# Environment Variables That Control dcg Runtime Behavior: Complete Reference

> Discover over 30 DCG environment variables that control runtime behavior like policy modes output formatting and git-aware protections without recompiling. Comprehensive reference for Destructive Command Guard.

- Repository: [Jeff Emanuel/destructive_command_guard](https://github.com/Dicklesworthstone/destructive_command_guard)
- Tags: api-reference
- Published: 2026-07-14

---

**Destructive Command Guard (dcg) reads over 30 `DCG_*` environment variables at startup, parsed by `crate::config::Config::apply_env_overrides` in [`src/config.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/config.rs), to configure update checks, policy modes, output formatting, git-aware protections, and emergency bypass mechanisms without recompiling the binary.**

The open-source `dcg` (Destructive Command Guard) tool provides a configurable safety layer for destructive shell commands. According to the Dicklesworthstone/destructive_command_guard source code, runtime behavior is governed by environment variables processed during early startup in [`src/main.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/main.rs) and consolidated through `Config::apply_env_overrides` in [`src/config.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/config.rs). These variables allow operators to toggle packs, adjust timeouts, disable telemetry, or enforce fail-closed policies without modifying TOML configuration files.

## Update Checks and Self-Healing

The following variables control whether dcg phones home for updates or attempts to repair broken installations:

- **`DCG_NO_UPDATE_CHECK`** – When set to any value, disables the automatic check for newer versions. Parsed in `src/update.rs#L861`.
- **`DCG_CHECK_UPDATES`** – Explicitly enables or disables update checks, overriding the default behavior. Defined in `src/config.rs#L3601`.
- **`DCG_SELF_HEAL_HOOK`** – Enables the self-heal hook that attempts to auto-fix a broken installation. Defined in `src/config.rs#L3615`.
- **`DCG_NO_SELF_HEAL`** – A convenience shortcut that disables the self-heal hook when set.

## Policy Enforcement and Timing

These variables govern how long hooks may run and the default security posture:

- **`DCG_HOOK_TIMEOUT_MS`** – Maximum time in milliseconds that a hook may run before dcg fails open. Defined in `src/config.rs#L3630`.
- **`DCG_POLICY_DEFAULT_MODE`** – Sets the default policy when no specific rule matches; accepts `deny`, `warn`, or `log`. Defined in `src/config.rs#L3683`.
- **`DCG_POLICY_OBSERVE_UNTIL`** – An ISO-8601 timestamp after which the default mode automatically reverts to `deny`. Defined in `src/config.rs#L3690`.

## Heredoc Parsing Configuration

dcg can parse code inside heredocs for additional languages. These variables control that behavior:

- **`DCG_HEREDOC_ENABLED`** – Enables the extra heredoc parser, which is more accurate but computationally costly. Defined in `src/config.rs#L3652`.
- **`DCG_HEREDOC_TIMEOUT_MS`** – Timeout in milliseconds for the heredoc parser before giving up. Defined in `src/config.rs#L3660`.
- **`DCG_HEREDOC_LANGUAGES`** – Comma-separated list of languages to analyze inside heredocs (e.g., `python,bash`). Defined in `src/config.rs#L3667`.

## Output Formatting and Color Control

Control terminal output, colors, and machine-readable formats:

- **`NO_COLOR`** – Standard variable that disables colored output when set. Checked in `src/main.rs#L68`.
- **`DCG_NO_COLOR`** – Same purpose as `NO_COLOR`, but preferred for dcg-specific configuration. Checked in `src/output/mod.rs#L19`.
- **`DCG_NO_RICH`** – Forces plain terminal output even when a TTY is detected. Checked in `src/output/mod.rs#L86`.
- **`DCG_HIGH_CONTRAST`** – Switches the palette to a high-contrast scheme for low-quality terminals. Checked in `src/output/mod.rs#L158`.
- **`DCG_COLOR`** – Explicitly controls color mode with values `always`, `never`, or `auto`. Checked in `src/output/mod.rs#L175`.
- **`DCG_ROBOT`** – Forces "robot" output mode, emitting only machine-readable JSON. Checked in `src/output/mod.rs#L244`.
- **`DCG_VERBOSE`** – Sets logging verbosity level (0–3). Parsed in `src/main.rs#L1144`.
- **`DCG_QUIET`** – Reduces log verbosity, inverse of `DCG_VERBOSE`.

## Failure-Closed Security Mode

- **`DCG_FAIL_CLOSED`** – When set to any truthy value, any internal error results in a denial rather than allowing the command to proceed. This is parsed early in `src/main.rs#L259`.

## Bypass and Exception Handling

Emergency overrides and one-time exception mechanisms:

- **`DCG_BYPASS`** – **Dangerous.** Disables all protection for the current process. Use with extreme caution. Defined in `src/config.rs#L3875`.
- **`DCG_ALLOW_ONCE_PATH`** – Path to a file storing one-time allow codes. Defined in `src/pending_exceptions.rs#L25`.
- **`DCG_ALLOW_ONCE_SECRET`** – Secret used to HMAC-sign allow-once codes to prevent tampering. Defined in `src/pending_exceptions.rs#L28`.
- **`DCG_PENDING_EXCEPTIONS_PATH`** – Path to a JSON file listing pending exception hashes. Defined in `src/pending_exceptions.rs#L23`.

## History and Telemetry Storage

Control the SQLite-based command history stored for forensics:

- **`DCG_HISTORY_DB`** – Overrides the default SQLite file path for command-history storage. Used in `src/history/mod.rs#L58`.
- **`DCG_HISTORY_DISABLED`** – Disables history collection entirely. Used in `src/history/mod.rs#L61`.
- **`DCG_HISTORY_ENABLED`** – Explicitly enables history collection. Defined in `src/config.rs#L3699`.
- **`DCG_HISTORY_REDACTION_MODE`** – Controls command redaction with values `none`, `pattern`, or `full`. Defined in `src/config.rs#L3706`.

## Interactive Prompt Settings

When dcg is configured to ask the user for confirmation codes, these variables adjust the behavior:

- **`DCG_INTERACTIVE_ENABLED`** – Turns the interactive "ask-for-code" mode on or off. Defined in `src/config.rs#L3717`.
- **`DCG_INTERACTIVE_VERIFICATION`** – Chooses the verification method: `code`, `command`, or `none`. Defined in `src/config.rs#L3724`.
- **`DCG_INTERACTIVE_TIMEOUT_SECONDS`** – How long dcg waits for user response before falling back to default policy. Defined in `src/config.rs#L3731`.
- **`DCG_INTERACTIVE_CODE_LENGTH`** – Length of the temporary allow-once code shown to the user. Defined in `src/config.rs#L3740`.
- **`DCG_INTERACTIVE_MAX_ATTEMPTS`** – Maximum retry attempts before giving up. Defined in `src/config.rs#L3747`.
- **`DCG_INTERACTIVE_ALLOW_NON_TTY_FALLBACK`** – Allows interactive mode to run even when stdin is not a TTY. Defined in `src/config.rs#L3754`.
- **`DCG_INTERACTIVE_DISABLE_IN_CI`** – Auto-disables interactive prompts when a CI environment is detected. Defined in `src/config.rs#L3761`.
- **`DCG_INTERACTIVE_REQUIRE_ENV`** – Requires a specific environment variable to be present for interactive mode to activate. Defined in `src/config.rs#L3768`.

## Git-Aware Branch Protection

Configure repository-aware protections that treat protected branches differently:

- **`DCG_GIT_AWARENESS_ENABLED`** – Turns on git-aware heuristics including branch detection and protected-branch enforcement. Defined in `src/config.rs#L3782`.
- **`DCG_GIT_PROTECTED_BRANCHES`** – Comma-separated list of branches considered protected (e.g., `main,production`). Defined in `src/config.rs#L3790`.
- **`DCG_GIT_PROTECTED_STRICTNESS`** – Severity level for protected-branch violations (`critical`, `high`, `medium`, `low`). Defined in `src/config.rs#L3802`.
- **`DCG_GIT_RELAXED_BRANCHES`** – Branches exempt from protected-branch rules. Defined in `src/config.rs#L3809`.
- **`DCG_GIT_RELAXED_STRICTNESS`** – Severity level for the relaxed branch list. Defined in `src/config.rs#L3821`.
- **`DCG_GIT_DEFAULT_STRICTNESS`** – Default severity when a branch is not explicitly listed. Defined in `src/config.rs#L3828`.
- **`DCG_GIT_DETACHED_HEAD_STRICTNESS`** – Severity for detached-HEAD situations. Defined in `src/config.rs#L3835`.
- **`DCG_GIT_RELAXED_DISABLED_PACKS`** – Packs that are disabled when a relaxed branch is active. Defined in `src/config.rs#L3842`.
- **`DCG_GIT_SHOW_BRANCH_IN_OUTPUT`** – If true, includes the current git branch in JSON denial payloads. Defined in `src/config.rs#L3852`.
- **`DCG_GIT_AWARENESS_WARN_IF_NOT_GIT`** – Emits a warning when dcg runs outside a git repository. Defined in `src/config.rs#L3859`.

## Pack Management

Control which detection packs are loaded and which are disabled:

- **`DCG_PACKS`** – Comma-separated list of pack identifiers to load (e.g., `core,aws`). Parsed in `src/config.rs#L3575`.
- **`DCG_DISABLE`** – Comma-separated list of pack identifiers to explicitly disable. Parsed in `src/config.rs#L3580`.
- **`DCG_CUSTOM_PATHS`** – Glob patterns pointing to additional pack YAML files. Parsed in `src/config.rs#L3585`.

## General Runtime Flags

Miscellaneous settings affecting configuration loading and interaction:

- **`DCG_NON_INTERACTIVE`** – Forces dcg to behave as if not attached to an interactive terminal, commonly used in CI. Handled in `src/cli.rs#L3600`.
- **`DCG_FORMAT`** – Selects output format such as `json` or `pretty`. Parsed in `src/main.rs#L1164`.
- **`DCG_CONFIG`** – Path to a custom TOML configuration file, overriding default search locations. Parsed in `src/main.rs#L1168`.

## Standard Shell Variables

dcg also respects standard environment variables for terminal capabilities and paths:

- **`TERM`** and **`COLORTERM`** – Used to detect terminal capabilities affecting color output. Checked in `src/output/mod.rs#L261`.
- **`HOME`**, **`XDG_CONFIG_HOME`**, and **`ProgramData`** – Determine default configuration and history file locations across platforms.

## How Environment Variables Are Applied

The precedence order is strict: **explicit configuration file → environment variable overrides → compiled defaults**.

During early startup, [`src/main.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/main.rs) parses critical flags like `DCG_BYPASS`, `DCG_NO_COLOR`, and `DCG_FORMAT` before any command evaluation. Subsequently, `Config::apply_env_overrides` in [`src/config.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/config.rs) collects all `DCG_*` variables. Subsystems query their state via `env_flag_enabled` or `env_flag_enabled_with` helper functions located in [`src/output/mod.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/output/mod.rs), which centralize boolean parsing logic (interpreting `1`, `true`, `yes`, etc., as enabled).

## Practical Configuration Examples

Set these variables in your shell before invoking `dcg`:

```bash

# Disable update checks and enable high-contrast output for CI

export DCG_NO_UPDATE_CHECK=1
export DCG_HIGH_CONTRAST=1
export DCG_NON_INTERACTIVE=1

# Load only core and AWS packs, disable Kubernetes checks

export DCG_PACKS="core,aws"
export DCG_DISABLE="kubernetes"

# Force fail-closed mode for maximum security

export DCG_FAIL_CLOSED=true

# Set a 100ms hook timeout for low-latency environments

export DCG_HOOK_TIMEOUT_MS=100

# Completely bypass protection (use with extreme caution)

export DCG_BYPASS=1

dcg --explain "git reset --hard"

```

In Rust applications embedding dcg, you can set these programmatically:

```rust
// Disable automatic updates
std::env::set_var("DCG_NO_UPDATE_CHECK", "1");

// Configure custom packs
std::env::set_var("DCG_PACKS", "core,aws,database.postgresql");
std::env::set_var("DCG_DISABLE", "kubernetes");

// Enable strict failure mode
std::env::set_var("DCG_FAIL_CLOSED", "true");

```

## Summary

- **Primary parsing** occurs in `crate::config::Config::apply_env_overrides` within [`src/config.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/config.rs).
- **Precedence** follows: config file → environment variables → defaults.
- **Boolean flags** are interpreted by `env_flag_enabled` in [`src/output/mod.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/output/mod.rs) accepting `1`, `true`, `yes`, etc.
- **Critical security variables** include `DCG_FAIL_CLOSED` for denial-on-error and `DCG_BYPASS` for emergency disabling.
- **Output control** respects both standard `NO_COLOR` and dcg-specific `DCG_NO_COLOR`, `DCG_ROBOT`, and `DCG_FORMAT`.
- **Git-aware protections** use the `DCG_GIT_*` family to enforce branch-specific policies.

## Frequently Asked Questions

### How do I temporarily disable dcg protection for a single command?

Set the **`DCG_BYPASS`** environment variable to any truthy value before running your command. This variable is evaluated in `src/config.rs#L3875` and causes dcg to allow all commands without inspection. Use this only in emergency situations, as it removes all protections.

### Why does dcg still show colors after I set `NO_COLOR`?

Check for **`DCG_NO_COLOR`** or **`DCG_COLOR`** overriding the standard variable. While `NO_COLOR` is read in `src/main.rs#L68`, dcg-specific variables take precedence. Set **`DCG_COLOR=never`** to explicitly force monochrome output regardless of terminal detection.

### Can I disable automatic update checks in CI pipelines?

Yes. Export **`DCG_NO_UPDATE_CHECK=1`** or **`DCG_CHECK_UPDATES=0`** before invoking dcg. The check is handled in `src/update.rs#L861` and skips the network request when these variables are present, preventing CI timeouts or unnecessary network traffic.

### How does dcg interpret boolean values in environment variables?

Boolean parsing is centralized in **`env_flag_enabled`** and **`env_flag_enabled_with`** functions located in [`src/output/mod.rs`](https://github.com/Dicklesworthstone/destructive_command_guard/blob/main/src/output/mod.rs). These functions recognize `1`, `true`, `yes`, `on`, and `enabled` as affirmative values, while `0`, `false`, `no`, `off`, and `disabled` are treated as negative. Case-insensitive comparison is used.