Skip to main content
Lerian SISBAJUD encrypts the personal data it keeps in its own database and bucket. You set these variables at deploy time. They take effect only after a service restart. BYOC configuration essentials documents the universal backbone that every Lerian Go service shares: server, datastores, multi-tenancy, telemetry, plugin authentication, and licensing. This page covers only the variables distinctive to Lerian SISBAJUD. In the tables below, the Default / Required column shows the default value. A bold qualifier (for example Required or Required if enabled) marks the variables you must set. — means no default. Any variable flagged Sensitive carries credential or key material. Inject it from your secret manager at deploy time. Never commit a value.

Service and runtime

Lerian SISBAJUD exposes /health (liveness), /readyz (readiness), and /version on the main port. It exposes /metrics only when ENVIRONMENT_NAME is local or development. When you enable multi-tenancy, it also exposes GET /readyz/tenant/{id}. See Health and readiness for the probe contract.

Security backend

An unsupported KMS_PROVIDER value fails the boot in every environment.
KMS_PROVIDER=vault requires the Vault variables below. KMS_PROVIDER=aws requires the shared AWS_REGION. Per-institution connector credentials are sealed inside institution-configuration metadata under a credentials-class KEK. No environment selector chooses their storage.

Vault (when KMS_PROVIDER=vault)

AWS (when KMS_PROVIDER=aws)

Crypto lifecycle

Envelope encryption uses a per-record data key sealed under the institution’s master key, plus a blind index for exact-match lookup on fiscal identifiers.

Domain workers

Judicial-order processing runs as a set of per-institution background crons. All are off by default except the processing-lock reaper, which runs by default.

Object storage

Event streaming

Lerian SISBAJUD publishes its business events and receives Midaz balance events over Kafka.

STA file exchange

Lerian SISBAJUD exchanges judicial files with BACEN through Lerian STA.

Midaz ledger connector

Lerian SISBAJUD reads balances and blocks through the Midaz ledger. Each institution’s configuration sets the Midaz address, the authorization address, and the credentials. No environment variable sets them.