Configuration
Configuration
preflight init writes preflight.yml to your project’s root. Commit it, so every machine and every CI run scans the same way.
An example
projectName: my-app
stack: rails # rails, next, react, vite, laravel and so on
urls:
staging: "https://staging.example.com"
production: "https://example.com"
services:
stripe:
declared: true
sentry:
declared: true
checks:
envParity:
enabled: true
envFile: ".env"
exampleFile: ".env.example"
healthEndpoint:
enabled: true
path: "/health" # optional: the common paths are tried when it isn't set
stripeWebhook:
enabled: true
url: "https://api.example.com/webhooks/stripe" # optional: probed with a GET
seoMeta:
enabled: true
mainLayout: "app/views/layouts/application.html.erb"
security:
enabled: true
secrets:
enabled: true
allowlist:
- path: web/js/golden-hour.js
fingerprint: "sha256:<hex>"
reason: "HTTP-referrer-restricted Google Timezone key"
indexNow:
enabled: true
key: "your32characterhexkeyhere00000"
emailAuth:
enabled: true # opt-in: SPF and DMARC on the production domain
humansTxt:
enabled: false # opt-in: credits the team
license:
enabled: false # opt-in: for open source projects
ignore:
- sitemap
- llms_txt
- google_analyticsThe project
projectName names the project in the report and on the dashboard. stack tells the checks where to look: which layout holds the meta tags, where the public files live, which package manager to audit. preflight init detects it; see supported stacks for the values.
URLs
urls.production and urls.staging are where the network checks go: ssl, security_headers, www_redirect, health_endpoint and the checks that read the rendered page. preflight init asks for both, and both are optional. A check with no URL to fetch passes with a note saying so, and the rest of the scan reads only your files.
Services
Each entry under services: says whether the project uses that service. A declared service that never gets initialized is reported. See services for the IDs.
Checks
Keys under checks: turn checks on or off and give them settings. They are camelCase (seoMeta, envParity), a separate schema from the snake_case check IDs.
| Key | Settings |
|---|---|
envParity |
envFile and exampleFile, compared for missing variables |
healthEndpoint |
path, when it isn’t one of the usual ones |
stripeWebhook |
url, probed with a GET; a 404 or no answer is reported |
seoMeta |
mainLayout, the template that holds your <head> |
security |
Turns the security header checks on or off |
secrets |
allowlist, for findings you have checked (see ignoring checks) |
indexNow |
key, your IndexNow key. Opt-in |
emailAuth |
Turns on the SPF and DMARC check. Opt-in |
adsTxt, humansTxt, license |
Turn on these file checks. Opt-in |
Ignore
ignore: lists the check and service IDs to leave out of every scan. preflight ignore <id> and preflight unignore <id> edit it for you.