OpenSRE Environment Variables: Complete Configuration Reference

OpenSRE requires environment variables for LLM authentication (ANTHROPIC_API_KEY, OPENAI_API_KEY, etc.), Grafana Cloud telemetry (GRAFANA_READ_TOKEN, GRAFANA_INSTANCE_URL), and core service connections (DATABASE_URI, REDIS_URI), with optional settings for AWS, databases, and chat platforms, all loaded at startup from .env via app/utils/config.py.

The Tracer-Cloud/opensre repository uses a twelve-factor configuration approach where all operational parameters are injected through environment variables. This design ensures secrets never touch the disk in plain text and allows the same container image to run across development, staging, and production without modification.

How OpenSRE Loads Configuration

Configuration parsing happens at startup through app/utils/config.py. The module exposes two critical functions: load_env() to read the .env file, and get_env() (plus typed wrappers like get_grafana_read_token()) to retrieve values.

By default, load_env() attempts to read a .env file in the working directory unless you set GRAFANA_CONFIG_SKIP_ENV_FILE=1:


# app/utils/config.py – core loader implementation

def load_env(env_path: Path | str | None = None, *, override: bool = False) -> None:
    """Read a .env file (default: ./ .env) and inject missing keys into os.environ."""
    if os.getenv("GRAFANA_CONFIG_SKIP_ENV_FILE") == "1":
        return
    env_path = Path(env_path or Path.cwd() / ".env")
    if not env_path.exists():
        return
    for line in env_path.read_text().splitlines():
        if not line.strip() or line.lstrip().startswith(("#", ";")):
            continue
        if "=" not in line:
            continue
        key, value = line.split("=", 1)
        key, value = key.strip(), value.strip().strip('"').strip("'")
        if key and (override or key not in os.environ):
            os.environ[key] = value

After initialization, any module can import helpers from app.utils.config to access secrets without hard-coding defaults.

Required Environment Variables

OpenSRE cannot start its root-cause analysis (RCA) workflows without the following groups configured.

LLM Provider Authentication

The LLM_PROVIDER variable determines which backend the LangGraph agents use. Valid values include anthropic, openai, openrouter, gemini, and nvidia. You must supply the corresponding API key:

  • ANTHROPIC_API_KEY
  • OPENAI_API_KEY
  • OPENROUTER_API_KEY
  • GEMINI_API_KEY
  • NVIDIA_API_KEY

These are validated in app/llm_credentials.py, which constructs the appropriate SDK client based on the provider name.

Grafana Cloud Telemetry

OpenSRE defaults to Grafana Cloud as its observability sink. The following credentials are mandatory when using the default telemetry backend:

  • GRAFANA_READ_TOKEN – Service account token with metrics:read, logs:read, and traces:read scopes
  • GRAFANA_INSTANCE_URL – Full URL including protocol (e.g., https://myorg.grafana.net)
  • GRAFANA_LOKI_DATASOURCE_UID
  • GRAFANA_TEMPO_DATASOURCE_UID
  • GRAFANA_MIMIR_DATASOURCE_UID

These are consumed by app/services/grafana/__init__.py to instantiate the GrafanaClient class.

Core Service Connections

The LangGraph back-end and Tracer SaaS integration require:

  • DATABASE_URI – SQLAlchemy-compatible connection string
  • REDIS_URI – Redis broker URL for agent state persistence
  • TRACER_API_URL – Endpoint for delivering investigation results
  • TRACER_INGEST_TOKEN – Authentication token for the Tracer ingestion API
  • JWT_TOKEN – Optional bearer token for securing the OpenSRE HTTP API (app/remote/server.py)

Optional Environment Variables

OpenSRE supports pluggable evidence sources and delivery channels that activate only when their respective variables are present.

AWS Credentials

When investigating AWS-specific incidents, set the standard Boto3 variables, parsed by app/utils/env.py:

  • AWS_REGION
  • AWS_ACCESS_KEY_ID
  • AWS_SECRET_ACCESS_KEY
  • AWS_SESSION_TOKEN (for temporary credentials)
  • AWS_ROLE_ARN and AWS_EXTERNAL_ID (for cross-account assume-role)

Database Access

Direct database queries during RCA require:

  • MONGODB_CONNECTION_STRING and MONGODB_DATABASE
  • MARIADB_HOST, MARIADB_USERNAME, MARIADB_PASSWORD, and related connection parameters

Platform Integrations

Pull context from source control and ticketing systems:

  • GITHUB_MCP_URL and GITHUB_MCP_AUTH_TOKEN
  • GITLAB_ACCESS_TOKEN and GITLAB_PROJECT_ID
  • BITBUCKET_APP_PASSWORD
  • JIRA_API_TOKEN

Chat Notifications

Deliver investigation reports to team channels via app/utils/slack_delivery.py:

  • SLACK_WEBHOOK_URL or SLACK_BOT_TOKEN
  • DISCORD_PUBLIC_KEY and DISCORD_APPLICATION_ID

Alternative Monitoring Integrations

Replace or supplement Grafana with:

  • DD_API_KEY and DD_APP_KEY (Datadog)
  • HONEYCOMB_API_KEY
  • CORALOGIX_API_KEY
  • POSTHOG_PERSONAL_API_KEY and POSTHOG_PROJECT_ID

Runtime Behavior Toggles

Control execution mode and data privacy:

  • ENV – Set to development or production
  • OPENSRE_MASK_ENABLED – Enable PII redaction
  • OPENSRE_MASK_KINDS and OPENSRE_MASK_EXTRA_REGEX – Configure masking rules

Configuration Code Examples

Loading Variables with the Config Helper

Access environment values through the centralized utility to ensure .env is parsed:

from app.utils import config

# Typed getter for Grafana token

token = config.get_grafana_read_token()

# Generic getter with default

region = config.get_env("AWS_REGION", "us-east-1")

Initializing the Grafana Client

Construct the telemetry client using values from the environment:

from app.services.grafana import GrafanaClient
from app.utils import config

client = GrafanaClient(
    endpoint=config.get_grafana_instance_url(),
    token=config.get_grafana_read_token(),
    loki_uid=config.get_datasource_uids()[0],
    tempo_uid=config.get_datasource_uids()[1],
    mimir_uid=config.get_datasource_uids()[2],
)

Building the LLM Client

Select the provider dynamically based on LLM_PROVIDER:

from app.llm_credentials import get_llm_client
from app.utils import config

provider = config.get_env("LLM_PROVIDER", "anthropic")
client = get_llm_client(provider)  # Automatically selects the correct API key

Sending Slack Notifications

Check for optional variables before attempting delivery:

import os
import httpx

def post_to_slack(text: str) -> None:
    webhook = os.getenv("SLACK_WEBHOOK_URL")
    if not webhook:
        raise RuntimeError("SLACK_WEBHOOK_URL not set")
    httpx.post(webhook, json={"text": text})

Summary

  • OpenSRE environment variables are defined in .env.example and loaded at runtime via app/utils/config.py.
  • Required variables cover LLM authentication (ANTHROPIC_API_KEY, OPENAI_API_KEY, etc.), Grafana Cloud access (GRAFANA_READ_TOKEN, GRAFANA_INSTANCE_URL), and core infrastructure (DATABASE_URI, REDIS_URI).
  • Optional groups include AWS credentials (app/utils/env.py), database connection strings, GitLab/GitHub tokens, and Slack webhooks.
  • Set GRAFANA_CONFIG_SKIP_ENV_FILE=1 to disable automatic .env loading in containerized environments.
  • The load_env() function injects file-based variables into os.environ, while typed getters like get_grafana_read_token() provide safe access patterns.

Frequently Asked Questions

Where is the complete list of OpenSRE environment variables?

The definitive reference is .env.example in the repository root. This file documents every variable the platform recognizes, including required keys for LLM providers and Grafana Cloud, plus optional toggles for AWS, databases, and chat integrations.

How do I prevent OpenSRE from loading the .env file?

Set the environment variable GRAFANA_CONFIG_SKIP_ENV_FILE=1 before starting the process. When this flag is present, app/utils/config.py skips the file-loading logic and expects all configuration to be present in the shell environment.

Are AWS credentials required for OpenSRE?

No. AWS variables (AWS_REGION, AWS_ACCESS_KEY_ID, etc.) are only required if your RCA workflows query CloudWatch, S3, or EC2 metadata. The platform functions without them if you rely solely on Grafana Cloud or other monitoring integrations.

How does OpenSRE handle sensitive data like API keys?

OpenSRE treats all API keys as environment variables and never writes them to disk. The app/utils/config.py loader strips quotes and injects values directly into the running process memory. For additional security, use the OPENSRE_MASK_ENABLED toggle to redact sensitive patterns from logs and traces before they leave the system.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →