Enabling the SDK
Varianz is opt-in: the SDK is disabled by default. A service that carries the SDK but is given no configuration stays dormant — VPoints pass through, nothing registers, no native library is touched, and every SDK call succeeds as a no-op. Resolution order (first match wins):VARIANZ_ENABLEDenvironment variable — wins unconditionally when set.enabledkey in a config file —VARIANZ_SDK_CONFIG=<path>if set, else./varianz.toml, else~/.varianz/sdk.toml. First existing file wins; files are not merged.- Built-in default: disabled.
true, 1, on, yes, enabled; false = false, 0, off, no, disabled. An unparseable value or unreadable config resolves to disabled with a single warning — the same fail-open posture as the rest of Varianz: when anything is wrong, VPoints simply run your original code.
The config file schema is a single top-level key; unknown keys are ignored:
The toggle behaves identically in every SDK. For Java/Kotlin, interception additionally requires the
varianz-agent to be attached (Gradle weave, Maven -Dvarianz.skipAgent=true) — see Java SDK.Coordinator endpoint
VARIANZ_COORDINATOR_ENDPOINT is the canonical name. Prefer it everywhere — application side and test side, every language.
Application side
The endpoint is normally passed in code —Varianz("http://..."), initCoordinator({ endpoint }), varianz.WithEndpoint(...), CoordinatorBinding.init(...). It is a default, not an instruction: the environment outranks it, because whoever deploys a build must be able to repoint it without rebuilding it.
Precedence, highest first:
VARIANZ_COORDINATOR_ENDPOINT— outranks everything, including an endpoint passed at the call site.endpointin a config file named byVARIANZ_SDK_CONFIG— naming a file is a deployment act, so it also outranks the call site.- The endpoint passed at the call site.
endpointin a config file found by search (./varianz.toml,~/.varianz/sdk.toml).
initCoordinator() is the exception: it raises no coordinator endpoint: set VARIANZ_COORDINATOR_ENDPOINT, point VARIANZ_SDK_CONFIG at a config file, add 'endpoint' to a config file, or supply one at the call site. (A Node service that never calls initCoordinator at all is local-only, like the others.)
Test side
Test fixtures resolve the endpoint so a suite can move between a laptop and CI without edits. Every one of them puts an explicitly supplied endpoint first — the reverse of the application side, because naming a coordinator in a test is a deliberate act by whoever ran it.Deprecated spellings
A deprecated spelling is consulted only when
VARIANZ_COORDINATOR_ENDPOINT is unset. Go, the JVM and C++ accept no alias at all; Node and Python keep shims because both ship through package registries, where a pinned install and a CI config keep exporting an old name long after an upgrade.
TLS
SDK clients always verify TLS against the platform trust store by default. There is no code-side override for plaintext — only the environment:
Every SDK client (Python, TypeScript, Go, JVM) reads these identically. Rotating a CA file on disk doesn’t affect established connections — reconnect or restart the client.
Environment tags
Stages can be scoped to deployment environments. Clients advertise theirs via SDK options (for exampleinitCoordinator({ region, cluster, tags })) or environment variables:
Git provenance
VPoints record their code location (file, line, git commit) for tooling. Detection reads the local.git; production artifacts usually run without one, so set these in your build/deploy pipeline:
Values merge field-by-field on top of whatever was auto-detected.
Build-time switches
JVM equivalent for the processor:
-Avarianz.proc.enabled=false.
