mirror of
https://github.com/usestrix/strix.git
synced 2026-08-16 17:27:26 +02:00
170 lines
5.8 KiB
Plaintext
170 lines
5.8 KiB
Plaintext
---
|
|
title: "Configuration"
|
|
description: "Environment variables for Strix"
|
|
---
|
|
|
|
Configure Strix using environment variables or a config file.
|
|
|
|
## LLM Configuration
|
|
|
|
<ParamField path="STRIX_LLM" type="string" required>
|
|
Model name in LiteLLM format (e.g., `openai/gpt-5.4`, `anthropic/claude-sonnet-4-6`).
|
|
</ParamField>
|
|
|
|
<ParamField path="LLM_API_KEY" type="string">
|
|
API key for your LLM provider. Not required for local models or cloud provider auth (Vertex AI, AWS Bedrock).
|
|
</ParamField>
|
|
|
|
<ParamField path="LLM_API_BASE" type="string">
|
|
Custom API base URL. Also accepts `OPENAI_API_BASE`, `LITELLM_BASE_URL`, or `OLLAMA_API_BASE`.
|
|
</ParamField>
|
|
|
|
<ParamField path="LLM_EXTRA_HEADERS" type="string">
|
|
Extra HTTP headers sent on every LLM request, as a JSON object (e.g.
|
|
`{"X-Feature-Key":"value","X-Tenant":"acme"}`). Useful for OpenAI-compatible
|
|
gateways that require attribution or routing headers in addition to the bearer
|
|
token. The bearer token itself still comes from `LLM_API_KEY`. Applies to both
|
|
the LiteLLM and native OpenAI routing paths.
|
|
</ParamField>
|
|
|
|
<ParamField path="LLM_TIMEOUT" default="300" type="integer">
|
|
Request timeout in seconds for LLM calls.
|
|
</ParamField>
|
|
|
|
<ParamField path="STRIX_LLM_MAX_RETRIES" default="5" type="integer">
|
|
Maximum number of retries for LLM API calls on transient failures.
|
|
</ParamField>
|
|
|
|
<ParamField path="STRIX_REASONING_EFFORT" default="high" type="string">
|
|
Control thinking effort for reasoning models. Valid values: `none`, `minimal`, `low`, `medium`, `high`, `xhigh`, `max`. Defaults to `medium` for quick scan mode.
|
|
</ParamField>
|
|
|
|
<ParamField path="STRIX_MEMORY_COMPRESSOR_TIMEOUT" default="30" type="integer">
|
|
Timeout in seconds for memory compression operations (context summarization).
|
|
</ParamField>
|
|
|
|
### Dedicated deduplication model
|
|
|
|
Finding deduplication is a cheap, structured classification task. By default it
|
|
runs on the main model, but you can route it to a smaller/cheaper model without
|
|
affecting the agents that do the actual testing.
|
|
|
|
<ParamField path="STRIX_DEDUPE_MODEL" type="string">
|
|
Model used to judge whether a candidate finding duplicates an existing report.
|
|
Falls back to `STRIX_LLM` when unset.
|
|
</ParamField>
|
|
|
|
<ParamField path="DEDUPE_LLM_API_KEY" type="string">
|
|
Optional provider key for the deduplication model.
|
|
</ParamField>
|
|
|
|
<ParamField path="DEDUPE_LLM_API_BASE" type="string">
|
|
Optional custom API base URL for the deduplication model. Use when the dedupe
|
|
model runs on a different endpoint than the main model.
|
|
</ParamField>
|
|
|
|
<ParamField path="DEDUPE_LLM_EXTRA_HEADERS" type="string">
|
|
Optional JSON object of extra HTTP headers sent on every deduplication-model
|
|
request, e.g. `{"X-Feature-Key":"value"}`. A dedicated dedupe model never
|
|
inherits `LLM_EXTRA_HEADERS`; set this when its endpoint needs custom headers.
|
|
</ParamField>
|
|
|
|
<ParamField path="STRIX_DEDUPE_REASONING_EFFORT" type="string">
|
|
Reasoning effort for the deduplication model. Defaults to the model's own
|
|
baseline when unset.
|
|
</ParamField>
|
|
|
|
## Optional Features
|
|
|
|
<ParamField path="PERPLEXITY_API_KEY" type="string">
|
|
API key for Perplexity AI. Enables real-time web search during scans for OSINT and vulnerability research.
|
|
</ParamField>
|
|
|
|
<ParamField path="POSTMAN_API_KEY" type="string">
|
|
Postman API key (`PMAK-…`). Enables fetching Postman collections by id as a target (`postman://<collection-uid>`), and Postman environments (`postman://<collection-uid>?env=<environment-uid>`) to resolve collection variables. Not needed when passing a local collection export file.
|
|
</ParamField>
|
|
|
|
<ParamField path="STRIX_TELEMETRY" default="1" type="string">
|
|
Telemetry toggle. Set to `0`, `false`, `no`, or `off` to disable telemetry (PostHog, Scarf, OTEL).
|
|
</ParamField>
|
|
|
|
<ParamField path="TRACELOOP_BASE_URL" type="string">
|
|
OTLP/Traceloop base URL for remote OpenTelemetry export. If unset, Strix keeps traces local only.
|
|
</ParamField>
|
|
|
|
<ParamField path="TRACELOOP_API_KEY" type="string">
|
|
API key used for remote trace export. Remote export is enabled only when both `TRACELOOP_BASE_URL` and `TRACELOOP_API_KEY` are set.
|
|
</ParamField>
|
|
|
|
<ParamField path="TRACELOOP_HEADERS" type="string">
|
|
Optional custom OTEL headers (JSON object or `key=value,key2=value2`). Useful for Langfuse or custom/self-hosted OTLP gateways.
|
|
</ParamField>
|
|
|
|
When remote OTEL vars are not set, Strix still writes complete run telemetry locally to:
|
|
|
|
```bash
|
|
strix_runs/<run_name>/events.jsonl
|
|
```
|
|
|
|
When remote vars are set, Strix dual-writes telemetry to both local JSONL and the remote OTEL endpoint.
|
|
|
|
## Docker Configuration
|
|
|
|
<ParamField path="STRIX_IMAGE" default="ghcr.io/usestrix/strix-sandbox:1.3.0" type="string">
|
|
Docker image to use for the sandbox container.
|
|
</ParamField>
|
|
|
|
<ParamField path="DOCKER_HOST" type="string">
|
|
Docker daemon socket path. Use for remote Docker hosts or custom configurations.
|
|
</ParamField>
|
|
|
|
<ParamField path="STRIX_RUNTIME_BACKEND" default="docker" type="string">
|
|
Runtime backend for the sandbox environment.
|
|
</ParamField>
|
|
|
|
## Sandbox Configuration
|
|
|
|
<ParamField path="STRIX_SANDBOX_EXECUTION_TIMEOUT" default="120" type="integer">
|
|
Maximum execution time in seconds for sandbox operations.
|
|
</ParamField>
|
|
|
|
<ParamField path="STRIX_SANDBOX_CONNECT_TIMEOUT" default="10" type="integer">
|
|
Timeout in seconds for connecting to the sandbox container.
|
|
</ParamField>
|
|
|
|
## Config File
|
|
|
|
Strix stores configuration in `~/.strix/cli-config.json`. You can also specify a custom config file:
|
|
|
|
```bash
|
|
strix --target ./app --config /path/to/config.json
|
|
```
|
|
|
|
**Config file format:**
|
|
|
|
```json
|
|
{
|
|
"env": {
|
|
"STRIX_LLM": "openai/gpt-5.4",
|
|
"LLM_API_KEY": "sk-...",
|
|
"STRIX_REASONING_EFFORT": "high"
|
|
}
|
|
}
|
|
```
|
|
|
|
## Example Setup
|
|
|
|
```bash
|
|
# Required
|
|
export STRIX_LLM="openai/gpt-5.4"
|
|
export LLM_API_KEY="sk-..."
|
|
|
|
# Optional: Enable web search
|
|
export PERPLEXITY_API_KEY="pplx-..."
|
|
|
|
# Optional: Custom timeouts
|
|
export LLM_TIMEOUT="600"
|
|
export STRIX_SANDBOX_EXECUTION_TIMEOUT="300"
|
|
|
|
```
|