— means no default. Variables carrying certificates, private keys, OAuth secrets, or HMAC keys are sensitive and must come from a secret manager.
Service and tenant mode
Dataprev client and authentication
Managed deployments must use tenant credential custody. They fail closed instead of falling back to an unauthenticated or non-mTLS client.
Contract and portability windows
Reconciliation and employment feeds
Exclusion and redirection
DATAPREV_EXCLUSION_ADAPTER and DATAPREV_EXCLUSION_FAKE_BASE_URL are retired. Remove them from deployment manifests. Non-inert legacy values fail validation.
Outcome recovery
A rail command can end with its outcome unestablished: the process died mid-call, or Dataprev never answered. Two recovery loops converge that state against the rail’s own registry. Both loops are off by default. Enable them in any deployment that submits averbações or rail commands. Otherwise an unestablished outcome never resolves.Auctions and client bids
M011 portability discovery requires
LEILAO_PORTABILITY_ENABLED=true, LEILAO_TENANT_ID, DATAPREV_ENABLED=true, STREAMING_ENABLED=true, a primary database, and the canonical outbox. It does not require LEILAO_ENABLED=true. The portability listing window is 72 hours by default (DATAPREV_PORTABILIDADE_SOLICITACAO_WINDOW_HOURS). The service refuses to boot unless that window is wider than LEILAO_PORTABILITY_INTERVAL_SEC plus the 300-second LEILAO_DISCOVERY_CLOCK_SKEW_SEC margin.
Credential custody and artifacts
Consignado has no non-event-driven startup mode: outbox, streaming, and brokers are mandatory even though the platform shares those settings. Keep the CloudEvent source pinned to
consignado-gw.
