Environment Variables That Control dcg Runtime Behavior: Complete Reference
Destructive Command Guard (dcg) reads over 30 DCG_* environment variables at startup, parsed by crate::config::Config::apply_env_overrides in src/config.rs, to configure update checks, policy modes, output formatting, git-aware protections, and emergency bypass mechanisms without recompiling the binary.
The open-source dcg (Destructive Command Guard) tool provides a configurable safety layer for destructive shell commands. According to the Dicklesworthstone/destructive_command_guard source code, runtime behavior is governed by environment variables processed during early startup in src/main.rs and consolidated through Config::apply_env_overrides in src/config.rs. These variables allow operators to toggle packs, adjust timeouts, disable telemetry, or enforce fail-closed policies without modifying TOML configuration files.
Update Checks and Self-Healing
The following variables control whether dcg phones home for updates or attempts to repair broken installations:
DCG_NO_UPDATE_CHECK– When set to any value, disables the automatic check for newer versions. Parsed insrc/update.rs#L861.DCG_CHECK_UPDATES– Explicitly enables or disables update checks, overriding the default behavior. Defined insrc/config.rs#L3601.DCG_SELF_HEAL_HOOK– Enables the self-heal hook that attempts to auto-fix a broken installation. Defined insrc/config.rs#L3615.DCG_NO_SELF_HEAL– A convenience shortcut that disables the self-heal hook when set.
Policy Enforcement and Timing
These variables govern how long hooks may run and the default security posture:
DCG_HOOK_TIMEOUT_MS– Maximum time in milliseconds that a hook may run before dcg fails open. Defined insrc/config.rs#L3630.DCG_POLICY_DEFAULT_MODE– Sets the default policy when no specific rule matches; acceptsdeny,warn, orlog. Defined insrc/config.rs#L3683.DCG_POLICY_OBSERVE_UNTIL– An ISO-8601 timestamp after which the default mode automatically reverts todeny. Defined insrc/config.rs#L3690.
Heredoc Parsing Configuration
dcg can parse code inside heredocs for additional languages. These variables control that behavior:
DCG_HEREDOC_ENABLED– Enables the extra heredoc parser, which is more accurate but computationally costly. Defined insrc/config.rs#L3652.DCG_HEREDOC_TIMEOUT_MS– Timeout in milliseconds for the heredoc parser before giving up. Defined insrc/config.rs#L3660.DCG_HEREDOC_LANGUAGES– Comma-separated list of languages to analyze inside heredocs (e.g.,python,bash). Defined insrc/config.rs#L3667.
Output Formatting and Color Control
Control terminal output, colors, and machine-readable formats:
NO_COLOR– Standard variable that disables colored output when set. Checked insrc/main.rs#L68.DCG_NO_COLOR– Same purpose asNO_COLOR, but preferred for dcg-specific configuration. Checked insrc/output/mod.rs#L19.DCG_NO_RICH– Forces plain terminal output even when a TTY is detected. Checked insrc/output/mod.rs#L86.DCG_HIGH_CONTRAST– Switches the palette to a high-contrast scheme for low-quality terminals. Checked insrc/output/mod.rs#L158.DCG_COLOR– Explicitly controls color mode with valuesalways,never, orauto. Checked insrc/output/mod.rs#L175.DCG_ROBOT– Forces "robot" output mode, emitting only machine-readable JSON. Checked insrc/output/mod.rs#L244.DCG_VERBOSE– Sets logging verbosity level (0–3). Parsed insrc/main.rs#L1144.DCG_QUIET– Reduces log verbosity, inverse ofDCG_VERBOSE.
Failure-Closed Security Mode
DCG_FAIL_CLOSED– When set to any truthy value, any internal error results in a denial rather than allowing the command to proceed. This is parsed early insrc/main.rs#L259.
Bypass and Exception Handling
Emergency overrides and one-time exception mechanisms:
DCG_BYPASS– Dangerous. Disables all protection for the current process. Use with extreme caution. Defined insrc/config.rs#L3875.DCG_ALLOW_ONCE_PATH– Path to a file storing one-time allow codes. Defined insrc/pending_exceptions.rs#L25.DCG_ALLOW_ONCE_SECRET– Secret used to HMAC-sign allow-once codes to prevent tampering. Defined insrc/pending_exceptions.rs#L28.DCG_PENDING_EXCEPTIONS_PATH– Path to a JSON file listing pending exception hashes. Defined insrc/pending_exceptions.rs#L23.
History and Telemetry Storage
Control the SQLite-based command history stored for forensics:
DCG_HISTORY_DB– Overrides the default SQLite file path for command-history storage. Used insrc/history/mod.rs#L58.DCG_HISTORY_DISABLED– Disables history collection entirely. Used insrc/history/mod.rs#L61.DCG_HISTORY_ENABLED– Explicitly enables history collection. Defined insrc/config.rs#L3699.DCG_HISTORY_REDACTION_MODE– Controls command redaction with valuesnone,pattern, orfull. Defined insrc/config.rs#L3706.
Interactive Prompt Settings
When dcg is configured to ask the user for confirmation codes, these variables adjust the behavior:
DCG_INTERACTIVE_ENABLED– Turns the interactive "ask-for-code" mode on or off. Defined insrc/config.rs#L3717.DCG_INTERACTIVE_VERIFICATION– Chooses the verification method:code,command, ornone. Defined insrc/config.rs#L3724.DCG_INTERACTIVE_TIMEOUT_SECONDS– How long dcg waits for user response before falling back to default policy. Defined insrc/config.rs#L3731.DCG_INTERACTIVE_CODE_LENGTH– Length of the temporary allow-once code shown to the user. Defined insrc/config.rs#L3740.DCG_INTERACTIVE_MAX_ATTEMPTS– Maximum retry attempts before giving up. Defined insrc/config.rs#L3747.DCG_INTERACTIVE_ALLOW_NON_TTY_FALLBACK– Allows interactive mode to run even when stdin is not a TTY. Defined insrc/config.rs#L3754.DCG_INTERACTIVE_DISABLE_IN_CI– Auto-disables interactive prompts when a CI environment is detected. Defined insrc/config.rs#L3761.DCG_INTERACTIVE_REQUIRE_ENV– Requires a specific environment variable to be present for interactive mode to activate. Defined insrc/config.rs#L3768.
Git-Aware Branch Protection
Configure repository-aware protections that treat protected branches differently:
DCG_GIT_AWARENESS_ENABLED– Turns on git-aware heuristics including branch detection and protected-branch enforcement. Defined insrc/config.rs#L3782.DCG_GIT_PROTECTED_BRANCHES– Comma-separated list of branches considered protected (e.g.,main,production). Defined insrc/config.rs#L3790.DCG_GIT_PROTECTED_STRICTNESS– Severity level for protected-branch violations (critical,high,medium,low). Defined insrc/config.rs#L3802.DCG_GIT_RELAXED_BRANCHES– Branches exempt from protected-branch rules. Defined insrc/config.rs#L3809.DCG_GIT_RELAXED_STRICTNESS– Severity level for the relaxed branch list. Defined insrc/config.rs#L3821.DCG_GIT_DEFAULT_STRICTNESS– Default severity when a branch is not explicitly listed. Defined insrc/config.rs#L3828.DCG_GIT_DETACHED_HEAD_STRICTNESS– Severity for detached-HEAD situations. Defined insrc/config.rs#L3835.DCG_GIT_RELAXED_DISABLED_PACKS– Packs that are disabled when a relaxed branch is active. Defined insrc/config.rs#L3842.DCG_GIT_SHOW_BRANCH_IN_OUTPUT– If true, includes the current git branch in JSON denial payloads. Defined insrc/config.rs#L3852.DCG_GIT_AWARENESS_WARN_IF_NOT_GIT– Emits a warning when dcg runs outside a git repository. Defined insrc/config.rs#L3859.
Pack Management
Control which detection packs are loaded and which are disabled:
DCG_PACKS– Comma-separated list of pack identifiers to load (e.g.,core,aws). Parsed insrc/config.rs#L3575.DCG_DISABLE– Comma-separated list of pack identifiers to explicitly disable. Parsed insrc/config.rs#L3580.DCG_CUSTOM_PATHS– Glob patterns pointing to additional pack YAML files. Parsed insrc/config.rs#L3585.
General Runtime Flags
Miscellaneous settings affecting configuration loading and interaction:
DCG_NON_INTERACTIVE– Forces dcg to behave as if not attached to an interactive terminal, commonly used in CI. Handled insrc/cli.rs#L3600.DCG_FORMAT– Selects output format such asjsonorpretty. Parsed insrc/main.rs#L1164.DCG_CONFIG– Path to a custom TOML configuration file, overriding default search locations. Parsed insrc/main.rs#L1168.
Standard Shell Variables
dcg also respects standard environment variables for terminal capabilities and paths:
TERMandCOLORTERM– Used to detect terminal capabilities affecting color output. Checked insrc/output/mod.rs#L261.HOME,XDG_CONFIG_HOME, andProgramData– Determine default configuration and history file locations across platforms.
How Environment Variables Are Applied
The precedence order is strict: explicit configuration file → environment variable overrides → compiled defaults.
During early startup, src/main.rs parses critical flags like DCG_BYPASS, DCG_NO_COLOR, and DCG_FORMAT before any command evaluation. Subsequently, Config::apply_env_overrides in src/config.rs collects all DCG_* variables. Subsystems query their state via env_flag_enabled or env_flag_enabled_with helper functions located in src/output/mod.rs, which centralize boolean parsing logic (interpreting 1, true, yes, etc., as enabled).
Practical Configuration Examples
Set these variables in your shell before invoking dcg:
# Disable update checks and enable high-contrast output for CI
export DCG_NO_UPDATE_CHECK=1
export DCG_HIGH_CONTRAST=1
export DCG_NON_INTERACTIVE=1
# Load only core and AWS packs, disable Kubernetes checks
export DCG_PACKS="core,aws"
export DCG_DISABLE="kubernetes"
# Force fail-closed mode for maximum security
export DCG_FAIL_CLOSED=true
# Set a 100ms hook timeout for low-latency environments
export DCG_HOOK_TIMEOUT_MS=100
# Completely bypass protection (use with extreme caution)
export DCG_BYPASS=1
dcg --explain "git reset --hard"
In Rust applications embedding dcg, you can set these programmatically:
// Disable automatic updates
std::env::set_var("DCG_NO_UPDATE_CHECK", "1");
// Configure custom packs
std::env::set_var("DCG_PACKS", "core,aws,database.postgresql");
std::env::set_var("DCG_DISABLE", "kubernetes");
// Enable strict failure mode
std::env::set_var("DCG_FAIL_CLOSED", "true");
Summary
- Primary parsing occurs in
crate::config::Config::apply_env_overrideswithinsrc/config.rs. - Precedence follows: config file → environment variables → defaults.
- Boolean flags are interpreted by
env_flag_enabledinsrc/output/mod.rsaccepting1,true,yes, etc. - Critical security variables include
DCG_FAIL_CLOSEDfor denial-on-error andDCG_BYPASSfor emergency disabling. - Output control respects both standard
NO_COLORand dcg-specificDCG_NO_COLOR,DCG_ROBOT, andDCG_FORMAT. - Git-aware protections use the
DCG_GIT_*family to enforce branch-specific policies.
Frequently Asked Questions
How do I temporarily disable dcg protection for a single command?
Set the DCG_BYPASS environment variable to any truthy value before running your command. This variable is evaluated in src/config.rs#L3875 and causes dcg to allow all commands without inspection. Use this only in emergency situations, as it removes all protections.
Why does dcg still show colors after I set NO_COLOR?
Check for DCG_NO_COLOR or DCG_COLOR overriding the standard variable. While NO_COLOR is read in src/main.rs#L68, dcg-specific variables take precedence. Set DCG_COLOR=never to explicitly force monochrome output regardless of terminal detection.
Can I disable automatic update checks in CI pipelines?
Yes. Export DCG_NO_UPDATE_CHECK=1 or DCG_CHECK_UPDATES=0 before invoking dcg. The check is handled in src/update.rs#L861 and skips the network request when these variables are present, preventing CI timeouts or unnecessary network traffic.
How does dcg interpret boolean values in environment variables?
Boolean parsing is centralized in env_flag_enabled and env_flag_enabled_with functions located in src/output/mod.rs. These functions recognize 1, true, yes, on, and enabled as affirmative values, while 0, false, no, off, and disabled are treated as negative. Case-insensitive comparison is used.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →