Environment Variables

MockForge supports extensive configuration through environment variables. This page documents all available environment variables, their purposes, and usage examples.

Core Functionality

Server Control

  • MOCKFORGE_LATENCY_ENABLED=true|false (default: true)

    • Enable/disable response latency simulation
    • When disabled, responses are immediate
  • MOCKFORGE_FAILURES_ENABLED=true|false (default: false)

    • Enable/disable failure injection
    • When enabled, can simulate HTTP errors and timeouts
  • MOCKFORGE_OVERRIDES_ENABLED=true|false (default: true)

    • Sets the core.overrides_enabled config field (1/true enables; any other value disables)
    • Note: no code reads this field yet, so it does not currently turn the overrides: rules on or off; they apply whenever they are configured
  • MOCKFORGE_LOG_LEVEL=debug|info|warn|error (default: info)

    • Set the logging verbosity level
    • Available: debug, info, warn, error

Recording and Replay

Recording, replay, and proxy modes are configured via CLI flags (--record, --replay, --proxy-target) and YAML, not env vars. See the Recording & Capture chapter for the full surface.

HTTP Server Configuration

Server Settings

  • MOCKFORGE_HTTP_PORT=3000 (default: 3000)

    • Port for the HTTP server to listen on
  • MOCKFORGE_HTTP_HOST=127.0.0.1 (default: 0.0.0.0)

    • Host address for the HTTP server to bind to

The OpenAPI spec path is set via --spec, MOCKFORGE_OPENAPI_SPEC_URL, or the http.spec YAML field. CORS, request timeouts, and other middleware options are YAML-configured under the relevant section (see CLI --help).

Validation and Templating

  • MOCKFORGE_REQUEST_VALIDATION=enforce|warn|off (default: enforce)

    • Level of request validation
    • enforce: Reject invalid requests with error
    • warn: Log warnings but allow requests
    • off: Skip validation entirely
  • MOCKFORGE_RESPONSE_VALIDATION=true|false (default: false)

    • Enable validation of generated responses
    • Useful for ensuring response format compliance
  • MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true|false (default: false)

    • Enable template expansion in responses
    • Allows use of {{uuid}}, {{now}}, etc. in responses
  • MOCKFORGE_AGGREGATE_ERRORS=true|false (default: true)

    • Aggregate multiple validation errors into a single response
    • When enabled, returns all validation errors at once
  • MOCKFORGE_VALIDATION_STATUS=400|422 (default: 400)

    • HTTP status code for validation errors
    • 400: Bad Request (general)
    • 422: Unprocessable Entity (validation-specific)

WebSocket Server Configuration

Server Settings

  • MOCKFORGE_WS_PORT=3001 (default: 3001)

    • Port for the WebSocket server to listen on
  • MOCKFORGE_WS_HOST=127.0.0.1 (default: 0.0.0.0)

    • Host address for the WebSocket server to bind to

Connection timeouts are YAML-only (websocket.connection_timeout_secs).

Replay Configuration

  • MOCKFORGE_WS_REPLAY_FILE=path/to/replay.jsonl
    • Path to WebSocket replay file
    • Enables scripted WebSocket message sequences

gRPC Server Configuration

Server Settings

  • MOCKFORGE_GRPC_PORT=50051 (default: 50051)
    • Port for the gRPC server to listen on

Host binding for the gRPC server is YAML-only (grpc.host).

Admin UI Configuration

Server Settings

  • MOCKFORGE_ADMIN_ENABLED=true|false (default: false)

    • Enable/disable the Admin UI
    • When enabled, provides web interface for management
  • MOCKFORGE_ADMIN_PORT=9080 (default: 9080)

    • Port for the Admin UI server to listen on
  • MOCKFORGE_ADMIN_HOST=127.0.0.1 (default: 127.0.0.1)

    • Host address for the Admin UI server to bind to

UI Configuration

  • MOCKFORGE_ADMIN_MOUNT_PATH=/admin (default: none)

    • Mount path for embedded Admin UI
    • When set, Admin UI is available under HTTP server
  • MOCKFORGE_ADMIN_API_ENABLED=true|false (default: true)

    • Enable/disable Admin UI API endpoints
    • Controls whether /__mockforge/* endpoints are available

Data Generation Configuration

Faker Control

  • MOCKFORGE_RAG_ENABLED=true|false (default: false)

    • Enable Retrieval-Augmented Generation for data
    • Requires additional setup for LLM integration
  • MOCKFORGE_FAKE_TOKENS=true|false (default: true)

    • Enable/disable faker token expansion
    • Controls whether {{faker.email}} etc. work

RAG / LLM Provider

  • MOCKFORGE_RAG_PROVIDER=openai|anthropic|ollama (default: openai)
    • LLM provider for retrieval-augmented generation.
  • MOCKFORGE_RAG_API_KEY=<key> — provider API key (falls back to OPENAI_API_KEY when unset).
  • MOCKFORGE_RAG_API_ENDPOINT=<url> — custom endpoint, overrides the provider default.
  • MOCKFORGE_RAG_MODEL=<name> — e.g. gpt-4, claude-3-5-sonnet, llama3.
  • MOCKFORGE_RAG_TEMPERATURE=<float> (default: 0.7).
  • MOCKFORGE_RAG_MAX_TOKENS=<int> (default: 2048).
  • MOCKFORGE_RAG_CONTEXT_WINDOW=<int> (default: 4096).
  • MOCKFORGE_RAG_TIMEOUT_SECONDS=<int> (default: 30).
  • MOCKFORGE_RAG_MAX_RETRIES=<int> (default: 3).
  • OPENAI_API_KEY=<key> — fallback when MOCKFORGE_RAG_API_KEY is unset.
  • MOCKFORGE_EMBEDDING_PROVIDER=openai|local|ollama — provider for embeddings used by RAG.
  • MOCKFORGE_EMBEDDING_MODEL=<name> — e.g. text-embedding-3-small.
  • MOCKFORGE_EMBEDDING_ENDPOINT=<url> — custom endpoint.
  • MOCKFORGE_SIMILARITY_THRESHOLD=<float> (0.0–1.0) — minimum match score.

Registry / Marketplace

  • MOCKFORGE_REGISTRY_TOKEN=<token> — auth token for publishing scenarios or plugins to the registry. Required for mockforge scenario publish and similar commands.
  • MOCKFORGE_PLUGIN_REGISTRY_URL=<url> — registry endpoint used by mockforge plugin install / publish (default: the public mockforge.dev registry).

OpenAPI / Spec Loading

  • MOCKFORGE_OPENAPI_SPEC_URL=<url> — alternative to --spec; load the OpenAPI spec from a URL at startup. Useful in containerized deployments where the spec lives behind a static CDN.

Distributed Tracing (OpenTelemetry / OTLP)

  • MOCKFORGE_OTLP_ENDPOINT=<url> — OTLP collector endpoint (e.g. http://jaeger:4317 or http://otel-collector:4318).
  • MOCKFORGE_OTLP_SERVICE_NAME=<name> — service name attached to spans (default: mockforge).
  • MOCKFORGE_OTLP_SAMPLING_RATE=<float> — 0.0–1.0. 1.0 = trace every request.

Rate Limiting

  • MOCKFORGE_RATE_LIMIT_ENABLED=true|false — toggle the HTTP middleware rate limiter.
  • MOCKFORGE_RATE_LIMIT_DISABLED=true|false — explicit opt-out (overrides config-file enabled: true). Useful for --no-rate-limit parity in containers.
  • MOCKFORGE_RATE_LIMIT_RPM=<int> — global requests-per-minute cap.

Kafka Protocol

  • MOCKFORGE_KAFKA_ENABLED=true|false — start the Kafka mock listener.
  • MOCKFORGE_KAFKA_ADVERTISED_HOST=<host> — hostname advertised in metadata responses (defaults to the bind host).
  • MOCKFORGE_KAFKA_ADVERTISED_PORT=<int> — port advertised in metadata responses (defaults to the bind port).
  • MOCKFORGE_KAFKA_FIXTURES_DIR=path/to/kafka-fixtures — directory of pre-recorded Kafka topic fixtures.
  • MOCKFORGE_KAFKA_RECORDING_DB=path/to/recording.sqlite — SQLite file for recording produce/consume exchanges; when set, every Kafka exchange is persisted for replay.

AMQP / MQTT Protocol

  • MOCKFORGE_AMQP_RECORDING_DB=path/to/recording.sqlite — SQLite file for recording AMQP publish/deliver exchanges; when set, every exchange is persisted for replay. Unset or unusable path is a no-op.
  • MOCKFORGE_MQTT_RECORDING_DB=path/to/recording.sqlite — SQLite file for recording MQTT publish/deliver exchanges; when set, every exchange is persisted for replay. Unset or unusable path is a no-op.

Federation

  • MOCKFORGE_FEDERATION_POLL_URL=<url> — upstream MockForge instance to poll for shared workspaces.
  • MOCKFORGE_FEDERATION_POLL_TOKEN=<token> — auth token for the upstream poll.
  • MOCKFORGE_FEDERATION_POLL_INTERVAL_SECS=<int> — poll cadence (default: 60).
  • MOCKFORGE_FEDERATION_WORKSPACE_ID=<uuid> — workspace this instance federates into.

Encryption / Secret Storage

  • MOCKFORGE_ENCRYPTION_KEY=<base64-key> — base64-encoded AES-256 key used to encrypt config/data at rest.
  • MOCKFORGE_MASTER_KEY=<base64-key> — master KEK that wraps per-workspace data encryption keys.
  • MOCKFORGE_BYOK_ENCRYPTION_KEY=<base64-key> — bring-your-own-key override for workspace encryption.
  • MOCKFORGE_SECRET_PROVIDER=env|aws|vault|gcp|azure — backend used by the secret-resolution layer (default: env).
  • MOCKFORGE_SECRET_CACHE_TTL=<secs> — how long resolved secrets stay in the in-process cache.
  • MOCKFORGE_KMS_PROVIDER=aws|gcp|azure|vault — when set, MockForge fetches the master key from a managed KMS instead of using MOCKFORGE_MASTER_KEY.
  • MOCKFORGE_KMS_REGION=<region> — region for the KMS provider (e.g. us-east-1).
  • MOCKFORGE_VAULT_ADDR=<url> — Vault server address when using MOCKFORGE_KMS_PROVIDER=vault.
  • MOCKFORGE_VAULT_TOKEN=<token> — Vault auth token.

Database (registry server / collab)

These apply to the multi-tenant registry server and the collab workspace backend; the OSS local mock server doesn’t need them.

  • MOCKFORGE_DB_TYPE=sqlite|postgres — backing store for the registry / collab.
  • MOCKFORGE_DB_CONNECTION=<url> — connection string (e.g. postgres://user:pass@host/db or sqlite:./mockforge.db).

Fixtures and Testing

Fixtures Configuration

  • MOCKFORGE_FIXTURES_DIR=path/to/fixtures (default: ./fixtures)
    • Directory where fixtures are stored
    • Used for recording and replaying HTTP requests

Authentication (OIDC)

  • MOCKFORGE_OIDC_ENABLED=true|false — enable OpenID Connect for the admin API and proxied routes.
  • MOCKFORGE_OIDC_ISSUER=<url> — issuer URL whose /.well-known/openid-configuration MockForge will fetch.
  • MOCKFORGE_OIDC_CONFIG=<path> — path to a YAML/JSON file overriding individual OIDC discovery fields.
  • MOCKFORGE_OIDC_SECRET=<client-secret> — confidential-client secret for the configured client_id.

Registry session cookies (registry server)

  • MOCKFORGE_SESSION_COOKIE_SECURE=true|false — set Secure; SameSite=None on the mockforge_session / mockforge_refresh auth cookies. Required for hosted HTTPS deployments where the admin UI is served from a different origin than the API; self-hosted plain-HTTP setups keep SameSite=Lax without Secure.

Hot Reload

Watch the spec / config / fixtures dirs and rebuild routes on change without restarting.

  • MOCKFORGE_HOT_RELOAD_ENABLED=true|false — master switch.
  • MOCKFORGE_HOT_RELOAD_SPEC=true|false — watch the OpenAPI spec file.
  • MOCKFORGE_HOT_RELOAD_FIXTURES=true|false — watch the fixtures directory.
  • MOCKFORGE_HOT_RELOAD_DEBOUNCE=<ms> — coalesce rapid filesystem events into a single reload.
  • MOCKFORGE_HOT_RELOAD_INTERVAL=<ms> — polling fallback when filesystem events aren’t available.
  • MOCKFORGE_HOT_RELOAD_TIMEOUT=<ms> — upper bound on a single reload before it’s aborted.
  • MOCKFORGE_HOT_RELOAD_GRACEFUL=true|false — drain in-flight requests before swapping routes.
  • MOCKFORGE_HOT_RELOAD_VALIDATE=true|false — re-run validation on every reload (safer; slower).

Plugins

  • MOCKFORGE_PLUGINS_ENABLED=true|false — load .so/.dylib/.wasm plugins on startup.
  • MOCKFORGE_PLUGIN_CACHE_DIR=<path> — where downloaded plugins are cached.
  • MOCKFORGE_PLUGIN_TIMEOUT_MS=<ms> — per-invocation timeout for plugin calls.
  • MOCKFORGE_PLUGIN_MAX_CONCURRENT=<int> — max concurrent plugin invocations across the process.
  • MOCKFORGE_PLUGIN_MAX_CPU=<percent> — CPU budget per plugin (0–100).
  • MOCKFORGE_PLUGIN_MAX_MEMORY=<bytes> — memory cap per plugin.
  • MOCKFORGE_PLUGIN_MAX_MODULE_SIZE=<bytes> — max accepted plugin binary size.
  • MOCKFORGE_PLUGIN_NETWORK_ACCESS=true|false — allow plugins to make outbound network calls.

Compression

  • MOCKFORGE_COMPRESSION_ENABLED=true|false — gzip/deflate/zstd response bodies above the threshold.
  • MOCKFORGE_COMPRESSION_ALGORITHM=gzip|deflate|zstd|br — preferred compression codec when the client accepts multiple.
  • MOCKFORGE_COMPRESSION_LEVEL=<int> — codec-specific level (e.g. 1–9 for gzip).

Resilience

  • MOCKFORGE_CIRCUIT_BREAKER_ENABLED=true|false — wrap upstream calls (proxy / record-replay) in a circuit breaker.
  • MOCKFORGE_CIRCUIT_BREAKER_THRESHOLD=<int> — consecutive failures before the breaker opens.
  • MOCKFORGE_POOL_MAX_CONNECTIONS=<int> — outbound HTTP connection pool size.
  • MOCKFORGE_POOL_IDLE_TIMEOUT=<secs> — close idle connections after this duration.

Performance Tuning

  • MOCKFORGE_WORKER_THREADS=<int> — Tokio worker-thread count (default: number of CPU cores).
  • MOCKFORGE_MAX_BODY_SIZE=<bytes> — reject inbound HTTP bodies larger than this.

Proxy / Record-Replay

  • MOCKFORGE_PROXY_UPSTREAM=<url> — when set, requests with no matching mock are proxied here. Pair with mockforge serve --recorder (or the recorder admin API) to capture upstream traffic for replay.
  • MOCKFORGE_PROXY_SPEC=<path> — OpenAPI/Swagger spec (JSON or YAML) backing the proxy’s passive conformance tap (#864).
  • MOCKFORGE_PROXY_VALIDATE_CONFORMANCE=true|false — validate proxied requests against the spec and report violations; requires MOCKFORGE_PROXY_SPEC.
  • MOCKFORGE_PROXY_VALIDATE_CONFORMANCE_STRICT=true|false — additionally reject non-conforming requests with a diagnostic response instead of forwarding.

Tunneling

  • MOCKFORGE_TUNNEL_SERVER_URL=<url> — control-plane URL for the MockForge tunnel server (used when mockforge tunnel start).
  • MOCKFORGE_TUNNEL_AUTH_TOKEN=<token> — auth token for the tunnel control plane.

Observability

Metrics CSV Log

  • MOCKFORGE_METRICS_LOG_FILE=path/to/metrics.csv
    • When set, the admin server’s system-monitoring task appends one CSV row every 10 s with timestamp,cpu_pct,mem_mb,total_reqs,err_rate.
    • Survives restarts; chartable in any spreadsheet, Grafana, or dashboarding tool.
    • Example: MOCKFORGE_METRICS_LOG_FILE=/var/log/mockforge-metrics.csv
    • The TUI dashboard also tracks lifetime peak CPU%, memory MB, and error rate in-memory and renders them as current (peak X) next to the live values.

Configuration Files

The config file path is set via --config <path>, not env var. MockForge also auto-discovers mockforge.yaml / mockforge.yml / mockforge.json in the working directory.

Usage Examples

Basic HTTP Server with OpenAPI

export MOCKFORGE_OPENAPI_SPEC_URL=file://./examples/openapi-demo.json
export MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true
export MOCKFORGE_ADMIN_ENABLED=true
cargo run -p mockforge-cli -- serve --http-port 3000 --admin-port 9080

Full WebSocket Support

export MOCKFORGE_WS_REPLAY_FILE=examples/ws-demo.jsonl
export MOCKFORGE_WS_PORT=3001
export MOCKFORGE_OPENAPI_SPEC_URL=file://./examples/openapi-demo.json
export MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true
cargo run -p mockforge-cli -- serve --admin

Development Setup

export MOCKFORGE_LOG_LEVEL=debug
export MOCKFORGE_LATENCY_ENABLED=false
export MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true
export MOCKFORGE_ADMIN_ENABLED=true
export MOCKFORGE_OPENAPI_SPEC_URL=file://./examples/openapi-demo.json
cargo run -p mockforge-cli -- serve

Production Setup

export MOCKFORGE_LOG_LEVEL=warn
export MOCKFORGE_LATENCY_ENABLED=true
export MOCKFORGE_FAILURES_ENABLED=false
export MOCKFORGE_REQUEST_VALIDATION=enforce
export MOCKFORGE_ADMIN_ENABLED=false
export MOCKFORGE_OPENAPI_SPEC_URL=file://./path/to/production-spec.json
cargo run -p mockforge-cli -- serve --http-port 80

Environment Variable Priority

Environment variables override configuration file settings. CLI flags take precedence over both. The priority order is:

  1. CLI flags (highest priority)
  2. Environment variables
  3. Configuration file settings
  4. Default values (lowest priority)

Security Considerations

  • Be careful with MOCKFORGE_ADMIN_ENABLED=true in production
  • Consider setting restrictive host bindings (127.0.0.1) for internal use
  • Use MOCKFORGE_FAKE_TOKENS=false for deterministic testing
  • Review CORS settings for cross-origin requests

Troubleshooting

Common Issues

  1. Environment variables not taking effect

    • Check variable names for typos
    • Ensure variables are exported before running the command
    • Use env | grep MOCKFORGE to verify variables are set
  2. Port conflicts

    • Use different ports via MOCKFORGE_HTTP_PORT, MOCKFORGE_WS_PORT, etc.
    • Check what processes are using ports with netstat -tlnp
  3. OpenAPI spec not loading

    • Verify file path in MOCKFORGE_OPENAPI_SPEC_URL
    • Ensure JSON/YAML syntax is valid
    • Check file permissions
  4. Template expansion not working

    • Set MOCKFORGE_RESPONSE_TEMPLATE_EXPAND=true
    • Verify token syntax (e.g., {{uuid}} not {uuid})

Operator and Deployment Variables

These are read by the hosted/cloud components (registry server, plugin host, plugin egress proxy, test runner) rather than by mockforge serve. Most are unset in a normal self-hosted deployment and only matter when running the managed stack. Defaults below are the values the code falls back to.

HTTP keep-alive hints

  • MOCKFORGE_HTTP_KEEPALIVE_TIMEOUT_SECS (default: 120)
    • Idle timeout advertised in the Keep-Alive response header
  • MOCKFORGE_HTTP_KEEPALIVE_MAX_REQUESTS (default: 1000)
    • Max requests per connection advertised in the Keep-Alive response header

Contract diff and drift capture

  • MOCKFORGE_CONTRACT_DIFF_MAX_BODY_MB (default: 10)
    • Largest response body, in MB, the contract-diff middleware will buffer
  • MOCKFORGE_DRIFT_MAX_BODY_MB (default: 10)
    • Same cap for the drift-tracking middleware
  • MOCKFORGE_CONTRACT_PROBE_INTERVAL_SECS (default: 1800)
    • Interval for the background contract probe. Values below 60 are ignored

Capture forwarding (cloud sync)

  • MOCKFORGE_CLOUD_CAPTURES_FORWARDER_URL (default: unset)
    • Endpoint captures are forwarded to. Falls back to MOCKFORGE_CAPTURE_INGEST_URL. Forwarding is off when neither is set
  • MOCKFORGE_CAPTURE_FORWARDER_BUFFER (default: 1024)
    • In-memory queue depth for pending captures
  • MOCKFORGE_CAPTURE_FORWARDER_TIMEOUT_MS (default: 5000)
    • HTTP timeout for each forward attempt

Kafka

  • MOCKFORGE_KAFKA_OFFSETS_DB (default: unset)
    • Path to persist consumer-group offsets. Unset or empty keeps offsets in memory only, so they are lost on restart

Observability

  • MOCKFORGE_OTLP_GRPC_PORT (default: 4317)
    • Port the registry server listens on for OTLP/gRPC telemetry

Hosted deployments

  • MOCKFORGE_CLOUD_PLUGINS_IMAGE (default: ghcr.io/saasy-solutions/mockforge-cloud-plugins:latest)
    • Container image for plugin-enabled hosted mocks. Non-plugin deployments use MOCKFORGE_DOCKER_IMAGE
  • MOCKFORGE_HOSTED_OVERAGE_CEILING_MULT (default: 0)
    • Multiple of the plan limit at which hosted traffic is cut off. 0 disables the ceiling. Values must be positive to take effect
  • MOCKFORGE_MANAGEMENT_TOKEN (default: unset)
    • Set by the registry on every hosted mock. When set, mockforge serve rejects writes (anything but GET, HEAD, OPTIONS) to MockForge’s own control routes (/__mockforge/*, /api/chaos, /api/recorder, /api/world-state, and the other management APIs) with 401 unless the request carries the token in X-MockForge-Management-Token or Authorization: Bearer. Reads and your mocked API are unaffected. Leave it unset for self-hosted servers

Incident dispatch

  • MOCKFORGE_PAGERDUTY_ENQUEUE_URL (default: https://events.pagerduty.com/v2/enqueue)
    • Override for the PagerDuty Events API endpoint, for testing or a proxy

Platform LLM (managed test generation)

  • MOCKFORGE_PLATFORM_LLM_PROVIDER (default: openai)
  • MOCKFORGE_PLATFORM_LLM_MODEL (default: gpt-4o-mini)
  • MOCKFORGE_PLATFORM_LLM_ENDPOINT (default: unset)
    • Base URL override, for a self-hosted or proxied provider

Test runner

  • MOCKFORGE_RUNNER_QUEUE_KEY (default: test_runs:queued)
    • Redis key the runner pops queued test runs from
  • MOCKFORGE_RUNNER_MAX_CONCURRENT_JOBS (default: 4)
  • MOCKFORGE_RUNNER_POLL_TIMEOUT_SECS (default: 5)

Plugin egress proxy

  • MOCKFORGE_PLUGIN_EGRESS_LISTEN (default: 127.0.0.1:8125)
    • Listen address for the egress proxy
  • MOCKFORGE_PLUGIN_EGRESS_ALLOWLIST (default: unset)
    • Comma-separated hosts plugins may reach. Takes precedence over the file form
  • MOCKFORGE_PLUGIN_EGRESS_ALLOWLIST_FILE (default: unset)
    • Path to an allowlist file, one host per line

Plugin host

  • MOCKFORGE_PLUGIN_HOST_SOCKET (default: /tmp/plugin-host.sock)
    • Unix socket the plugin host listens on
  • MOCKFORGE_PLUGIN_HOST_SOCKET_MODE (default: platform default)
    • Permission bits for that socket. Accepts 0o660, 660, 0660 or 0x1B0
  • MOCKFORGE_PLUGIN_HOST_SIGNATURE_MODE=required|optional (default: optional)
    • Whether plugin signatures are enforced. An unrecognised value falls back to optional with a warning, so set this explicitly in production

Trusted signing keys, one of:

  • MOCKFORGE_PLUGIN_HOST_TRUSTED_KEYS (default: unset)
    • Inline comma-separated public keys
  • MOCKFORGE_PLUGIN_HOST_TRUSTED_KEYS_FILE (default: unset)
    • Path to a file of public keys

Remote trust root, blocklist, rotation and metrics are each off unless their URL is set. The bearer and interval variables only apply once the matching URL is present:

Trust root:

  • MOCKFORGE_PLUGIN_HOST_TRUST_ROOT_URL (default: unset, feature off)
  • MOCKFORGE_PLUGIN_HOST_TRUST_ROOT_BEARER (default: unset)
  • MOCKFORGE_PLUGIN_HOST_TRUST_ROOT_INTERVAL_SECS (default: built-in interval)

Blocklist:

  • MOCKFORGE_PLUGIN_HOST_BLOCKLIST_URL (default: unset, feature off)
  • MOCKFORGE_PLUGIN_HOST_BLOCKLIST_BEARER (default: unset)
  • MOCKFORGE_PLUGIN_HOST_BLOCKLIST_INTERVAL_SECS (default: built-in interval)

Key rotation:

  • MOCKFORGE_PLUGIN_HOST_ROTATION_INTERVAL_SECS (default: built-in interval)
  • MOCKFORGE_PLUGIN_HOST_ROTATION_BEARER (default: unset)

Metrics export:

  • MOCKFORGE_PLUGIN_HOST_METRICS_URL (default: unset, export off)
  • MOCKFORGE_PLUGIN_HOST_METRICS_BEARER (default: unset)
  • MOCKFORGE_PLUGIN_HOST_METRICS_FLUSH_INTERVAL_SECS (default: built-in interval)
  • MOCKFORGE_PLUGIN_HOST_METRICS_QUEUE_SIZE (default: built-in queue depth)

Test-only escape hatches

Both relax SSRF protection and must never be set in production. Each accepts 1 or true; anything else leaves the guard strict.

  • MOCKFORGE_SSRF_ALLOW_LOOPBACK (default: unset, guard strict)
    • Allows conformance/test-run targets to point at loopback addresses
  • MOCKFORGE_SSO_ALLOW_INSECURE_ISSUERS (default: unset, guard strict)
    • Allows http:// and localhost OIDC issuers. Logs a warning when set, because it disables the issuer SSRF guard that protects the verified-domain trust model

For more detailed configuration options, see the Configuration Files documentation.