Skip to content

Configuration

Wakemeup edited this page Jul 21, 2026 · 1 revision

Configuration

Hooray accepts strict YAML (.yaml/.yml) or TOML (.toml). Unknown fields are rejected. --config FILE selects a file; documented HOORAY_* environment variables override values.

Defaults

max_concurrency: 32
max_request_bytes: 1048576
max_input_bytes: 104857600
max_archive_bytes: 536870912
max_archive_entries: 100000
database_path: hooray.db
osv_url: https://api.osv.dev
osv_connect_timeout_secs: 10
osv_request_timeout_secs: 30
policy_path: hooray-policy.yaml
monitor_interval_secs: 300
api_bind: 127.0.0.1:8080
auth_bearer_sha256: null
offline: false

Environment variables

  • HOORAY_MAX_CONCURRENCY
  • HOORAY_MAX_REQUEST_BYTES
  • HOORAY_MAX_INPUT_BYTES
  • HOORAY_MAX_ARCHIVE_BYTES
  • HOORAY_MAX_ARCHIVE_ENTRIES
  • HOORAY_DATABASE_PATH
  • HOORAY_OSV_URL
  • HOORAY_OSV_CONNECT_TIMEOUT_SECS
  • HOORAY_OSV_REQUEST_TIMEOUT_SECS
  • HOORAY_POLICY_PATH
  • HOORAY_MONITOR_INTERVAL_SECS
  • HOORAY_API_BIND
  • HOORAY_AUTH_BEARER_SHA256
  • HOORAY_OFFLINE

Boolean environment values accept only documented strict spellings; malformed values fail configuration loading.

Authentication

auth_bearer_sha256 is the lowercase SHA-256 digest of the expected bearer token, not the token itself. A non-loopback api_bind is rejected unless authentication is configured. Tokens and their hashes are never echoed in API errors or debug output.

printf %s 'replace-with-a-long-random-token' | sha256sum

Clients send:

Authorization: Bearer replace-with-a-long-random-token

Offline mode

offline: true prevents vulnerability-provider calls. Local inventory, source, license, policy, reporting, and persistence still work. A policy file is still required when the configured path is used.

Resource limits

Limits are validated against zero, maximum, and overflow boundaries. Archive limits apply to cumulative image expansion. Report rendering has an independent 64 MiB output ceiling. API request bodies and concurrent scans are bounded.

Clone this wiki locally