Configuration

OpenSRE uses a hierarchical configuration system managed by the config-service. Configuration flows from org-level defaults down to team-specific overrides — dicts merge, lists replace.

Environment Variables

The minimal required configuration is one env var:

VariableRequiredDescription
ANTHROPIC_API_KEYYesDirect Anthropic API key — the agent runtime (Claude Agent SDK) calls Anthropic by default
ANTHROPIC_MODELNoRoot agent model (default: a current Claude Sonnet)
MEMORY_LLM_MODELNoFaster/cheaper model used for episodic memory extraction (default: a Claude Haiku model)
OPENROUTER_API_KEYNoOnly needed if you opt into the LiteLLM proxy to route through OpenRouter or another provider — see below
SLACK_BOT_TOKENNoSlack bot token (xoxb-...)
SLACK_APP_TOKENNoSlack app token (xapp-...) for Socket Mode
NEO4J_URINoNeo4j connection URI (in-network default when using make dev)
NEO4J_USERNAMENoNeo4j username (default: neo4j)
NEO4J_PASSWORDNoNeo4j password
ADMIN_TOKENNoAdmin token for web UI
WEB_UI_SSO_ORG_IDNoOrg id for the web-console Entra SSO button (see Entra SSO)
WEB_UI_PUBLIC_BASE_URLNoPublic origin used as the Entra redirect_uri
SSO_CLIENT_SECRETNoEntra/OIDC client secret on config-service (env only)

Organizations, Teams, and Tokens

config-service organizes everything under a two-level tree: one or more organizations, each with one or more teams. For local development, CONFIG_MODE=local auto-seeds a single org (local) and team (default) from config_service/config/local.yaml — you don't create these by hand for make dev.

Two token types gate access, both issued by config-service's admin API:

TokenScopeWhere it comes from locally
Admin tokenOrg/team management, issuing and revoking tokens, org-wide configADMIN_TOKEN env var (default local-admin-token)
Team tokenRuntime auth for investigations and team-scoped config (team:read, team:write)Minted via the admin API against a specific org/team, e.g. make e2e-token for local/default

The web console's sign-in screen (http://localhost:3002) takes either token:

  • Paste a team token to use the console as an investigator for that team.
  • Paste the admin token to unlock Admin — org tree (add orgs/teams, issue or revoke tokens per node) and token management — so you can manage everything from the UI instead of re-running make e2e-token each time.

For a fresh org/team beyond the local default (e.g. a real deployment), use the same admin API make e2e-token calls under the hood — POST /api/v1/admin/orgs/{org_id}/teams/{team_id}/tokens with the admin token — or do it from Admin → org tree once you're signed in with the admin token.

Web console SSO

Microsoft Entra ID login uses Admin → SSO, not Helm services.webUi.oidc.enabled. Create a confidential Web app in Entra, paste tenant / client id into the admin form, set SSO_CLIENT_SECRET on config-service, and keep token login as break-glass. Full steps: Entra SSO.

Integration Configuration

Integrations are configured under the integrations key in your team config (config_service/config/local.yaml in CONFIG_MODE=local, or via the admin API/UI otherwise). Only uncomment or add the sections you need — credentials are pulled from environment variables via ${VAR} substitution, not hardcoded.

Prometheus

integrations:
  prometheus:
    url: ${PROMETHEUS_URL}
    # Optional basic auth
    # username: ${PROMETHEUS_USERNAME}
    # password: ${PROMETHEUS_PASSWORD}

Grafana

integrations:
  grafana:
    url: ${GRAFANA_URL}
    api_key: ${GRAFANA_API_KEY}

Datadog

integrations:
  datadog:
    api_key: ${DATADOG_API_KEY}
    app_key: ${DATADOG_APP_KEY}
    site: datadoghq.com  # or datadoghq.eu, us3.datadoghq.com, etc.

Elasticsearch

integrations:
  elasticsearch:
    domain: ${ELASTICSEARCH_DOMAIN}
    username: ${ELASTICSEARCH_USERNAME}
    api_key: ${ELASTICSEARCH_API_KEY}

PagerDuty

integrations:
  pagerduty:
    api_key: ${PAGERDUTY_API_KEY}
    # Optional: restrict to specific service IDs
    # service_ids:
    #   - PXXXXXX

There's no enabled: true flag — an integration is active once it's present under integrations. See Integrations for the full list and Investigation Skills for which skill each one powers.

LLM Configuration

By default the agent calls Anthropic directly:

ai_model:
  provider: anthropic
  model_id: claude-sonnet-4-6
integrations:
  anthropic:
    api_key: ${ANTHROPIC_API_KEY}

To route through OpenRouter or another provider instead, either point ai_model.provider at openrouter with the matching integrations.openrouter.api_key, or start the optional LiteLLM proxy and set ANTHROPIC_BASE_URL=http://litellm:4000 — see Quick Start and litellm_config.yaml.

Configuration Hierarchy

Configuration is stored in config-service and organized hierarchically:

org (base defaults)
 └── team (team-specific overrides)
      └── agent (per-agent overrides, e.g. model/skills for one agent)

Dict values are deep merged at each level. List values are replaced — if a team specifies a list, it replaces the org-level list entirely.

Skills Configuration

Enable or disable skills for the whole team with a wildcard plus a disable-list:

skills:
  enabled:
    - '*'
  disabled:
    - observability-datadog
    - database-mysql

Or restrict to an explicit allow-list instead of '*'. For finer control, override skills on a single agent:

{
  "agents": {
    "my-agent-id": {
      "skills": {
        "infrastructure-kubernetes": true,
        "observability-datadog": false
      }
    }
  }
}

Disabled skill directories are removed from that thread's skill workspace at session start — see Investigation Skills for the full catalog.