OpenSRE uses a hierarchical configuration system managed by the config-service. Configuration flows from org-level defaults down to team-specific overrides — dicts merge, lists replace.
The minimal required configuration is one env var:
| Variable | Required | Description |
|---|---|---|
ANTHROPIC_API_KEY | Yes | Direct Anthropic API key — the agent runtime (Claude Agent SDK) calls Anthropic by default |
ANTHROPIC_MODEL | No | Root agent model (default: a current Claude Sonnet) |
MEMORY_LLM_MODEL | No | Faster/cheaper model used for episodic memory extraction (default: a Claude Haiku model) |
OPENROUTER_API_KEY | No | Only needed if you opt into the LiteLLM proxy to route through OpenRouter or another provider — see below |
SLACK_BOT_TOKEN | No | Slack bot token (xoxb-...) |
SLACK_APP_TOKEN | No | Slack app token (xapp-...) for Socket Mode |
NEO4J_URI | No | Neo4j connection URI (in-network default when using make dev) |
NEO4J_USERNAME | No | Neo4j username (default: neo4j) |
NEO4J_PASSWORD | No | Neo4j password |
ADMIN_TOKEN | No | Admin token for web UI |
WEB_UI_SSO_ORG_ID | No | Org id for the web-console Entra SSO button (see Entra SSO) |
WEB_UI_PUBLIC_BASE_URL | No | Public origin used as the Entra redirect_uri |
SSO_CLIENT_SECRET | No | Entra/OIDC client secret on config-service (env only) |
config-service organizes everything under a two-level tree: one or more organizations, each with one or more teams. For local development, CONFIG_MODE=local auto-seeds a single org (local) and team (default) from config_service/config/local.yaml — you don't create these by hand for make dev.
Two token types gate access, both issued by config-service's admin API:
| Token | Scope | Where it comes from locally |
|---|---|---|
| Admin token | Org/team management, issuing and revoking tokens, org-wide config | ADMIN_TOKEN env var (default local-admin-token) |
| Team token | Runtime auth for investigations and team-scoped config (team:read, team:write) | Minted via the admin API against a specific org/team, e.g. make e2e-token for local/default |
The web console's sign-in screen (http://localhost:3002) takes either token:
make e2e-token each time.For a fresh org/team beyond the local default (e.g. a real deployment), use the same admin API make e2e-token calls under the hood — POST /api/v1/admin/orgs/{org_id}/teams/{team_id}/tokens with the admin token — or do it from Admin → org tree once you're signed in with the admin token.
Microsoft Entra ID login uses Admin → SSO, not Helm services.webUi.oidc.enabled. Create a confidential Web app in Entra, paste tenant / client id into the admin form, set SSO_CLIENT_SECRET on config-service, and keep token login as break-glass. Full steps: Entra SSO.
Integrations are configured under the integrations key in your team config (config_service/config/local.yaml in CONFIG_MODE=local, or via the admin API/UI otherwise). Only uncomment or add the sections you need — credentials are pulled from environment variables via ${VAR} substitution, not hardcoded.
integrations:
prometheus:
url: ${PROMETHEUS_URL}
# Optional basic auth
# username: ${PROMETHEUS_USERNAME}
# password: ${PROMETHEUS_PASSWORD}
integrations:
grafana:
url: ${GRAFANA_URL}
api_key: ${GRAFANA_API_KEY}
integrations:
datadog:
api_key: ${DATADOG_API_KEY}
app_key: ${DATADOG_APP_KEY}
site: datadoghq.com # or datadoghq.eu, us3.datadoghq.com, etc.
integrations:
elasticsearch:
domain: ${ELASTICSEARCH_DOMAIN}
username: ${ELASTICSEARCH_USERNAME}
api_key: ${ELASTICSEARCH_API_KEY}
integrations:
pagerduty:
api_key: ${PAGERDUTY_API_KEY}
# Optional: restrict to specific service IDs
# service_ids:
# - PXXXXXX
There's no enabled: true flag — an integration is active once it's present under integrations. See Integrations for the full list and Investigation Skills for which skill each one powers.
By default the agent calls Anthropic directly:
ai_model:
provider: anthropic
model_id: claude-sonnet-4-6
integrations:
anthropic:
api_key: ${ANTHROPIC_API_KEY}
To route through OpenRouter or another provider instead, either point ai_model.provider at openrouter with the matching integrations.openrouter.api_key, or start the optional LiteLLM proxy and set ANTHROPIC_BASE_URL=http://litellm:4000 — see Quick Start and litellm_config.yaml.
Configuration is stored in config-service and organized hierarchically:
org (base defaults)
└── team (team-specific overrides)
└── agent (per-agent overrides, e.g. model/skills for one agent)
Dict values are deep merged at each level. List values are replaced — if a team specifies a list, it replaces the org-level list entirely.
Enable or disable skills for the whole team with a wildcard plus a disable-list:
skills:
enabled:
- '*'
disabled:
- observability-datadog
- database-mysql
Or restrict to an explicit allow-list instead of '*'. For finer control, override skills on a single agent:
{
"agents": {
"my-agent-id": {
"skills": {
"infrastructure-kubernetes": true,
"observability-datadog": false
}
}
}
}
Disabled skill directories are removed from that thread's skill workspace at session start — see Investigation Skills for the full catalog.