Get started

Configure OpenSourceOM

om reads process environment variables. It does not load .env. Docker Compose interpolates .env for the API service. Copy .env.example in the core repository and export only the variables you need in the shell that runs the CLI.

A database URL is built from the POSTGRES_* variables unless DATABASE_URL is set. The default URL is postgres://opensourceom:opensourceom@localhost:5432/opensourceom?sslmode=disable.

Process

Variable Default Used by
OM_ENV development API container label. The CLI stores it and does not branch on it.
OM_LOG_LEVEL info Reserved. The API logger is the standard library logger.
OM_PUBLIC_URL http://localhost:8080 Public URL hint. Requests use the listen address.
OM_API_PORT 8080 om serve
OM_API_SECRET change-me-in-production Shared secret for every /v1 route except GET /v1/health. See Security.

Database

Variable Default
DATABASE_URL Built from the fields below
POSTGRES_USER opensourceom
POSTGRES_PASSWORD opensourceom
POSTGRES_DB opensourceom
POSTGRES_HOST localhost
POSTGRES_PORT 5432

Inside Compose, the API service sets POSTGRES_HOST=postgres. On your laptop, keep the CLI default of localhost.

Collectors

Variable Default Required for
AWS_REGION us-east-1 om scan aws (one region per run)
AZURE_SUBSCRIPTION_ID empty om scan azure
AZURE_LOCATION eastus Fallback region on Azure node IDs
GCP_PROJECT_ID empty om scan gcp
GCP_REGION us-central1 Region segment on GCP identity and bucket IDs
K8S_CLUSTER default Account id. Also the kubeconfig context when it is not default and a kubeconfig is used. In a pod with no KUBECONFIG, it is only the account id.
K8S_NAMESPACE empty (all namespaces) Limit om scan k8s to one namespace
NVD_API_KEY empty Higher NVD rate limits for om enrich cve when no catalog is set
OM_CVE_CATALOG empty JSON file used instead of NVD. --catalog overrides it.

AWS, Azure, and GCP credentials themselves come from each SDK’s default chain (AWS_ACCESS_KEY_ID, az login, GOOGLE_APPLICATION_CREDENTIALS, instance metadata, and so on). Core does not have its own credential store.

Exports

Variable Used when
SLACK_WEBHOOK_URL om export findings run --format slack
JIRA_URL Jira site base URL
JIRA_EMAIL Jira account email
JIRA_API_TOKEN Jira API token
JIRA_PROJECT Project key for created issues