Configuration
How to configure workspace images: custom images, environment variables, OTel endpoints, and plugin configuration.
Choosing a Workspace Image
The default workspace image is agentic-workspace-toolchain, pinned by digest in syn-shared. It is the omni-agent image (both the claude and the codex harness, so switching a phase's agent.provider needs no image change) plus a native build floor: a C toolchain, rustup, pnpm and bun.
# Override via environment variable
SYN_WORKSPACE_DOCKER_IMAGE=ghcr.io/agentparadise/agentic-workspace-toolchain@sha256:<digest>To use a custom or locally-built image:
# Build locally
cd lib/agentic-workspace
uv run scripts/build-provider.py omni-agent --tag my-workspace:latest
# Point syn137 at it. A local image has no signature, so it must be
# allowed explicitly and must already exist on the Docker host.
SYN_WORKSPACE_DOCKER_IMAGE=my-workspace:latest
SYN_IMAGE_VERIFY_ALLOW_LOCAL_IMAGES=trueEnvironment Variables
Set by the Image (Defaults)
These are baked into the image and generally should not be overridden:
| Variable | Default | Purpose |
|---|---|---|
ANTHROPIC_NO_ATTRIBUTION | 1 | Disable Claude attribution in commits |
DISABLE_TELEMETRY | 1 | Disable vendor usage metrics |
DISABLE_ERROR_REPORTING | 1 | Disable vendor error reporting |
RTK_TELEMETRY_DISABLED | 1 | Disable RTK analytics |
CLAUDE_CODE_ENABLE_TELEMETRY | 1 | Enable OTel metric export |
OTEL_METRICS_EXPORTER | otlp | Export metrics via OTLP |
OTEL_METRIC_EXPORT_INTERVAL | 5000 | 5s export interval |
Set by Orchestrator at Runtime
These are injected automatically by syn137 when creating workspaces:
| Variable | Purpose |
|---|---|
ANTHROPIC_API_KEY | Claude API key, for claude phases (injected via sidecar) |
CODEX_AUTH_JSON | Deployment variable, not injected into the workspace. Provisioning stages its contents to ~/.codex/auth.json at mode 0600 and deletes the staged copy. A codex phase runs with an empty agent environment |
CLAUDE_CODE_ENABLE_TELEMETRY | Activates OTel export (set to 1 when collector is configured) |
OTEL_EXPORTER_OTLP_ENDPOINT | Collector endpoint, auto-set to COLLECTOR_URL from syn-api config |
GITHUB_TOKEN | GitHub access (injected via sidecar) |
GH_REPO | The primary repo as owner/repo, so gh resolves a repository without a working tree to infer one from. Absent when the workflow configures no repo, or when the primary one does not parse. See Workspace Hydration. |
CLAUDE_SESSION_ID | The session this phase's events are keyed by |
You do not need to set these manually. The orchestrator injects them when workspace containers are provisioned.
Container environment is not the agent environment. The table above is what
the workspace container receives. The environment handed to the agent
process is built separately and is narrower. A claude phase gets its Anthropic
credential there. A codex phase gets an empty agent environment, which is
precisely what keeps ANTHROPIC_API_KEY and CLAUDE_CODE_OAUTH_TOKEN out of
reach of a codex run, and its own credential arrives as the staged
~/.codex/auth.json file rather than as a variable.
OTel Configuration
How OTel connects to syn-collector
OTel export is a claude harness feature. Codex phases emit no OTel metrics or logs. CLAUDE_CODE_ENABLE_TELEMETRY=1 is baked into the workspace image as a default. When syn-api has COLLECTOR_URL set, it also injects OTEL_EXPORTER_OTLP_ENDPOINT pointing at the collector. If no COLLECTOR_URL is configured, OTel export silently no-ops, no crash, no side effects.
syn-collector's internal port is 8080 (service name collector inside Docker). The dev stack maps it to localhost:8080.
# Inside Docker (agent-net), what the container uses:
http://collector:8080
# From your host machine, for debugging:
http://localhost:8080syn-collector accepts OTLP JSON on /v1/metrics and /v1/logs.
Privacy Controls
By default, prompt content and tool I/O are not exported:
OTEL_LOG_USER_PROMPTS=0 # Don't log prompt content
OTEL_LOG_TOOL_DETAILS=0 # Don't log tool input/outputSet to 1 to enable detailed logging (useful for debugging, not recommended for production).
Plugin Configuration
Plugins are loaded from /opt/agentic/plugins/ at container startup. The entrypoint builds --plugin-dir flags for each discovered plugin directory.
Plugin Environment Variables
Plugins can declare required environment variables in their plugin.json. The orchestrator auto-forwards these from the workspace configuration. See ADR-033 for the plugin specification (moved from agentic-primitives, 2026-09, see #1417).
Workspace Directory Structure
/workspace/
AGENTS.md # Synthesized - imports each repo's AGENTS.md (when repos configured)
CLAUDE.md # Synthesized - imports each repo's CLAUDE.md (when repos configured)
artifacts/
input/ # Previous phase outputs (read-only)
output/ # Current phase deliverables
repos/ # Always present; empty when the phase set clone_repos: false
api-service/ # The bare repo name - the owner is not in the path
web-app/
/opt/agentic/
plugins/ # Pre-bundled plugins
config/ # Runtime configuration
version.json # Image version manifest
entrypoint.shSee Workspace Hydration for how repos are cloned and context files are synthesized.
Syntropic137 Docs v0.33.1 · Last updated March 2026