DocumentationSearch docs
  1. 01Getting started
  2. 02Scanning
  3. 03Checks
  4. 04Services
  5. 05Configuration
  6. 06Ignoring checks
  7. 07CI
  8. 08Agent skill
  9. 09Dashboard
  10. 10Supported stacks

Configuration

Configuration

preflight init writes preflight.yml to your project’s root. Commit it, so every machine and every CI run scans the same way.

An example

projectName: my-app
stack: rails  # rails, next, react, vite, laravel and so on

urls:
  staging: "https://staging.example.com"
  production: "https://example.com"

services:
  stripe:
    declared: true
  sentry:
    declared: true

checks:
  envParity:
    enabled: true
    envFile: ".env"
    exampleFile: ".env.example"

  healthEndpoint:
    enabled: true
    path: "/health"  # optional: the common paths are tried when it isn't set

  stripeWebhook:
    enabled: true
    url: "https://api.example.com/webhooks/stripe"  # optional: probed with a GET

  seoMeta:
    enabled: true
    mainLayout: "app/views/layouts/application.html.erb"

  security:
    enabled: true

  secrets:
    enabled: true
    allowlist:
      - path: web/js/golden-hour.js
        fingerprint: "sha256:<hex>"
        reason: "HTTP-referrer-restricted Google Timezone key"

  indexNow:
    enabled: true
    key: "your32characterhexkeyhere00000"

  emailAuth:
    enabled: true   # opt-in: SPF and DMARC on the production domain

  humansTxt:
    enabled: false  # opt-in: credits the team

  license:
    enabled: false  # opt-in: for open source projects

ignore:
  - sitemap
  - llms_txt
  - google_analytics

The project

projectName names the project in the report and on the dashboard. stack tells the checks where to look: which layout holds the meta tags, where the public files live, which package manager to audit. preflight init detects it; see supported stacks for the values.

URLs

urls.production and urls.staging are where the network checks go: ssl, security_headers, www_redirect, health_endpoint and the checks that read the rendered page. preflight init asks for both, and both are optional. A check with no URL to fetch passes with a note saying so, and the rest of the scan reads only your files.

Services

Each entry under services: says whether the project uses that service. A declared service that never gets initialized is reported. See services for the IDs.

Checks

Keys under checks: turn checks on or off and give them settings. They are camelCase (seoMeta, envParity), a separate schema from the snake_case check IDs.

Key Settings
envParity envFile and exampleFile, compared for missing variables
healthEndpoint path, when it isn’t one of the usual ones
stripeWebhook url, probed with a GET; a 404 or no answer is reported
seoMeta mainLayout, the template that holds your <head>
security Turns the security header checks on or off
secrets allowlist, for findings you have checked (see ignoring checks)
indexNow key, your IndexNow key. Opt-in
emailAuth Turns on the SPF and DMARC check. Opt-in
adsTxt, humansTxt, license Turn on these file checks. Opt-in

Ignore

ignore: lists the check and service IDs to leave out of every scan. preflight ignore <id> and preflight unignore <id> edit it for you.