OpenSRE Environment Variables: Complete Configuration Reference
OpenSRE requires environment variables for LLM authentication (ANTHROPIC_API_KEY, OPENAI_API_KEY, etc.), Grafana Cloud telemetry (GRAFANA_READ_TOKEN, GRAFANA_INSTANCE_URL), and core service connections (DATABASE_URI, REDIS_URI), with optional settings for AWS, databases, and chat platforms, all loaded at startup from .env via app/utils/config.py.
The Tracer-Cloud/opensre repository uses a twelve-factor configuration approach where all operational parameters are injected through environment variables. This design ensures secrets never touch the disk in plain text and allows the same container image to run across development, staging, and production without modification.
How OpenSRE Loads Configuration
Configuration parsing happens at startup through app/utils/config.py. The module exposes two critical functions: load_env() to read the .env file, and get_env() (plus typed wrappers like get_grafana_read_token()) to retrieve values.
By default, load_env() attempts to read a .env file in the working directory unless you set GRAFANA_CONFIG_SKIP_ENV_FILE=1:
# app/utils/config.py – core loader implementation
def load_env(env_path: Path | str | None = None, *, override: bool = False) -> None:
"""Read a .env file (default: ./ .env) and inject missing keys into os.environ."""
if os.getenv("GRAFANA_CONFIG_SKIP_ENV_FILE") == "1":
return
env_path = Path(env_path or Path.cwd() / ".env")
if not env_path.exists():
return
for line in env_path.read_text().splitlines():
if not line.strip() or line.lstrip().startswith(("#", ";")):
continue
if "=" not in line:
continue
key, value = line.split("=", 1)
key, value = key.strip(), value.strip().strip('"').strip("'")
if key and (override or key not in os.environ):
os.environ[key] = value
After initialization, any module can import helpers from app.utils.config to access secrets without hard-coding defaults.
Required Environment Variables
OpenSRE cannot start its root-cause analysis (RCA) workflows without the following groups configured.
LLM Provider Authentication
The LLM_PROVIDER variable determines which backend the LangGraph agents use. Valid values include anthropic, openai, openrouter, gemini, and nvidia. You must supply the corresponding API key:
- ANTHROPIC_API_KEY
- OPENAI_API_KEY
- OPENROUTER_API_KEY
- GEMINI_API_KEY
- NVIDIA_API_KEY
These are validated in app/llm_credentials.py, which constructs the appropriate SDK client based on the provider name.
Grafana Cloud Telemetry
OpenSRE defaults to Grafana Cloud as its observability sink. The following credentials are mandatory when using the default telemetry backend:
- GRAFANA_READ_TOKEN – Service account token with
metrics:read,logs:read, andtraces:readscopes - GRAFANA_INSTANCE_URL – Full URL including protocol (e.g.,
https://myorg.grafana.net) - GRAFANA_LOKI_DATASOURCE_UID
- GRAFANA_TEMPO_DATASOURCE_UID
- GRAFANA_MIMIR_DATASOURCE_UID
These are consumed by app/services/grafana/__init__.py to instantiate the GrafanaClient class.
Core Service Connections
The LangGraph back-end and Tracer SaaS integration require:
- DATABASE_URI – SQLAlchemy-compatible connection string
- REDIS_URI – Redis broker URL for agent state persistence
- TRACER_API_URL – Endpoint for delivering investigation results
- TRACER_INGEST_TOKEN – Authentication token for the Tracer ingestion API
- JWT_TOKEN – Optional bearer token for securing the OpenSRE HTTP API (
app/remote/server.py)
Optional Environment Variables
OpenSRE supports pluggable evidence sources and delivery channels that activate only when their respective variables are present.
AWS Credentials
When investigating AWS-specific incidents, set the standard Boto3 variables, parsed by app/utils/env.py:
- AWS_REGION
- AWS_ACCESS_KEY_ID
- AWS_SECRET_ACCESS_KEY
- AWS_SESSION_TOKEN (for temporary credentials)
- AWS_ROLE_ARN and AWS_EXTERNAL_ID (for cross-account assume-role)
Database Access
Direct database queries during RCA require:
- MONGODB_CONNECTION_STRING and MONGODB_DATABASE
- MARIADB_HOST, MARIADB_USERNAME, MARIADB_PASSWORD, and related connection parameters
Platform Integrations
Pull context from source control and ticketing systems:
- GITHUB_MCP_URL and GITHUB_MCP_AUTH_TOKEN
- GITLAB_ACCESS_TOKEN and GITLAB_PROJECT_ID
- BITBUCKET_APP_PASSWORD
- JIRA_API_TOKEN
Chat Notifications
Deliver investigation reports to team channels via app/utils/slack_delivery.py:
- SLACK_WEBHOOK_URL or SLACK_BOT_TOKEN
- DISCORD_PUBLIC_KEY and DISCORD_APPLICATION_ID
Alternative Monitoring Integrations
Replace or supplement Grafana with:
- DD_API_KEY and DD_APP_KEY (Datadog)
- HONEYCOMB_API_KEY
- CORALOGIX_API_KEY
- POSTHOG_PERSONAL_API_KEY and POSTHOG_PROJECT_ID
Runtime Behavior Toggles
Control execution mode and data privacy:
- ENV – Set to
developmentorproduction - OPENSRE_MASK_ENABLED – Enable PII redaction
- OPENSRE_MASK_KINDS and OPENSRE_MASK_EXTRA_REGEX – Configure masking rules
Configuration Code Examples
Loading Variables with the Config Helper
Access environment values through the centralized utility to ensure .env is parsed:
from app.utils import config
# Typed getter for Grafana token
token = config.get_grafana_read_token()
# Generic getter with default
region = config.get_env("AWS_REGION", "us-east-1")
Initializing the Grafana Client
Construct the telemetry client using values from the environment:
from app.services.grafana import GrafanaClient
from app.utils import config
client = GrafanaClient(
endpoint=config.get_grafana_instance_url(),
token=config.get_grafana_read_token(),
loki_uid=config.get_datasource_uids()[0],
tempo_uid=config.get_datasource_uids()[1],
mimir_uid=config.get_datasource_uids()[2],
)
Building the LLM Client
Select the provider dynamically based on LLM_PROVIDER:
from app.llm_credentials import get_llm_client
from app.utils import config
provider = config.get_env("LLM_PROVIDER", "anthropic")
client = get_llm_client(provider) # Automatically selects the correct API key
Sending Slack Notifications
Check for optional variables before attempting delivery:
import os
import httpx
def post_to_slack(text: str) -> None:
webhook = os.getenv("SLACK_WEBHOOK_URL")
if not webhook:
raise RuntimeError("SLACK_WEBHOOK_URL not set")
httpx.post(webhook, json={"text": text})
Summary
- OpenSRE environment variables are defined in
.env.exampleand loaded at runtime viaapp/utils/config.py. - Required variables cover LLM authentication (ANTHROPIC_API_KEY, OPENAI_API_KEY, etc.), Grafana Cloud access (GRAFANA_READ_TOKEN, GRAFANA_INSTANCE_URL), and core infrastructure (DATABASE_URI, REDIS_URI).
- Optional groups include AWS credentials (
app/utils/env.py), database connection strings, GitLab/GitHub tokens, and Slack webhooks. - Set
GRAFANA_CONFIG_SKIP_ENV_FILE=1to disable automatic.envloading in containerized environments. - The
load_env()function injects file-based variables intoos.environ, while typed getters likeget_grafana_read_token()provide safe access patterns.
Frequently Asked Questions
Where is the complete list of OpenSRE environment variables?
The definitive reference is .env.example in the repository root. This file documents every variable the platform recognizes, including required keys for LLM providers and Grafana Cloud, plus optional toggles for AWS, databases, and chat integrations.
How do I prevent OpenSRE from loading the .env file?
Set the environment variable GRAFANA_CONFIG_SKIP_ENV_FILE=1 before starting the process. When this flag is present, app/utils/config.py skips the file-loading logic and expects all configuration to be present in the shell environment.
Are AWS credentials required for OpenSRE?
No. AWS variables (AWS_REGION, AWS_ACCESS_KEY_ID, etc.) are only required if your RCA workflows query CloudWatch, S3, or EC2 metadata. The platform functions without them if you rely solely on Grafana Cloud or other monitoring integrations.
How does OpenSRE handle sensitive data like API keys?
OpenSRE treats all API keys as environment variables and never writes them to disk. The app/utils/config.py loader strips quotes and injects values directly into the running process memory. For additional security, use the OPENSRE_MASK_ENABLED toggle to redact sensitive patterns from logs and traces before they leave the system.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →