# OpenSRE Environment Variables: Complete Configuration Reference

> Master OpenSRE configuration with our complete environment variables reference. Learn essential settings for LLM auth, Grafana telemetry, database connections and more. Optimize your OpenSRE setup today.

- Repository: [Tracer/opensre](https://github.com/Tracer-Cloud/opensre)
- Tags: api-reference
- Published: 2026-04-18

---

**OpenSRE requires environment variables for LLM authentication (ANTHROPIC_API_KEY, OPENAI_API_KEY, etc.), Grafana Cloud telemetry (GRAFANA_READ_TOKEN, GRAFANA_INSTANCE_URL), and core service connections (DATABASE_URI, REDIS_URI), with optional settings for AWS, databases, and chat platforms, all loaded at startup from `.env` via [`app/utils/config.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/utils/config.py).**

The **Tracer-Cloud/opensre** repository uses a twelve-factor configuration approach where all operational parameters are injected through environment variables. This design ensures secrets never touch the disk in plain text and allows the same container image to run across development, staging, and production without modification.

## How OpenSRE Loads Configuration

Configuration parsing happens at startup through **[`app/utils/config.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/utils/config.py)**. The module exposes two critical functions: `load_env()` to read the `.env` file, and `get_env()` (plus typed wrappers like `get_grafana_read_token()`) to retrieve values.

By default, `load_env()` attempts to read a `.env` file in the working directory unless you set **`GRAFANA_CONFIG_SKIP_ENV_FILE=1`**:

```python

# app/utils/config.py – core loader implementation

def load_env(env_path: Path | str | None = None, *, override: bool = False) -> None:
    """Read a .env file (default: ./ .env) and inject missing keys into os.environ."""
    if os.getenv("GRAFANA_CONFIG_SKIP_ENV_FILE") == "1":
        return
    env_path = Path(env_path or Path.cwd() / ".env")
    if not env_path.exists():
        return
    for line in env_path.read_text().splitlines():
        if not line.strip() or line.lstrip().startswith(("#", ";")):
            continue
        if "=" not in line:
            continue
        key, value = line.split("=", 1)
        key, value = key.strip(), value.strip().strip('"').strip("'")
        if key and (override or key not in os.environ):
            os.environ[key] = value

```

After initialization, any module can import helpers from `app.utils.config` to access secrets without hard-coding defaults.

## Required Environment Variables

OpenSRE cannot start its root-cause analysis (RCA) workflows without the following groups configured.

### LLM Provider Authentication

The **`LLM_PROVIDER`** variable determines which backend the LangGraph agents use. Valid values include `anthropic`, `openai`, `openrouter`, `gemini`, and `nvidia`. You must supply the corresponding API key:

- **ANTHROPIC_API_KEY**
- **OPENAI_API_KEY**
- **OPENROUTER_API_KEY**
- **GEMINI_API_KEY**
- **NVIDIA_API_KEY**

These are validated in [`app/llm_credentials.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/llm_credentials.py), which constructs the appropriate SDK client based on the provider name.

### Grafana Cloud Telemetry

OpenSRE defaults to Grafana Cloud as its observability sink. The following credentials are mandatory when using the default telemetry backend:

- **GRAFANA_READ_TOKEN** – Service account token with `metrics:read`, `logs:read`, and `traces:read` scopes
- **GRAFANA_INSTANCE_URL** – Full URL including protocol (e.g., `https://myorg.grafana.net`)
- **GRAFANA_LOKI_DATASOURCE_UID**
- **GRAFANA_TEMPO_DATASOURCE_UID**
- **GRAFANA_MIMIR_DATASOURCE_UID**

These are consumed by [`app/services/grafana/__init__.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/services/grafana/__init__.py) to instantiate the `GrafanaClient` class.

### Core Service Connections

The LangGraph back-end and Tracer SaaS integration require:

- **DATABASE_URI** – SQLAlchemy-compatible connection string
- **REDIS_URI** – Redis broker URL for agent state persistence
- **TRACER_API_URL** – Endpoint for delivering investigation results
- **TRACER_INGEST_TOKEN** – Authentication token for the Tracer ingestion API
- **JWT_TOKEN** – Optional bearer token for securing the OpenSRE HTTP API ([`app/remote/server.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/remote/server.py))

## Optional Environment Variables

OpenSRE supports pluggable evidence sources and delivery channels that activate only when their respective variables are present.

### AWS Credentials

When investigating AWS-specific incidents, set the standard Boto3 variables, parsed by **[`app/utils/env.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/utils/env.py)**:

- **AWS_REGION**
- **AWS_ACCESS_KEY_ID**
- **AWS_SECRET_ACCESS_KEY**
- **AWS_SESSION_TOKEN** (for temporary credentials)
- **AWS_ROLE_ARN** and **AWS_EXTERNAL_ID** (for cross-account assume-role)

### Database Access

Direct database queries during RCA require:

- **MONGODB_CONNECTION_STRING** and **MONGODB_DATABASE**
- **MARIADB_HOST**, **MARIADB_USERNAME**, **MARIADB_PASSWORD**, and related connection parameters

### Platform Integrations

Pull context from source control and ticketing systems:

- **GITHUB_MCP_URL** and **GITHUB_MCP_AUTH_TOKEN**
- **GITLAB_ACCESS_TOKEN** and **GITLAB_PROJECT_ID**
- **BITBUCKET_APP_PASSWORD**
- **JIRA_API_TOKEN**

### Chat Notifications

Deliver investigation reports to team channels via **app/utils/slack_delivery.py**:

- **SLACK_WEBHOOK_URL** or **SLACK_BOT_TOKEN**
- **DISCORD_PUBLIC_KEY** and **DISCORD_APPLICATION_ID**

### Alternative Monitoring Integrations

Replace or supplement Grafana with:

- **DD_API_KEY** and **DD_APP_KEY** (Datadog)
- **HONEYCOMB_API_KEY**
- **CORALOGIX_API_KEY**
- **POSTHOG_PERSONAL_API_KEY** and **POSTHOG_PROJECT_ID**

### Runtime Behavior Toggles

Control execution mode and data privacy:

- **ENV** – Set to `development` or `production`
- **OPENSRE_MASK_ENABLED** – Enable PII redaction
- **OPENSRE_MASK_KINDS** and **OPENSRE_MASK_EXTRA_REGEX** – Configure masking rules

## Configuration Code Examples

### Loading Variables with the Config Helper

Access environment values through the centralized utility to ensure `.env` is parsed:

```python
from app.utils import config

# Typed getter for Grafana token

token = config.get_grafana_read_token()

# Generic getter with default

region = config.get_env("AWS_REGION", "us-east-1")

```

### Initializing the Grafana Client

Construct the telemetry client using values from the environment:

```python
from app.services.grafana import GrafanaClient
from app.utils import config

client = GrafanaClient(
    endpoint=config.get_grafana_instance_url(),
    token=config.get_grafana_read_token(),
    loki_uid=config.get_datasource_uids()[0],
    tempo_uid=config.get_datasource_uids()[1],
    mimir_uid=config.get_datasource_uids()[2],
)

```

### Building the LLM Client

Select the provider dynamically based on `LLM_PROVIDER`:

```python
from app.llm_credentials import get_llm_client
from app.utils import config

provider = config.get_env("LLM_PROVIDER", "anthropic")
client = get_llm_client(provider)  # Automatically selects the correct API key

```

### Sending Slack Notifications

Check for optional variables before attempting delivery:

```python
import os
import httpx

def post_to_slack(text: str) -> None:
    webhook = os.getenv("SLACK_WEBHOOK_URL")
    if not webhook:
        raise RuntimeError("SLACK_WEBHOOK_URL not set")
    httpx.post(webhook, json={"text": text})

```

## Summary

- **OpenSRE environment variables** are defined in **`.env.example`** and loaded at runtime via **[`app/utils/config.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/utils/config.py)**.
- **Required** variables cover LLM authentication (ANTHROPIC_API_KEY, OPENAI_API_KEY, etc.), Grafana Cloud access (GRAFANA_READ_TOKEN, GRAFANA_INSTANCE_URL), and core infrastructure (DATABASE_URI, REDIS_URI).
- **Optional** groups include AWS credentials (**[`app/utils/env.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/utils/env.py)**), database connection strings, GitLab/GitHub tokens, and Slack webhooks.
- Set **`GRAFANA_CONFIG_SKIP_ENV_FILE=1`** to disable automatic `.env` loading in containerized environments.
- The **`load_env()`** function injects file-based variables into `os.environ`, while typed getters like **`get_grafana_read_token()`** provide safe access patterns.

## Frequently Asked Questions

### Where is the complete list of OpenSRE environment variables?

The definitive reference is **`.env.example`** in the repository root. This file documents every variable the platform recognizes, including required keys for LLM providers and Grafana Cloud, plus optional toggles for AWS, databases, and chat integrations.

### How do I prevent OpenSRE from loading the .env file?

Set the environment variable **`GRAFANA_CONFIG_SKIP_ENV_FILE=1`** before starting the process. When this flag is present, [`app/utils/config.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/utils/config.py) skips the file-loading logic and expects all configuration to be present in the shell environment.

### Are AWS credentials required for OpenSRE?

No. AWS variables (**AWS_REGION**, **AWS_ACCESS_KEY_ID**, etc.) are only required if your RCA workflows query CloudWatch, S3, or EC2 metadata. The platform functions without them if you rely solely on Grafana Cloud or other monitoring integrations.

### How does OpenSRE handle sensitive data like API keys?

OpenSRE treats all API keys as environment variables and never writes them to disk. The **[`app/utils/config.py`](https://github.com/Tracer-Cloud/opensre/blob/main/app/utils/config.py)** loader strips quotes and injects values directly into the running process memory. For additional security, use the **`OPENSRE_MASK_ENABLED`** toggle to redact sensitive patterns from logs and traces before they leave the system.