building the sandbox environment
internal/openshell/harness/harness.go — Spec.Env sets it; the harness launchers export the proxy variables from it
internal/openshell/harness/shellenv.go — egressEnvScript exports the proxy variables from it for the launchers, login shells and sandbox exec
DEFENSECLAW_FOREIGN_GUARD—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the administrator-owned defenseclaw-hook path baked in at render time, which the script asks for the foreign-hook decision before each Hermes pre_tool_call and at on_session_start.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_GATEWAY_ADDR—127.0.0.1:<api_port>loopback host:port, unsetGateway API address for the Windows native Go hook entrypoint.Loopback-only enforcement — a non-loopback gateway address is rejected so a hook cannot be redirected to an off-box collector.internal/cli/hook.go — Primary env resolution of the hook's gateway API address
internal/cli/hook.go — Sidecar .hookcfg fallback for the same key
DEFENSECLAW_GUARD_AGENT_HOME—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the agent's own HOME, captured before the script hardens its environment, so the foreign-hook check reads the Hermes config the agent reads.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hooks/hermes-hook.sh — Captured at the top of the standalone Hermes hook
DEFENSECLAW_GUARD_CAUSE—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: why the foreign-hook check gave no decision (its exit status, no answer, or an answer DefenseClaw could not read), named in the block message.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_GUARD_EVENT—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the Hermes event name read from the hook payload, which selects whether the foreign-hook check runs.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_GUARD_OUTPUT—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the Hermes block object printed when the foreign-hook check denies the call.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_GUARD_REASON—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the reason code of a foreign-hook denial, logged and printed on stderr.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_GUARD_RESULT—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the JSON answer of defenseclaw-hook --foreign-hook-check; only an explicit allow answer (deny false) continues to the gateway.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_GUARD_SESSION—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the Hermes session id read from the hook payload, sent with the block to the gateway's foreign-hook session route when the check gave no decision.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_GUARD_STATUS—unsetset by the scriptShell variable of the standalone Linux and macOS hermes-hook.sh: the exit status of defenseclaw-hook --foreign-hook-check, named in the block message when the check gave no decision.Assigned by the script before it is read, so a value in the agent's environment has no effect.internal/gateway/connector/hermes_foreign_guard.go — Foreign-hook guard block rendered into hermes-hook.sh
DEFENSECLAW_HOOK_CONNECTOR—(set by hooks)claudecode, codex, openclaw, zeptoclaw, inspect, ...Internal label identifying which connector's hook is executing.—internal/gateway/connector/hooks/inspect-tool.sh — Each hook exports this
DEFENSECLAW_HOOK_CWD—(set by hooks)absolute-pathResolved CWD exported by hooks; used by sanitizeHookCWD to bound git operations.—internal/gateway/connector/hooks/_hardening.sh — Hook hardening
DEFENSECLAW_HOOK_HOME—(set by hooks)absolute-pathHardened HOME exported by hooks to insulate them from operator HOME.—internal/gateway/connector/hooks/_hardening.sh — Hook hardening
DEFENSECLAW_HOOK_MAX_BODYlow1048576positive integerRequest-body cap (in bytes) for hooks.—internal/gateway/connector/hooks/_hardening.sh — Body-cap enforcement
DEFENSECLAW_HOOK_NAME—(set by hooks)inspect-tool, inspect-request, ...Internal label identifying which hook is executing.—internal/gateway/connector/hooks/inspect-tool.sh — Each hook exports this
DEFENSECLAW_HOOK_PATH—(set by hooks)colon-separated pathsHardened PATH exported by hooks (system-only) so a hostile workspace can't shadow git/curl/etc.—internal/gateway/connector/hooks/_hardening.sh — Hook hardening
DEFENSECLAW_HOOK_PATH_TRUSTED—unset (always stripped before PATH lockdown)unsetCompanion name to DEFENSECLAW_HOOK_PATH that an agent process might set.Hook PATH lockdown — stripped so an agent-supplied 'trusted' flag cannot re-enable an attacker-controlled PATH.internal/gateway/connector/hooks/_hardening.sh — unset DEFENSECLAW_HOOK_PATH_TRUSTED during env hardening (anti-consumed)
DEFENSECLAW_HOOK_SOCKET—(rendered by setup for standalone Unix installs that name a hook socket; absent everywhere else)absolute-pathPath of the standalone gateway's peer-authorized unix hook socket, assigned inside a rendered standalone Unix hook (connector shell hooks and the Codex notify bridge) before the socket and its directory owners are checked and the request is sent with curl --unix-socket.—internal/gateway/connector/hook_socket_transport.go — Shell transport block that assigns and verifies the socket path
DEFENSECLAW_HOOK_SOCKET_UID—(rendered by setup next to DEFENSECLAW_HOOK_SOCKET)uidGateway service account uid that a rendered standalone Unix hook accepts, besides root, as the owner of the hook socket and its directory.—internal/gateway/connector/hook_socket_transport.go — Shell transport block owner check
DEFENSECLAW_HOST_TZ—(set by DefenseClaw in the sandbox)IANA zone name, unsetIANA time zone of the machine a sandbox was created from (America/New_York), set inside every OpenShell sandbox by sandbox run.—internal/openshell/timezone.go — Go constant and the host's zone the CLI sends with a create
internal/openshell/harness/shellenv.go — timeZoneScript: the in-image shells export TZ from it
DEFENSECLAW_INTERNAL_HOOK_DELEGATIONHIGHunset (set and overwritten by the stable hook launcher on Windows)v2:<inherited parent handle>:<32-hex transaction id>:<64-hex hook SHA-256>, unsetCarries the parent-owned proof for a stable hook launcher to delegate to the exact full-hook generation it already admitted.Private parent-to-child hook admission proof only. The environment value has no authority without the inherited live-process handle, canonical launcher identity, protected state, and exact transaction and digest match.internal/hookruntime/delegation_windows.go — Binds the delegated child to its live canonical launcher parent and the exact protected runtime generation before reusing the parent-completed full-image admission
DEFENSECLAW_MANAGED_HOOKHIGHunset (set to 1 only by generated managed hooks)1, unsetImmutable sentinel baked into managed-enterprise hook scripts so missing authentication material and unavailable enforcement fail closed even when an inherited environment requests permissive availability behavior.Managed enforcement fail-closed boundary — the value is generated by the privileged hook installer and is not an operator security opt-out.internal/gateway/connector/hooks/_hardening.sh — Managed shell-hook wrappers set and export the sentinel before sourcing this shared runtime, whose missing-token and transport-failure branches then force fail-closed behavior
DEFENSECLAW_OPENCLAW_MAINlow(set by plugin bootstrap)absolute-pathSentinel read by the OpenClaw plugin bootstrapper to locate its main module.—extensions/defenseclaw/src/aws-sdk-http1-for-guardrail.ts — Plugin bootstrap sentinel
DEFENSECLAW_PLUGIN_AGENT_ID—(set by plugin)any-stringPlugin-side agent ID.—extensions/defenseclaw/src/__tests__/agent_identity.test.ts — JS plugin reader (tested)
DEFENSECLAW_SANDBOX_IDmedium(set by DefenseClaw in the sandbox)opaque DefenseClaw binding id, unsetThe sandbox's DefenseClaw ingress binding id, which the sandbox manager sets inside every sandbox it launches, through the harness spec's environment.
Fix: Unset it outside a DefenseClaw sandbox.
Sandbox bypass: while set, sandbox run and the shell wrappers run the harness natively on the host, as DEFENSECLAW_NO_SANDBOX does, without a notice. DefenseClaw sets it only inside the sandboxes it launches and refuses it from .env files, so a value on the host was planted or leaked.internal/openshell/sandbox_env.go — Go constant used when building the sandbox environment
internal/openshell/harness/harness.go — Spec.Env passes it to the sandbox so nested DefenseClaw invocations can detect the sandbox
cli/defenseclaw/main.py — Lets a nested defenseclaw sandbox run reach the gateway stub without a config, as in Go
cli/defenseclaw/commands/cmd_doctor.py — Doctor reports a set value as a security override (any non-empty value is active)
DEFENSECLAW_SANDBOX_NAME—(set by DefenseClaw in the sandbox)sandbox name, unsetHuman-readable DefenseClaw sandbox name that the sandbox manager sets inside every sandbox it launches, through the harness spec's environment.—internal/openshell/sandbox_env.go — Go constant used when building the sandbox environment
internal/openshell/harness/harness.go — Spec.Env passes it to the sandbox for attribution
DEFENSECLAW_SIDECAR_INSTANCE_ID—(auto-generated by gateway)uuid-or-similarSidecar instance ID; auto-generated by the gateway at boot, propagated via headers.—internal/cli/scan_v7.go — Go reader
DEFENSECLAW_SSH_SHIM_PROBE—unset (set only for the probe run)probe token, unsetSet by DefenseClaw only for the one probe run of the ssh shim it puts first on the OpenShell CLI's PATH: the shim prints the value and exits without running ssh, which proves a PATH search finds and executes it.—internal/openshell/sshshim.go — Shim probe: set for the probe run, stripped from the OpenShell CLI's environment
internal/openshell/sshshim_test.go — Tests the probe answer and that the CLI never sees it
DEFENSECLAW_WINDOWS_APPROVED_AGENT_CLIENTS_ENFORCEDHIGHunset (optional application-control posture is not attested)1, unsetCarry protected installer evidence that optional application control restricts every enabled enterprise agent client to approved binaries.Authenticated service evidence — only the signed installer may publish this marker after live WDAC or AppLocker certification. Its absence does not block managed-hook installation or reconciliation.internal/cli/windows_codex_requirements.go — Reports optional approved-agent application-control evidence
packaging/windows/DefenseClawEnterprise.psm1 — Pins the authenticated attestation in each protected service environment when supplied
DEFENSECLAW_WINDOWS_CLAUDE_EFFECTIVE_POLICY_VERIFIEDHIGHunset (effective policy is unverified)1, unsetCarry protected installer evidence that DefenseClaw is Claude Code's effective first-source-wins managed policy.Authenticated service evidence — protected local policy bytes alone do not establish which Claude managed-policy source is effective.internal/cli/windows_codex_requirements.go — Includes Claude effective-policy evidence in the aggregate Windows enterprise report
packaging/windows/DefenseClawEnterprise.psm1 — Pins fresh effective-policy certification in each protected service environment
DEFENSECLAW_WINDOWS_CODEX_APPROVED_CLIENT_ENFORCEDHIGHunset1, unsetRetain the protected Codex-specific compatibility alias for the all-agent application-control attestation.Compatibility-only service claim — it is not a substitute for DEFENSECLAW_WINDOWS_APPROVED_AGENT_CLIENTS_ENFORCED or live application-control certification.packaging/windows/DefenseClawEnterprise.psm1 — Publishes the compatibility claim alongside the authoritative approved-agent marker
DEFENSECLAW_WINDOWS_UNINSTALL_PURGE_USER_STATEmediumunset (the finalize only names each per-user folder)1, unsetTell the standalone Windows managed-hook teardown finalize that the uninstall purges, so it also removes each enrolled account's per-user DefenseClaw folder.Lifecycle-owned helper switch: the lifecycle sets or clears it for every helper it runs, so a caller's inherited value never reaches the finalize.internal/cli/windows_managed_hooks_teardown.go — Removes each enrolled account's %USERPROFILE%.defenseclaw as LocalSystem after a committed uninstall with purge
packaging/windows/DefenseClawEnterprise.psm1 — Sets it for the helpers of a standalone uninstall with purge and clears it for every other helper run

Upgrade-internal (do not override)

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_ANTIGRAVITY_CONFIG_HOMEmediumunsetabsolute normalized path selected by the Setup transaction, unsetCarries the exact Antigravity configuration home already captured and validated by the native Windows Setup transaction into its isolated connector maintenance child.Trusted Setup custody binding only. This is not an Antigravity vendor environment variable and must never be used for ordinary Antigravity discovery.cmd/defenseclaw-setup/transaction.go — Filters ambient copies and passes only the transaction-bound Antigravity home to connector lifecycle children
cmd/defenseclaw-setup/main.go — Requires one absolute normalized value and converts it to the hidden --config-home argument
DEFENSECLAW_CURSOR_CONFIG_HOMEmediumunsetabsolute normalized path selected by the Setup transaction, unsetCarries the exact Cursor configuration home already captured and validated by the native Windows Setup transaction into its isolated connector maintenance child.Trusted Setup custody binding only. This is not a Cursor vendor environment variable and must never be used for ordinary Cursor discovery.cmd/defenseclaw-setup/transaction.go — Filters ambient copies and passes only the transaction-bound Cursor home to connector lifecycle children
cmd/defenseclaw-setup/main.go — Requires one absolute normalized value and converts it to the hidden --config-home argument
DEFENSECLAW_DEVIN_CONFIG_HOMEmediumunsetabsolute normalized path selected by the Setup transaction, unsetCarries the exact Devin configuration directory captured and validated by the native Windows Setup transaction into isolated connector maintenance children.Private authenticated lifecycle binding only. This is not a Devin vendor environment variable and has no authority unless it came from protected native install state or the Setup transaction.cmd/defenseclaw-setup/transaction.go — Scrubs ambient copies and passes only the transaction-bound Devin configuration directory to connector lifecycle children
cmd/defenseclaw-setup/main.go — Requires one absolute normalized value and converts it to the hidden --config-home argument
internal/nativeinstallstate/state.go — Rehydrates the authenticated Devin configuration directory for direct gateway and launcher recovery
DEFENSECLAW_DEVIN_EXECUTABLEHIGHunsetabsolute normalized current-user Devin executable admitted by Setup, unsetCarries the exact Devin executable selected and admitted by native Windows Setup through isolated maintenance and recovery child environments.Private authenticated executable binding only. It must remain tied to the exact signed Devin binary admitted by Setup and must never be treated as a general operator path override.cmd/defenseclaw-setup/transaction.go — Scrubs ambient copies and publishes only the Setup-admitted Devin executable to connector lifecycle children
internal/nativeinstallstate/state.go — Rehydrates the authenticated Devin executable from protected native install state
DEFENSECLAW_INSTALL_CALLER—unsetapp, unsetSet to app by the macOS app so install.sh does not quit or relaunch the running app itself.—scripts/install.sh — Skips quitting and relaunching the app
DEFENSECLAW_INTERNAL_SETUP_CONNECTORHIGHunsetantigravity, unsetIdentifies the connector selected by the packaged Windows Setup process for its private initialization child.Private paired Setup binding only. The value is not sufficient by itself: the child also requires DEFENSECLAW_INTERNAL_SETUP_PARENT to match the packaged Setup ancestor through the custody-bound installed launcher.cmd/defenseclaw-setup/main.go — Scrubs ambient copies and sets antigravity only for the packaged Setup initialization child
cli/defenseclaw/commands/cmd_init.py — Requires the exact connector value together with the verified installed-launcher and Setup parent chain before allowing the private Antigravity initialization
DEFENSECLAW_INTERNAL_SETUP_PARENTHIGHunsetabsolute path to the running DefenseClawSetup-x64.exe parent, unsetCarries the absolute path of the running packaged Windows Setup executable into its private initialization child.Private paired Setup binding only. This is not a public path override and must be accepted only when it names the packaged Setup process above the custody-bound installed launcher.cmd/defenseclaw-setup/main.go — Scrubs ambient copies, resolves the current Setup executable, and passes its exact path to the initialization child
cli/defenseclaw/commands/cmd_init.py — Requires an absolute DefenseClawSetup-x64.exe path that exactly matches the installed launcher's parent process image
DEFENSECLAW_REPO—cisco-ai-defense/defenseclawowner/nameGitHub owner/name whose releases defenseclaw upgrade and the installers use (for testing on a fork).—cli/defenseclaw/upgrade_shim.py — Release lookup and installer download
scripts/install.sh — Release asset downloads
scripts/defenseclaw-upgrade.sh — Latest-release lookup for the 0.8.x handoff
DEFENSECLAW_UPGRADE_FRESH_PROCESS—unset1, unsetSet by 0.8.x upgrade controllers on the processes they start.—cmd/defenseclaw-setup/main.go — Scrubs ambient delegation and scopes it only to an authenticated prior-gateway launch during durable transaction recovery
scripts/defenseclaw-upgrade.sh — Clears the 0.8.x controller marker before running the 1.x installer

Splunk-bridge bundle

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_HEC_TOKENHIGH(set in .env.example)hec-tokenSplunk-bridge HEC token.—bundles/splunk_local_bridge/env/.env.example — Bridge .env
DEFENSECLAW_HEC_URL—(set in .env.example)any-hec-urlSplunk-bridge bundle: HEC endpoint URL.—bundles/splunk_local_bridge/env/.env.example — Bridge .env
DEFENSECLAW_INDEX—defenseclaw_localsplunk-index-nameSplunk-bridge target index.—bundles/splunk_local_bridge/env/.env.example — Bridge .env
DEFENSECLAW_INTEGRATION_ENABLED—falsetrue, falseSplunk-bridge integration toggle.—bundles/splunk_local_bridge/env/.env.example — Bridge .env
DEFENSECLAW_O11Y_DASHBOARD_NAME_PREFIX—empty (no prefix)string, unsetPrefix label applied to the Splunk Observability dashboard groups, dashboards, and detectors created by the Terraform setup command.—cli/defenseclaw/commands/cmd_setup_splunk_o11y_dashboards.py — --name-prefix Click option bound to this env var
DEFENSECLAW_REF—unknownany-stringSplunk-bridge bundle git ref label.—bundles/splunk_local_bridge/env/.env.example — Bridge .env
DEFENSECLAW_SOURCE—defenseclawany-source-stringSplunk-bridge source label.—bundles/splunk_local_bridge/env/.env.example — Bridge .env
DEFENSECLAW_SOURCETYPE—defenseclaw:jsonsplunk-sourcetypeSplunk-bridge sourcetype.—bundles/splunk_local_bridge/env/.env.example — Bridge .env
DEFENSECLAW_SPLUNK_O11Y_DASHBOARDS_WORK_DIR—<data_dir>/splunk_o11y_dashboards/terraformabsolute directory path, unsetTerraform working directory for Splunk Observability dashboard provisioning.—cli/defenseclaw/commands/cmd_setup_splunk_o11y_dashboards.py — --work-dir Click option bound to this env var
DEFENSECLAW_TERRAFORM_PLUGIN_DIR—unset (no -plugin-dir passed to terraform init)absolute directory path, unsetOptional Terraform provider plugin directory for offline / cached provider installs when running 'defenseclaw setup splunk-o11y-dashboards'.—cli/defenseclaw/commands/cmd_setup_splunk_o11y_dashboards.py — --plugin-dir Click option bound to this env var

Test fixtures (test-only)

Env varImpactDefaultAccepted valuesPurposeSecurity concernConsumers
DEFENSECLAW_ATTRIBUTION_ROOT—unsetabsolute Windows path, unsetPasses a temporary attribution root path from the Windows guardian-attribution Go test harness to its PowerShell child processes so they resolve InstallRoot/StateRoot/ClaudeManagedPolicyPath under the test's t.TempDir() instead of the machine defaults.—cmd/defenseclaw/service_windows_test.go — The Windows guardian-attribution tests set the env var when launching PowerShell child processes so managed-path resolution happens under an isolated t.TempDir()
DEFENSECLAW_AUDIT_DB_LOCK_HELPER_PATH—unsetabsolute temporary database path, unsetPasses the temporary audit database path to isolated subprocesses that verify SQLite kernel-lock and WAL lifecycle behavior.—internal/audit/audit_db_lock_unix_test.go — Peer-process lock and SQLite-close fixtures; never read by production runtime paths
DEFENSECLAW_AUTHENTICODE_HELPER—unsettest-defined absolute path, unsetCarries the Authenticode PowerShell helper path to the native unsigned-PE regression fixture.—cli/tests/test_windows_installer_artifacts.py — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_BOUNDED_DIGEST_ROOT—unsetabsolute Windows path, unsetRoot directory the bounded artifact-digest test harness writes its managed.token fixture under.—cmd/defenseclaw/service_windows_test.go — Anchors the fixture the bounded artifact-digest certification test emits
DEFENSECLAW_CISCO_CA_BUNDLEHIGHunset<path to PEM bundle>, unsetCI/test-only trust-root override for the POSIX Cisco Authenticode signature check in packaging/scripts/lib/assert-cisco-signature.sh.—packaging/scripts/lib/assert-cisco-signature.sh — Passed to osslsigncode verify -CAfile when set (POSIX signature check)
.github/workflows/windows-deterministic-build.yml — Set to a disposable CA in the assemble-linux / assemble-macos jobs so a Cisco-CN dummy cert can pass the check for the byte-identity gate
DEFENSECLAW_CODEX_POLICY_ENTRY_PATH—unsetabsolute test marker path, unsetTest-only marker path used by the Codex effective-policy subprocess fixture to record helper entry.—internal/gateway/connector/codex_policy_test.go — Codex policy timeout/process-tree test fixture; never read by production runtime paths
DEFENSECLAW_CODEX_POLICY_GRANDCHILD_HELPER—unset1, unsetSelects the Codex policy grandchild fixture used to verify process-tree containment.—internal/gateway/connector/codex_policy_test.go — Test-only Codex policy grandchild helper
DEFENSECLAW_CODEX_POLICY_HANG_HELPER—unset1, unsetSelects the Codex policy subprocess fixture that deliberately blocks for timeout coverage.—internal/gateway/connector/codex_policy_test.go — Test-only Codex policy timeout helper
DEFENSECLAW_CODEX_POLICY_HELPER—unsettest-defined value, unsetSelects the isolated Codex effective-policy helper subprocess.—internal/gateway/connector/codex_policy_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_CODEX_POLICY_MARKER_PATH—unsetabsolute test marker path, unsetTest-only descendant marker path used by the Codex policy process-tree fixture.—internal/gateway/connector/codex_policy_test.go — Codex policy descendant-cleanup fixture
DEFENSECLAW_CODEX_POLICY_READY_PATH—unsetabsolute test marker path, unsetTest-only ready-signal path shared with the Codex policy process-tree fixture.—internal/gateway/connector/codex_policy_test.go — Codex policy process-tree readiness fixture
DEFENSECLAW_CODEX_POLICY_TREE_HELPER—unset1, unsetSelects the Codex policy subprocess-tree fixture used to verify descendant cleanup.—internal/gateway/connector/codex_policy_test.go — Test-only Codex policy process-tree helper
DEFENSECLAW_DEFERRED_RUN_HELPER_ACK—unsettest-defined absolute path, unsetCarries the acknowledgement path for the isolated deferred-cleanup Run launch fixture.—cmd/defenseclaw-setup/deferred_uninstall_cleanup_windows_test.go — Native Windows deferred-cleanup Run launch fixture; never read by production runtime paths
DEFENSECLAW_DEFERRED_RUN_HELPER_TRANSACTION—unsettest-defined lowercase 32-hex transaction identifier, unsetCarries the expected transaction identifier for the isolated deferred-cleanup Run launch fixture.—cmd/defenseclaw-setup/deferred_uninstall_cleanup_windows_test.go — Native Windows deferred-cleanup Run launch fixture; never read by production runtime paths
DEFENSECLAW_DEFERRED_RUN_ROOT—unsettest-defined absolute path, unsetSupplies the isolated cache root used to reproduce the former environment-based Run registration.—cmd/defenseclaw-setup/deferred_uninstall_cleanup_windows_test.go — Native Windows deferred-cleanup Run launch fixture; never read by production runtime paths
DEFENSECLAW_DEFERRED_VERIFY_PARENT_HELPER—unset1, unsetSelects the isolated parent-process helper used to verify stable deferred-cleanup process identity on Windows.—internal/cli/connector_deferred_verify_windows_test.go — Native Windows parent-process identity fixture; never read by production runtime paths
DEFENSECLAW_DELEGATION_ENV_SENTINEL—unsettest-defined value, unsetCarries an inherited environment sentinel through the isolated stable-hook delegation fixture.—internal/hookruntime/delegation_windows_test.go — Native Windows hook-delegation test fixture; never read by production runtime paths
DEFENSECLAW_E2E_CODEX_POLICY_HELPER—unset1, unsetSelects the bounded Codex app-server fixture used by native connector lifecycle E2E tests.—test/e2e/codex_policy_fixture_windows_test.go — Native Windows E2E Codex policy fixture
DEFENSECLAW_E2E_HARNESS—unsethermes, openhands, antigravity, omnigent, unsetNames the hook-only harness the live hook-only sandbox test drives (hermes, openhands, antigravity or omnigent); the test is skipped when it is unset.—test/e2e/openshell/hookonly_e2e_test.go — Live hook-only harness sandbox test (openshell_integration build tag, on branch test/openshell-live)
DEFENSECLAW_ENV_CONFIG_SKIP_TRUSTmediumunset (trust check enforced)1, unsetSkip the on-disk trust check LoadEnvConfigEndpoint enforces on the AVC-authored env_config.json: root ownership and no group/world write on Unix, administrator ownership across the ancestor chain on Windows.Bypassing the env_config file trust check lets a file at the canonical path that untrusted principals can write retarget bearer-authenticated inspection POSTs. Test-only.internal/config/env_config.go — trustEnvConfigFile short-circuits when set — production installs must leave this unset so a non-root-authored / group-writable env_config.json is refused
internal/config/env_config_windows.go — shouldEnforceEnvConfigTrust short-circuits when set, skipping the managed.ValidateTrustedFilePath ancestor walk
DEFENSECLAW_FAKE_CLAUDE_LIST—unsetcomma-separated mock responses, unsetTest-only stub: comma-separated list of responses the fake claude CLI returns.—internal/gateway/connector/codeguard_native_test.go — Test stub
DEFENSECLAW_FAKE_CLAUDE_LOG—unsetabsolute-path, unsetTest-only stub: path the fake claude CLI logs invocations to.—internal/gateway/connector/codeguard_native_test.go — Test stub
DEFENSECLAW_GATEWAY_CODEX_APP_SERVER_HELPER—unset1, unsetSelects the bounded Codex app-server fixture used by gateway package tests.—internal/gateway/codex_setup_fixture_windows_test.go — Native Windows gateway Codex policy fixture
DEFENSECLAW_GATEWAY_URL—unset (in-process e2e server)http(s) base URL e.g. http://127.0.0.1:18970, unsetBase URL of an external gateway for the security-suite e2e tier (TestSecuritySuiteE2E).—internal/gateway/security_suite_test.go — TestSecuritySuiteE2E reads this to locate the gateway; uses an in-process server when unset
DEFENSECLAW_HOOK_DELEGATED_ADMISSION_TEST_ROOT—unsettest-defined absolute directory path, unsetSelects the isolated protected runtime root for the delegated hook-admission helper subprocess.—internal/hookruntime/delegation_windows_test.go — Native Windows delegated-admission test fixture; never read by production runtime paths
DEFENSECLAW_HOOK_DELEGATION_TEST_HELPER—unset1, unsetSelects the isolated stable-hook delegation helper subprocess.—internal/hookruntime/delegation_windows_test.go — Native Windows hook-delegation test fixture; never read by production runtime paths
DEFENSECLAW_HOOK_TOKEN_LOCK_HELPER—unset1, unsetSelects the connector hook-token cross-process lock fixture.—internal/gateway/connector/hook_api_token_test.go — Connector hook-token lock fixture
DEFENSECLAW_HOOK_TOKEN_LOCK_PATH—unsetabsolute test lock path, unsetLock path passed to the connector hook-token cross-process fixture.—internal/gateway/connector/hook_api_token_test.go — Connector hook-token lock target
DEFENSECLAW_HOOK_TOKEN_LOCK_READY—unsetabsolute test marker path, unsetReady-signal path shared with the connector hook-token cross-process fixture.—internal/gateway/connector/hook_api_token_test.go — Connector hook-token lock readiness fixture
DEFENSECLAW_HOOK_TOKEN_LOCK_RELEASE—unsetabsolute test marker path, unsetRelease-signal path shared with the connector hook-token cross-process fixture.—internal/gateway/connector/hook_api_token_test.go — Connector hook-token lock release fixture
DEFENSECLAW_HTTP_COMMAND_INJECTION_BENIGN_CORPORA—unset (external corpus regression skipped)platform path-list of JSONL corpus files, unsetSupplies path-separated external benign corpus files to the optional ActionFacts HTTP command-injection false-positive regression.—internal/actionfacts/http_command_injection_test.go — Test-only external benign-corpus input; never read by production runtime paths
DEFENSECLAW_HTTP_COMMAND_INJECTION_CORPUS—unset (external corpus regression skipped)path to a JSONL corpus file, unsetSupplies an external public JSONL corpus to the optional ActionFacts HTTP command-injection closed-proof regression.—internal/actionfacts/http_command_injection_test.go — Test-only external public-corpus input; never read by production runtime paths
DEFENSECLAW_HTTP_SQLI_CORPUS—unset (external corpus regression skipped)path to a JSONL corpus file, unsetSupplies an external public JSONL corpus to the optional ActionFacts HTTP SQL-injection closed-proof regression.—internal/actionfacts/http_sql_injection_test.go — Test-only external public-corpus input; never read by production runtime paths
DEFENSECLAW_INSTALL_MANAGED_DESCRIPTOR—unset (Linux /etc/defenseclaw/managed-runtime.json; macOS /opt/cisco/defenseclaw/etc/managed-runtime.json)absolute path, unsetAdds a temporary managed runtime descriptor to the ones install.sh checks, so tests can prove the per-user installer refuses to run on a computer whose DefenseClaw is managed by the organization.Test-only. It can only add a descriptor path: install.sh always checks the platform descriptor as well, so setting it never skips the managed-host refusal.scripts/install.sh — Refuses a per-user install when the managed runtime descriptor exists
DEFENSECLAW_JUDGE_BENCHMARK_API_KEY_ENV—unsetenvironment-variable name, unsetNames the credential environment variable used by the opt-in judge benchmark provider.—internal/gateway/llm_judge_corpus_benchmark_test.go — Passes a credential variable name, never a credential value
DEFENSECLAW_JUDGE_BENCHMARK_BASE_URL—http://127.0.0.1:11434http(s) URL, unsetOverrides the local OpenAI-compatible endpoint used by the opt-in judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark provider endpoint; never read by the production gateway
DEFENSECLAW_JUDGE_BENCHMARK_BEDROCK_ACCESS_KEY_ENV—AWS_ACCESS_KEY_IDenvironment-variable name, unsetNames the AWS access-key environment variable for an opt-in Bedrock judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Passes a credential variable name, never a credential value
DEFENSECLAW_JUDGE_BENCHMARK_BEDROCK_AUTH_MODE—profileprofile, iam, api-key, unsetSelects the credential-resolution mode for an opt-in Bedrock judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in Bedrock benchmark authentication mode
DEFENSECLAW_JUDGE_BENCHMARK_BEDROCK_PROFILE—AWS_PROFILE, otherwise default in the convenience wrapperAWS profile name, unsetSelects the local AWS profile for an opt-in Bedrock judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in Bedrock benchmark profile name
DEFENSECLAW_JUDGE_BENCHMARK_BEDROCK_REGION—us-east-1AWS region, unsetSelects the AWS region for an opt-in Bedrock judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in Bedrock benchmark region
DEFENSECLAW_JUDGE_BENCHMARK_BEDROCK_SECRET_KEY_ENV—AWS_SECRET_ACCESS_KEYenvironment-variable name, unsetNames the AWS secret-key environment variable for an opt-in Bedrock judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Passes a credential variable name, never a credential value
DEFENSECLAW_JUDGE_BENCHMARK_BEDROCK_SESSION_TOKEN_ENV—AWS_SESSION_TOKENenvironment-variable name, unsetNames the AWS session-token environment variable for an opt-in Bedrock judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Passes a credential variable name, never a credential value
DEFENSECLAW_JUDGE_BENCHMARK_CONCURRENCY—1integer 1 through 64, unsetBounds parallel provider calls in the opt-in production-path judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark worker count
DEFENSECLAW_JUDGE_BENCHMARK_CORPUS—unsetpath to an operator-supplied benchmark corpus, unsetSelects the normalized case-v1 JSONL input for an explicitly enabled production-path judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark input; never read by the production gateway
DEFENSECLAW_JUDGE_BENCHMARK_MODEL—unsetprovider/model identifier, unsetSelects the provider-qualified model for an explicitly enabled production-path judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark model selection; never read by the production gateway
DEFENSECLAW_JUDGE_BENCHMARK_OUTPUT—unsetpath inside an operator-controlled benchmark output directory, unsetSelects the value-free prediction output path for an explicitly enabled production-path judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark output; never read by the production gateway
DEFENSECLAW_JUDGE_BENCHMARK_RESUME—unset1, unsetResumes an opt-in judge benchmark from a validated output prefix.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark prefix-resume control
DEFENSECLAW_JUDGE_BENCHMARK_RETRY_FAILURES—unset1, unsetDrops the first failed prediction and its suffix before resuming an opt-in judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark retry control
DEFENSECLAW_JUDGE_BENCHMARK_RULE_PACK—policies/guardrail/defaultrule-pack directory, unsetOverrides the rule-pack directory loaded by the opt-in production-path judge benchmark.—internal/gateway/llm_judge_corpus_benchmark_test.go — Opt-in benchmark rule-pack selection; never read by the production gateway
DEFENSECLAW_LAUNCHER_LOGICAL_CWD—unsettest-defined value, unsetCarries the expected logical working directory to the long-CWD launcher fixture.—cmd/defenseclaw-launcher/long_cwd_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_LAUNCHER_LONG_CWD_HELPER—unsettest-defined value, unsetSelects the isolated long-CWD launcher helper subprocess.—cmd/defenseclaw-launcher/long_cwd_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_LEAK—unset1, unsetMarker a test sets in its own environment to prove that Unix agent discovery does not run the agent executable, or pass the caller's environment to it, without allowExec.—internal/enterprisehooks/enumerator_unix_test.go — Test-only environment leak marker for agent discovery
DEFENSECLAW_LEAK_CHECK—unsetany-string, unsetMarker a test sets in its own environment to prove that the trusted directory-tool runner starts its command with a clean environment.—internal/unixidentity/identity_test.go — Test-only environment leak marker for the directory tool runner
DEFENSECLAW_LEDGER_ROOT—unsetabsolute Windows path, unsetState-root anchor for the Windows guardian semantic-ledger test harness.—cmd/defenseclaw/service_windows_test.go — Anchors the semantic-ledger StateRoot in the guardian-semantic tests
DEFENSECLAW_LONG_PATH_HELPER—unsettest-defined value, unsetSelects the isolated native Setup long-path helper subprocess.—cmd/defenseclaw-setup/long_path_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_MANAGED_BREAKAWAY_CHILD—unset1, unsetSelects the detached managed-breakaway child subprocess fixture.—internal/processutil/command_windows_test.go — Native Windows process-tree test fixture; never read by production runtime paths
DEFENSECLAW_MANAGED_BREAKAWAY_HELPER—unset1, unsetSelects the managed-breakaway parent subprocess fixture.—internal/processutil/command_windows_test.go — Native Windows process-tree test fixture; never read by production runtime paths
DEFENSECLAW_MCPHUNT_PUBLIC_DIR—unset (external corpus regression skipped)absolute directory path containing JSON result files, unsetSupplies an external public MCPHunt result directory to the optional SQL value-lineage format regression.—internal/gateway/tool_value_lineage_sql_test.go — Test-only external public-result input; never read by production runtime paths
DEFENSECLAW_PROCESSUTIL_INHERITED_OUTPUT_CHILD—unset1, unsetSelects the inherited-output descendant subprocess fixture.—internal/processutil/command_windows_test.go — Native Windows inherited-output test fixture; never read by production runtime paths
DEFENSECLAW_PROCESSUTIL_INHERITED_OUTPUT_HELPER—unset1, unsetSelects the inherited-output parent subprocess fixture.—internal/processutil/command_windows_test.go — Native Windows inherited-output test fixture; never read by production runtime paths
DEFENSECLAW_PROCESS_TREE_GRANDCHILD—unset1, unsetSelects the process-tree grandchild subprocess fixture.—internal/processutil/command_windows_test.go — Native Windows process-tree test fixture; never read by production runtime paths
DEFENSECLAW_PROCESS_TREE_HELPER—unset1, unsetSelects the process-tree parent subprocess fixture.—internal/processutil/command_windows_test.go — Native Windows process-tree test fixture; never read by production runtime paths
DEFENSECLAW_PROCESS_TREE_MARKER—unsetabsolute test marker path, unsetMarker path written by the managed-breakaway process-tree fixture.—internal/processutil/command_windows_test.go — Native Windows process-tree test fixture; never read by production runtime paths
DEFENSECLAW_PROCESS_TREE_PID_FILE—unsetabsolute test PID path, unsetPID-record path shared with the process-tree cancellation fixture.—internal/processutil/command_windows_test.go — Native Windows process-tree test fixture; never read by production runtime paths
DEFENSECLAW_REQUIRE_PARTITION_MANIFESTS—unset (partition metadata optional in the external regression)1, unsetRequires partition metadata when the external strict normalization-manifest regression is enabled.—benchmarks/internal/benchmark/manifest_external_test.go — Test-only strict partition-manifest assertion; never read by production runtime paths
DEFENSECLAW_SANDBOX_RENDER_DIR—unsetabsolute-path, unsetNames a directory TestSandboxArtifactsGolden writes each harness's rendered sandbox overlay under (<dir>/<connector>/<in-image path>), so a manifest drift can be reviewed by diffing the trees two revisions render.—internal/gateway/connector/sandbox_artifacts_test.go — Writes the rendered sandbox artifacts for review
DEFENSECLAW_SENSOR_HELPER_TEST_PROCESS—unset1, unsetTurns the sensor-helper test binary into the helper itself when a version test re-runs it to check --version and the flag handling of main().—cmd/defenseclaw-sensor-helper/version_test.go — Test-only child-process selector for the sensor-helper version tests
DEFENSECLAW_SETUP_CANCEL_TEST_HELPER—unset1, unsetSelects the parent-cancellation native Setup helper subprocess.—cmd/defenseclaw-setup/main_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_SETUP_LOCK_TEST_HELPER—unsettest-defined value, unsetSelects the cross-process native Setup mutex fixture.—cmd/defenseclaw-setup/setup_lock_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_SETUP_MAINTENANCE_TEST_HELPER—unset1, unsetSelects the isolated native Setup maintenance-gateway helper subprocess.—cmd/defenseclaw-setup/maintenance_gateway_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_SETUP_SERVICE_CONTROL_TEST_HELPER—unset1, unsetSelects the isolated native Setup gateway and watchdog stop-command helper subprocess.—cmd/defenseclaw-setup/maintenance_gateway_windows_test.go — Native Windows service-control test fixture; never read by production runtime paths
cmd/defenseclaw-setup/recovery_windows_test.go — Enables the delayed owned-process exit regression fixture
DEFENSECLAW_SETUP_TEST_GATEWAY_STOP—unsettest-defined absolute path, unsetCarries the absolute stop-marker path for the delayed native Setup gateway-exit fixture.—cmd/defenseclaw-setup/maintenance_gateway_windows_test.go — Writes the gateway stop marker from the isolated control subprocess
cmd/defenseclaw-setup/recovery_windows_test.go — Supplies the private gateway stop-marker path
DEFENSECLAW_SETUP_TEST_WATCHDOG_STOP—unsettest-defined absolute path, unsetCarries the absolute stop-marker path for the delayed native Setup watchdog-exit fixture.—cmd/defenseclaw-setup/maintenance_gateway_windows_test.go — Writes the watchdog stop marker from the isolated control subprocess
cmd/defenseclaw-setup/recovery_windows_test.go — Supplies the private watchdog stop-marker path
DEFENSECLAW_SETUP_TIMEOUT_TEST_HELPER—unsettest-defined value, unsetSelects the bounded native Setup child-timeout helper.—cmd/defenseclaw-setup/main_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_SHIM_CAPTURE—unsettest-defined absolute path, unsetCarries the output path used by the isolated PATH-shim argv fidelity fixture.—internal/gateway/connector/connector_test.go — Captures the fake curl request body so the test can verify exact shim argv forwarding; never read by production runtime paths
DEFENSECLAW_SPARSE_EVIDENCE_ROOT—unsetabsolute Windows path, unsetWork-root anchor for the Windows sparse-artifact recovery evidence harness.—cmd/defenseclaw/service_windows_test.go — Anchors the WorkRoot the sparse-artifact recovery evidence test emits into
DEFENSECLAW_STRICT_NORMALIZATION_MANIFESTS—unset (external manifest regression skipped)whitespace-separated manifest file paths, unsetSupplies whitespace-separated external manifest paths to the optional strict normalization-manifest decoder regression.—benchmarks/internal/benchmark/manifest_external_test.go — Test-only external manifest input; never read by production runtime paths
DEFENSECLAW_TEMP_RACE_ROOT—unsetabsolute Windows path, unsetRoot directory the Windows temp-race observation harness writes its baseline / observation records under.—cmd/defenseclaw/service_windows_test.go — Passed to the PowerShell child driving the Windows temp-race observation test
DEFENSECLAW_TEST_AGENT_PROCESS_HELPER—unset1, unsetSelects the test helper process that prints the agent process identity it sees, so the agentprocess tests can run it through the platform's shells.—internal/agentprocess/agentprocess_test.go — Test-only agent process identity helper selector
DEFENSECLAW_TEST_APPLY_TARGET_HELPER—unset1, unsetSelects the test helper process that stands in for the per-user apply-target worker.—internal/cli/enterprise_hooks_standalone_unix_test.go — Test-only apply-target worker helper selector
DEFENSECLAW_TEST_CODEX_MANAGED_DATA—unsetabsolute Windows path, unsetPasses the isolated Codex managed data root from the Windows connector-reconcile Go test to its re-execed subprocess so the child resolves managed-Codex artifacts under t.TempDir().—internal/cli/connector_reconcile_subprocess_windows_test.go — Handed to the re-execed subprocess to anchor the managed data root during the reconcile test
DEFENSECLAW_TEST_CODEX_MANAGED_HOME—unsetabsolute Windows path, unsetPasses the isolated user-home root from the Windows connector-reconcile Go test to its re-execed subprocess so the child resolves per-user managed-Codex artifacts under t.TempDir() rather than the runner's real profile.—internal/cli/connector_reconcile_subprocess_windows_test.go — Handed to the re-execed subprocess to anchor the per-user home during the reconcile test
DEFENSECLAW_TEST_CODEX_MANAGED_SUBPROCESS—unset1, unsetMarker the Windows connector-reconcile subprocess test sets in a re-execed child so it takes the Codex-managed code path instead of the parent's test-harness path.—internal/cli/connector_reconcile_subprocess_windows_test.go — Marker the re-execed child reads to select the Codex-managed subprocess path under test
DEFENSECLAW_TEST_COMMAND—unsetstart, status, restart, unsetGateway subcommand selected by the native Windows daemon executable test harness.—internal/cli/daemon_executable_windows_test.go — PowerShell test harness passes the selected gateway lifecycle command
DEFENSECLAW_TEST_EXE—unsetabsolute temporary executable path, unsetAbsolute path to the temporary gateway executable invoked by the native Windows daemon executable tests.—internal/cli/daemon_executable_windows_test.go — PowerShell test harness invokes the isolated gateway executable
DEFENSECLAW_TEST_GRACEFUL_STOP_MARKER—unsettest-defined value, unsetCarries the marker used by the authenticated graceful-stop daemon fixture.—internal/daemon/daemon_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_TEST_GRACEFUL_STOP_OBSERVED—unsettest-defined value, unsetCarries the observation marker used to prove the daemon graceful-stop fixture received its shutdown request.—internal/daemon/daemon_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_TEST_GRACEFUL_STOP_RELEASE—unsettest-defined value, unsetCarries the release marker used to let the daemon graceful-stop fixture finish after observing shutdown.—internal/daemon/daemon_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_TEST_KEY—unsetany-string, unsetPlaceholder LLM key used in test fixtures only.—cli/tests/test_llm_env.py — Test fixture
DEFENSECLAW_TEST_KEY_NOTSET_12345—unsetunsetPlaceholder env var name used to assert 'unset' behavior in tests.—cli/tests/test_llm_env.py — Test fixture for unset assertions
DEFENSECLAW_TEST_KIRO_SHELL_CHILD—unsetv3, v2, unsetTurns the Windows connector test binary into a stand-in for the GUI-subsystem hook launcher when the Kiro shell-boundary test runs a rendered Kiro hook command; the value names the hook surface it expects.—internal/gateway/connector/kiro_windows_shell_test.go — Test-only child-process selector for the Kiro Windows shell-boundary test
DEFENSECLAW_TEST_LEAK—unsetany-string, unsetMarker a test sets in the parent environment to prove the per-user apply-target worker does not inherit it.—internal/cli/enterprise_hooks_standalone_unix_test.go — Test-only environment leak marker for the apply-target worker
DEFENSECLAW_TEST_LLM_KEY—unsetany-string, unsetPlaceholder LLM key used in some test setups when DEFENSECLAW_LLM_KEY needs an alternate target.—cli/tests/test_llm_env.py — Test fixture
DEFENSECLAW_TEST_MARKER—unsetabsolute file path, unsetTest-only marker path used by the fake ClawHub launcher to record a single invocation.—cli/tests/test_cmd_skill.py — Fake Windows ClawHub launcher appends an invocation marker during command-adapter tests
DEFENSECLAW_TEST_RESTRICTED_ENTERPRISE_STAGING—unset1, unsetMarker the Windows enterprise-payload restricted-environment staging test sets in a re-execed helper so the helper knows it is running inside a simulated restricted-user posture and applies the matching payload-staging path.—internal/cli/windows_enterprise_payload_test.go — Marker the re-execed staging helper reads to select the restricted-environment payload-staging path under test
DEFENSECLAW_TEST_WAIT_PROCESS_EXIT—unset1, unsetActivate the short-lived helper subprocess used to verify that native Windows daemon shutdown waits on the original process handle.—internal/daemon/proc_windows_flags_test.go — Native Windows daemon test binary enters its delayed-exit helper mode
DEFENSECLAW_TEST_WATCHDOG_WAIT_EXIT—unsettest-defined value, unsetSelects the native watchdog original-handle wait fixture.—internal/cli/watchdog_pidfile_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_TEST_WATCHDOG_WAIT_READY—unsettest-defined value, unsetCarries the readiness marker used by the native watchdog original-handle wait fixture.—internal/cli/watchdog_pidfile_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_TEST_WINDOWS_NOTIFICATION—unset1, unsetEnables the attended native Windows notification delivery test.—internal/notify/notify_windows_test.go — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_UNSIGNED_PE—unsettest-defined absolute path, unsetCarries an unsigned portable-executable fixture path to the native Authenticode evidence regression.—cli/tests/test_windows_installer_artifacts.py — Native Windows test fixture; never read by production runtime paths
DEFENSECLAW_UPDATE_GOLDEN—unset1, unsetRegenerates the host hook, sandbox artifact, OpenShell policy and provider profile golden files, and the bounded chain catalog, instead of comparing against them.—internal/gateway/connector/hook_render_golden_test.go — Rewrites the host hook byte manifest
internal/gateway/connector/sandbox_artifacts_test.go — Rewrites the sandbox artifact goldens
internal/openshell/policy/policy_test.go — Rewrites the policy YAML goldens
internal/openshell/profiles/profiles_test.go — Rewrites the provider profile goldens
internal/guardrail/tool_chain_catalog_json_test.go — Rewrites policies/guardrail/tool-chains.json from the chain catalog
DEFENSECLAW_UPGRADE_LOCAL_DIR—unsetany-absolute-pathTests only: defenseclaw upgrade and the 0.8.x handoff take the installer and release assets from this directory.—cli/defenseclaw/upgrade_shim.py — Copies the installer from a local release directory
scripts/defenseclaw-upgrade.sh — Runs the installer with --local
DEFENSECLAW_V2_1177_RECREATE_LIVE—unsettest payload, unsetRecreates a live target during the CAS V2 1177 hard-exit regression fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 recreated-live fixture
DEFENSECLAW_V2_FORCE_SHORT_REPAIR—unset1, unsetForces deterministic short-name repair paths in native CAS V2 tests.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 short-name repair fixture
DEFENSECLAW_V2_HARD_EXIT_ABORT—unset1, unsetInjects an abort decision into the native CAS V2 hard-exit fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 abort fixture
DEFENSECLAW_V2_HARD_EXIT_HELPER—unset1, unsetSelects the native CAS V2 hard-exit subprocess fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 hard-exit fixture
DEFENSECLAW_V2_HARD_EXIT_OCCURRENCE—1positive decimal integer, unsetOne-based phase occurrence at which the native CAS V2 fixture terminates its subprocess.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 hard-exit occurrence selector
DEFENSECLAW_V2_HARD_EXIT_OPERATION—unsettest-defined operation, unsetMutation operation selected for the native CAS V2 hard-exit fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 operation selector
DEFENSECLAW_V2_HARD_EXIT_PATH—unsetabsolute test target path, unsetTarget path passed to the native CAS V2 hard-exit fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 hard-exit target
DEFENSECLAW_V2_HARD_EXIT_PHASE—unsettest-defined CAS phase, unsetDurability phase at which the native CAS V2 fixture terminates its subprocess.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 hard-exit phase selector
DEFENSECLAW_V2_HARD_EXIT_RECOVER—unset1, unsetRequests recovery instead of a new mutation in the native CAS V2 hard-exit fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 recovery selector
DEFENSECLAW_V2_HARD_EXIT_SAFE_ABORT—unset1, unsetInjects a pre-publication safe abort into the native CAS V2 hard-exit fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 safe-abort fixture
DEFENSECLAW_V2_HARD_EXIT_STATE—unsetabsolute test state path, unsetRecovery-state directory passed to the native CAS V2 hard-exit fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 hard-exit state fixture
DEFENSECLAW_V2_LOCK_EXIT_HELD—unset1, unsetTerminates the native CAS V2 lock fixture while the transaction lock remains held.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock hard-exit fixture
DEFENSECLAW_V2_LOCK_HELPER—unset1, unsetSelects the native CAS V2 cross-process lock fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock fixture
DEFENSECLAW_V2_LOCK_HIDE_TARGET—unset1, unsetTemporarily hides the live target in the native CAS V2 lock fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 hidden-target fixture
DEFENSECLAW_V2_LOCK_HOLD_PHASE—unsettest-defined CAS phase, unsetCAS phase at which the native cross-process fixture holds its transaction lock.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock hold-phase selector
DEFENSECLAW_V2_LOCK_ONLY—unset1, unsetRequests lock-only behavior from the native CAS V2 cross-process fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock-only selector
DEFENSECLAW_V2_LOCK_PATH—unsetabsolute test target path, unsetTarget path passed to the native CAS V2 cross-process lock fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock target
DEFENSECLAW_V2_LOCK_PAYLOAD—unsettest payload, unsetMutation payload passed to the native CAS V2 cross-process lock fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock payload fixture
DEFENSECLAW_V2_LOCK_READY—unsetabsolute test marker path, unsetReady-signal path shared with the native CAS V2 cross-process lock fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock readiness fixture
DEFENSECLAW_V2_LOCK_RELEASE—unsetabsolute test marker path, unsetRelease-signal path shared with the native CAS V2 cross-process lock fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock release fixture
DEFENSECLAW_V2_LOCK_STATE—unsetabsolute test state path, unsetRecovery-state directory passed to the native CAS V2 cross-process lock fixture.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 lock state fixture
DEFENSECLAW_V2_POST_P_REPARSE_TARGET—unsetabsolute test target path, unsetReplacement reparse target injected after the CAS V2 publication point for fail-closed topology tests.—internal/gateway/connector/atomic_transform_v2_exit_windows_test.go — Native CAS V2 post-publication reparse fixture
DEFENSECLAW_WINDOWS_PROCESS_HELPER—unset1, unsetActivate the isolated subprocess entry point used by native Windows process-snapshot tests.—internal/inventory/process_snapshot_windows_test.go — Native Windows test binary enters its named-process helper mode

Managed enterprise deployments

On an enterprise deployment, the lifecycle writes each service's environment itself. Do not set these variables in a user's shell or in the services by hand.

VariableRole on a managed host
DEFENSECLAW_DEPLOYMENT_MODESet to managed_enterprise by the managed service definitions, so a replaced config cannot turn managed mode off
DEFENSECLAW_ENTERPRISE_PROFILEPins the profile (secure_client or standalone). The standalone service definitions set it to standalone. It must agree with enterprise.profile in the config. Unset, the profile comes from the config, then the per-OS default: secure_client on Windows and macOS, standalone on Linux
DEFENSECLAW_CONFIGPoints the services at the administrator-owned config, for example /etc/defenseclaw/config.yaml on Linux
DEFENSECLAW_HOOK_GUARDIAN_AUTH_DIRThe guardian's authorization ledger directory: /var/lib/defenseclaw-hook-guardian on Linux, /opt/cisco/defenseclaw/hook-guardian-state on macOS
DEFENSECLAW_UNIX_SERVICE_ACCOUNTThe macOS service definitions, and the gateway commands the macOS lifecycle runs, set it to _defenseclaw. Linux uses the default, defenseclaw. Set it yourself only for custom packaging that runs the gateway under another account; a wrong value makes the runtime trust check reject the real service account
DEFENSECLAW_INSTALL_MANAGED_DESCRIPTORTest-only. Points install.sh at a temporary runtime descriptor. The per-user gateway still refuses to start on a managed host

On this release, administrators also set DEFENSECLAW_CONFIG when they run the enterprise policy commands, so the commands read the managed config instead of the caller's ~/.defenseclaw/config.yaml:

sudo DEFENSECLAW_CONFIG=/etc/defenseclaw/config.yaml /opt/defenseclaw/bin/defenseclaw-gateway enterprise policy show --json

On macOS use /opt/cisco/defenseclaw/etc/config.yaml. On Windows, set $env:DEFENSECLAW_CONFIG = 'C:\ProgramData\Cisco\DefenseClaw\etc\config.yaml' in an elevated PowerShell first. See Machine policy status.

When in doubt

Run defenseclaw doctor. The doctor walks the same env-var resolution code paths as the running gateway and surfaces effective values plus any active opt-outs.

defenseclaw doctor
defenseclaw keys list

Reference