Configure OpenSourceOM
om reads process environment variables. It does not load .env.
Docker Compose interpolates .env for the API service. Copy
.env.example in the core repository and export only the variables you need in the
shell that runs the CLI.
A database URL is built from the POSTGRES_* variables unless DATABASE_URL
is set. The default URL is
postgres://opensourceom:opensourceom@localhost:5432/opensourceom?sslmode=disable.
Process
| Variable | Default | Used by |
|---|---|---|
OM_ENV | development | API container label. The CLI stores it and does not branch on it. |
OM_LOG_LEVEL | info | Reserved. The API logger is the standard library logger. |
OM_PUBLIC_URL | http://localhost:8080 | Public URL hint. Requests use the listen address. |
OM_API_PORT | 8080 | om serve |
OM_API_SECRET | change-me-in-production | Shared secret for every /v1 route except GET /v1/health. See Security. |
Database
| Variable | Default |
|---|---|
DATABASE_URL | Built from the fields below |
POSTGRES_USER | opensourceom |
POSTGRES_PASSWORD | opensourceom |
POSTGRES_DB | opensourceom |
POSTGRES_HOST | localhost |
POSTGRES_PORT | 5432 |
Inside Compose, the API service sets POSTGRES_HOST=postgres. On your laptop, keep
the CLI default of localhost.
Collectors
| Variable | Default | Required for |
|---|---|---|
AWS_REGION | us-east-1 | om scan aws (one region per run) |
AZURE_SUBSCRIPTION_ID | empty | om scan azure |
AZURE_LOCATION | eastus | Fallback region on Azure node IDs |
GCP_PROJECT_ID | empty | om scan gcp |
GCP_REGION | us-central1 | Region segment on GCP identity and bucket IDs |
K8S_CLUSTER | default | Account id. Also the kubeconfig context when it is not default and a kubeconfig is used. In a pod with no KUBECONFIG, it is only the account id. |
K8S_NAMESPACE | empty (all namespaces) | Limit om scan k8s to one namespace |
NVD_API_KEY | empty | Higher NVD rate limits for om enrich cve when no catalog is set |
OM_CVE_CATALOG | empty | JSON file used instead of NVD. --catalog overrides it. |
AWS, Azure, and GCP credentials themselves come from each SDK’s default chain
(AWS_ACCESS_KEY_ID, az login, GOOGLE_APPLICATION_CREDENTIALS,
instance metadata, and so on). Core does not have its own credential store.
Exports
| Variable | Used when |
|---|---|
SLACK_WEBHOOK_URL | om export findings run --format slack |
JIRA_URL | Jira site base URL |
JIRA_EMAIL | Jira account email |
JIRA_API_TOKEN | Jira API token |
JIRA_PROJECT | Project key for created issues |
Copyright © 2026 OpenSourceOM. Licensed under Apache-2.0.