Workspaces

Configuration

How to configure workspace images: custom images, environment variables, OTel endpoints, and plugin configuration.

Choosing a Workspace Image

The default workspace image is agentic-workspace-toolchain, pinned by digest in syn-shared. It is the omni-agent image (both the claude and the codex harness, so switching a phase's agent.provider needs no image change) plus a native build floor: a C toolchain, rustup, pnpm and bun.

# Override via environment variable
SYN_WORKSPACE_DOCKER_IMAGE=ghcr.io/agentparadise/agentic-workspace-toolchain@sha256:<digest>

To use a custom or locally-built image:

# Build locally
cd lib/agentic-workspace
uv run scripts/build-provider.py omni-agent --tag my-workspace:latest

# Point syn137 at it. A local image has no signature, so it must be
# allowed explicitly and must already exist on the Docker host.
SYN_WORKSPACE_DOCKER_IMAGE=my-workspace:latest
SYN_IMAGE_VERIFY_ALLOW_LOCAL_IMAGES=true

Environment Variables

Set by the Image (Defaults)

These are baked into the image and generally should not be overridden:

VariableDefaultPurpose
ANTHROPIC_NO_ATTRIBUTION1Disable Claude attribution in commits
DISABLE_TELEMETRY1Disable vendor usage metrics
DISABLE_ERROR_REPORTING1Disable vendor error reporting
RTK_TELEMETRY_DISABLED1Disable RTK analytics
CLAUDE_CODE_ENABLE_TELEMETRY1Enable OTel metric export
OTEL_METRICS_EXPORTERotlpExport metrics via OTLP
OTEL_METRIC_EXPORT_INTERVAL50005s export interval

Set by Orchestrator at Runtime

These are injected automatically by syn137 when creating workspaces:

VariablePurpose
ANTHROPIC_API_KEYClaude API key, for claude phases (injected via sidecar)
CODEX_AUTH_JSONDeployment variable, not injected into the workspace. Provisioning stages its contents to ~/.codex/auth.json at mode 0600 and deletes the staged copy. A codex phase runs with an empty agent environment
CLAUDE_CODE_ENABLE_TELEMETRYActivates OTel export (set to 1 when collector is configured)
OTEL_EXPORTER_OTLP_ENDPOINTCollector endpoint, auto-set to COLLECTOR_URL from syn-api config
GITHUB_TOKENGitHub access (injected via sidecar)
GH_REPOThe primary repo as owner/repo, so gh resolves a repository without a working tree to infer one from. Absent when the workflow configures no repo, or when the primary one does not parse. See Workspace Hydration.
CLAUDE_SESSION_IDThe session this phase's events are keyed by

You do not need to set these manually. The orchestrator injects them when workspace containers are provisioned.

Container environment is not the agent environment. The table above is what the workspace container receives. The environment handed to the agent process is built separately and is narrower. A claude phase gets its Anthropic credential there. A codex phase gets an empty agent environment, which is precisely what keeps ANTHROPIC_API_KEY and CLAUDE_CODE_OAUTH_TOKEN out of reach of a codex run, and its own credential arrives as the staged ~/.codex/auth.json file rather than as a variable.

OTel Configuration

How OTel connects to syn-collector

OTel export is a claude harness feature. Codex phases emit no OTel metrics or logs. CLAUDE_CODE_ENABLE_TELEMETRY=1 is baked into the workspace image as a default. When syn-api has COLLECTOR_URL set, it also injects OTEL_EXPORTER_OTLP_ENDPOINT pointing at the collector. If no COLLECTOR_URL is configured, OTel export silently no-ops, no crash, no side effects.

syn-collector's internal port is 8080 (service name collector inside Docker). The dev stack maps it to localhost:8080.

# Inside Docker (agent-net), what the container uses:
http://collector:8080

# From your host machine, for debugging:
http://localhost:8080

syn-collector accepts OTLP JSON on /v1/metrics and /v1/logs.

Privacy Controls

By default, prompt content and tool I/O are not exported:

OTEL_LOG_USER_PROMPTS=0   # Don't log prompt content
OTEL_LOG_TOOL_DETAILS=0   # Don't log tool input/output

Set to 1 to enable detailed logging (useful for debugging, not recommended for production).

Plugin Configuration

Plugins are loaded from /opt/agentic/plugins/ at container startup. The entrypoint builds --plugin-dir flags for each discovered plugin directory.

Plugin Environment Variables

Plugins can declare required environment variables in their plugin.json. The orchestrator auto-forwards these from the workspace configuration. See ADR-033 for the plugin specification (moved from agentic-primitives, 2026-09, see #1417).

Workspace Directory Structure

/workspace/
  AGENTS.md              # Synthesized - imports each repo's AGENTS.md (when repos configured)
  CLAUDE.md              # Synthesized - imports each repo's CLAUDE.md (when repos configured)
  artifacts/
    input/               # Previous phase outputs (read-only)
    output/              # Current phase deliverables
  repos/                 # Always present; empty when the phase set clone_repos: false
    api-service/         # The bare repo name - the owner is not in the path
    web-app/
/opt/agentic/
  plugins/               # Pre-bundled plugins
  config/                # Runtime configuration
  version.json           # Image version manifest
  entrypoint.sh

See Workspace Hydration for how repos are cloned and context files are synthesized.

Syntropic137 Docs v0.33.1 · Last updated March 2026

On this page