# Environment Variables

<!-- BOOKSTACK-DOCUMENT-RELEASE:BEGIN -->
# Environment Variables

| Field | Value |
| --- | --- |
| Distribution | BSS — OpenSOF |
| Product | OpenSOF |
| Release | 0.15.1 |
| Deployment | `opensof.bss.dev` |
| Source | `/srv/bss/releases/OpenSOF-v0.15.0-20app` |
| Evidence | Static environment-reference scan; values redacted |
| Source fingerprint | `cda583b42f2a0d296b268ab5b174932a378c8be6fb52ffa1af14af896e990f6e` |
| Status | Generated baseline — human review required |

> **Verification boundary:** This page combines platform design guidance with static evidence from the release. It does not prove that every detected interface is enabled, reachable, secure, or operational in the deployed environment.

## Observed variables

| Variable | Secret-like | Observed default | Mechanism | Evidence |
| --- | --- | --- | --- | --- |
| `ADDRESS` | No | — | interpolation | `openrf/agent/functions/probe-n310.sh` |
| `AEGIS_SENTINEL_LABEL` | No | `COMPILED_DEPLOYMENT.aegisSentinelLabel).trim() \|\| COMPILED_DEPLOYMENT.aegisSentinelLabel` | process.env | `server.js`<br>`tools/integrate_opensof_service_entries.py` |
| `ALT` | No | — | shell | `edge/openssa-sensor/install-demo-sensor.sh` |
| `ANTHROPIC_API_KEY` | Yes | — | process.env | `server.js`<br>`lib/openllm/agents.js`<br>`lib/openllm/providers.js` |
| `API` | No | — | interpolation | `open-cybersec/app.js`<br>`public/open-cybersec/app.js`<br>`public/open-llm/app.js` |
| `API_BASE` | No | — | interpolation | `open-rf/app.js`<br>`public/open-networks/app.js`<br>`public/open-rf/app.js` |
| `BACKUP_ROOT` | No | — | shell | `modules/open-networks/integration/install-module-files.sh` |
| `BASE` | No | `http://127.0.0.1:3000` | shell, interpolation | `DEPLOY-GODADDY.md`<br>`OPENCYBERSEC-QUICKSTART.md`<br>`OPENCYBERSEC.md`<br>`UPGRADE-v0.14.0.md`<br>`rocketchat/outgoing-webhook-test.sh`<br>`scenarios/run_demo_sequence.sh` |
| `BASE_PATH` | No | — | interpolation, shell | `open-rf/app.js`<br>`public/open-rf/app.js`<br>`third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `BLAZEGRAPH` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `BUILD` | No | — | shell | `edge/openpnt-linuxptp/SELF-TEST.sh`<br>`edge/openssa-sensor/install/install-native-uhd.sh`<br>`edge/openssa-sensor/native/uhd_spectrum_engine/build-simulation.sh`<br>`edge/openssa-sensor/native/uhd_spectrum_engine/build.sh` |
| `BUILDPATH` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `BUILD_DIR` | No | `$ENGINE/build` | interpolation | `edge/openssa-sensor/install/install-native-uhd.sh`<br>`edge/openssa-sensor/native/uhd_spectrum_engine/build-simulation.sh`<br>`edge/openssa-sensor/native/uhd_spectrum_engine/build.sh` |
| `BUILD_ROOT` | No | — | shell | `edge/openpnt-linuxptp/install-linuxptp.sh` |
| `CATALINA_BASE` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `CATALINA_HOME` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `CFG` | No | — | shell | `edge/openssa-sensor/install-demo-sensor.sh` |
| `CONFIG` | No | — | shell | `drivers/install_openpnt_agent.sh`<br>`edge/opencybersec/install.sh`<br>`edge/openssa-sensor/install/check-sensor.sh`<br>`edge/openssa-sensor/install/install-sensor.sh`<br>`openrf/agent/functions/start-5g-ran-b210-50mhz.sh`<br>`openrf/agent/functions/start-5g-ran-n78-n310.sh` |
| `CORE_DIR` | No | — | shell | `openrf/agent/functions/start-5g-core.sh`<br>`openrf/agent/functions/status-5g-core.sh` |
| `CROSS_COMPILE` | No | — | interpolation | `third_party/openil_linuxptp/incdefs.sh` |
| `CURRENT` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `DATA_DIR` | No | `path.join(ROOT` | interpolation, process.env | `OPENCYBERSEC-QUICKSTART.md`<br>`OPENCYBERSEC.md`<br>`RELEASE-MANIFEST-v0.14.0.json`<br>`UPGRADE-v0.14.0.md`<br>`server.js` |
| `DRIVER` | No | — | shell | `edge/openssa-sensor/install-demo-sensor.sh`<br>`edge/openssa-sensor/install/check-sensor.sh`<br>`edge/openssa-sensor/install/install-ubuntu-deps.sh` |
| `EF_STORE_ADAPTER` | No | — | getenv, shell | `third_party/ontowiki/application/classes/OntoWiki/Test/IntegrationTestBootstrap.php` |
| `ENGINE` | No | — | shell | `edge/openssa-sensor/install/install-native-uhd.sh` |
| `ENV_FILE` | No | — | shell | `edge/opencybersec/install.sh` |
| `EOD_TECH_TARGET` | No | `@eodtech` | process.env | `server.js` |
| `EUID` | No | `$(id -u` | interpolation, shell | `drivers/install_openpnt_agent.sh`<br>`edge/opencybersec/install.sh`<br>`edge/opencybersec/uninstall.sh`<br>`edge/openpnt-linuxptp/install-linuxptp.sh`<br>`edge/openpnt-linuxptp/uninstall-linuxptp.sh`<br>`openrf/agent/install.sh` |
| `E_UNREACHABLE` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `FG_ROOT` | No | — | shell | `edge/openlvc/flightgear/opensof-lvc.xml` |
| `FOURSTORE` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `FUSEKI` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `GNB` | No | — | shell | `openrf/agent/functions/start-5g-ran-b210-50mhz.sh`<br>`openrf/agent/functions/start-5g-ran-n78-n310.sh` |
| `HERE` | No | — | shell | `edge/openpnt-linuxptp/SELF-TEST.sh`<br>`edge/openpnt-linuxptp/install-linuxptp.sh`<br>`edge/openssa-sensor/native/uhd_spectrum_engine/build-simulation.sh`<br>`edge/openssa-sensor/native/uhd_spectrum_engine/build.sh`<br>`examples/opencybersec/ingest-examples.sh`<br>`scenarios/run_demo_sequence.sh` |
| `HOME` | No | `/tmp` | process.env, shell | `lib/openllm/pipeline-engine.js`<br>`openrf/agent/functions/start-5g-core.sh`<br>`openrf/agent/functions/status-5g-core.sh`<br>`third_party/ontowiki/.travis.yml` |
| `HOST` | No | `0.0.0.0` | process.env, interpolation | `server.js`<br>`lib/openrf-controller/server.js` |
| `INSTALL_DIR` | No | — | shell | `edge/opencybersec/install.sh` |
| `INSTANCE` | No | — | shell | `edge/openpnt-linuxptp/install-linuxptp.sh` |
| `ISQLFILE` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `JOBS` | No | — | shell | `edge/openpnt-linuxptp/install-linuxptp.sh` |
| `KBUILD_OUTPUT` | No | — | interpolation, shell | `third_party/openil_linuxptp/incdefs.sh` |
| `KNOWLEDGE_NS` | No | — | interpolation | `server.js` |
| `LANG` | No | `C.UTF-8` | process.env | `lib/openllm/pipeline-engine.js` |
| `LAT` | No | — | shell | `edge/openssa-sensor/install-demo-sensor.sh` |
| `LON` | No | — | shell | `edge/openssa-sensor/install-demo-sensor.sh` |
| `MISSION_KNOWLEDGE_NS` | No | — | interpolation | `server.js` |
| `MOUNT_PATH` | No | `COMPILED_DEPLOYMENT.mountPath` | process.env, interpolation | `server.js` |
| `NATIVE_SOURCE` | No | — | shell | `edge/openssa-sensor/install/install-sensor.sh`<br>`edge/openssa-sensor/install/update-existing-sensor.sh` |
| `NODE_ID` | No | `COMPILED_DEPLOYMENT.nodeId` | process.env | `server.js`<br>`edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `NS` | No | — | interpolation | `lib/openiia.js` |
| `OPENAAR_BATCH_SIZE` | No | `100` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_CLOCK_SOURCE` | No | `SYSTEM` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_MAX_SPOOL_MB` | No | `2048` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_NODE_ID` | No | `socket.gethostname(` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_RECONNECT_S` | No | `5` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_RECORDER_ID` | No | `f"EDGE-{socket.gethostname(` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_REPORT_INTERVAL_S` | No | `30` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_RUN_ID` | No | — | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_SERVER` | No | `http://127.0.0.1:3000` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_SIGNING_KEY` | Yes | `[REDACTED]` | process.env | `server.js` |
| `OPENAAR_SITE` | No | `FIELD` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_SNAPSHOT_EVERY_EVENTS` | No | `100` | process.env | `server.js` |
| `OPENAAR_SNAPSHOT_INTERVAL_S` | No | `30` | process.env | `server.js` |
| `OPENAAR_SPOOL_DIR` | No | `/var/lib/openaar-edge` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_TIME_UNCERTAINTY_NS` | No | `0` | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_TOPICS` | No | — | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAAR_TYPES` | No | — | os.getenv | `drivers/openaar_edge_recorder.py` |
| `OPENAI_API_KEY` | Yes | — | process.env | `server.js`<br>`lib/openllm/providers.js` |
| `OPENANALYTICS_CONNECTOR_TIMEOUT_MS` | No | `60000` | process.env | `server.js` |
| `OPENBUS_API_TOKEN` | Yes | `[REDACTED]` | shell, os.getenv, process.env, getenv, interpolation | `OPENKNOWLEDGE-OPENTASK.md`<br>`OPENLVC-DEMO.md`<br>`OPENLVC-RTI.md`<br>`demo_simulator.py`<br>`server.js`<br>`drivers/openaar_edge_recorder.py` |
| `OPENBUS_MAX_HISTORY` | No | `500` | process.env | `server.js` |
| `OPENCHAT_DEFAULT_TARGET` | No | `#eod-ops` | process.env | `server.js` |
| `OPENCOP_TRACK_URL` | No | `https://opencop.c24.airoapp.ai/api/tracks` | process.env | `server.js` |
| `OPENCOP_UI_URL` | No | `BUILTIN_OPENCOP_UI_URL` | process.env | `server.js` |
| `OPENCYBERSEC_AGENT_TOKEN` | Yes | `[REDACTED]` | shell, process.env, interpolation | `OPENCYBERSEC-QUICKSTART.md`<br>`OPENCYBERSEC.md`<br>`server.js`<br>`examples/opencybersec/ingest-examples.sh` |
| `OPENCYBERSEC_OPERATOR_TOKEN` | Yes | `[REDACTED]` | shell, process.env, interpolation | `OPENCYBERSEC-QUICKSTART.md`<br>`OPENCYBERSEC.md`<br>`server.js`<br>`examples/opencybersec/ingest-examples.sh` |
| `OPENCYBERSEC_READ_TOKEN` | Yes | — | process.env | `server.js` |
| `OPENFILES_HEALTH_URL` | No | — | process.env | `server.js`<br>`tools/integrate_opensof_service_entries.py` |
| `OPENFILES_PUBLIC_URL` | No | — | process.env | `tools/integrate_opensof_service_entries.py` |
| `OPENFILES_SERVICE_URL` | No | — | process.env | `server.js` |
| `OPENIIA_MAX_EVIDENCE_BYTES` | No | `12000000` | process.env | `server.js` |
| `OPENISAC_HEALTH_URL` | No | — | process.env | `server.js`<br>`tools/integrate_opensof_service_entries.py` |
| `OPENISAC_PUBLIC_URL` | No | `https://bss.dev/live/isac/` | process.env | `tools/integrate_opensof_service_entries.py` |
| `OPENISAC_SERVICE_URL` | No | — | process.env | `server.js` |
| `OPENKNOWLEDGE_EDITOR_TOKEN` | Yes | `[REDACTED]` | process.env | `server.js` |
| `OPENKNOWLEDGE_GRAPH` | No | `https://opensof.local/graph/core` | process.env | `server.js` |
| `OPENKNOWLEDGE_MODEL_FILE` | No | `path.join(DATA` | process.env | `server.js` |
| `OPENKNOWLEDGE_ONTOWIKI_URL` | No | — | process.env | `server.js` |
| `OPENKNOWLEDGE_SPARQL_ENDPOINT` | No | — | process.env | `server.js` |
| `OPENKNOWLEDGE_TIMEOUT_MS` | No | `8000` | process.env | `server.js` |
| `OPENLLM_AGENT_MAX_OUTPUT_BYTES` | No | — | process.env | `lib/openllm/agents.js` |
| `OPENLLM_AGENT_TIMEOUT_MS` | No | — | process.env | `lib/openllm/agents.js` |
| `OPENLLM_ALLOW_LOCAL_EXECUTION` | No | — | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_ANTHROPIC_API_KEY` | Yes | `[REDACTED]` | process.env | `server.js`<br>`lib/openllm/providers.js` |
| `OPENLLM_ANTHROPIC_URL` | No | `https://api.anthropic.com/v1').replace(/\/+$/` | process.env | `lib/openllm/providers.js` |
| `OPENLLM_ANTHROPIC_VERSION` | No | `2023-06-01` | process.env | `lib/openllm/providers.js` |
| `OPENLLM_CLAUDE_BIN` | No | `claude` | process.env | `lib/openllm/agents.js` |
| `OPENLLM_CODEX_BIN` | No | `codex` | process.env | `lib/openllm/agents.js` |
| `OPENLLM_COMMAND_MODE` | No | `off').toLowerCase(` | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_FALLBACK_WRITE_MAX_BYTES` | No | — | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_HEALTH_TIMEOUT_MS` | No | — | process.env | `lib/openllm/providers.js` |
| `OPENLLM_MAX_AUDIT` | No | — | process.env | `lib/openllm.js` |
| `OPENLLM_MAX_RUNS` | No | — | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_MODEL_CACHE_TTL_MS` | No | — | process.env | `lib/openllm/providers.js` |
| `OPENLLM_OPENAI_API_KEY` | Yes | `[REDACTED]` | process.env | `server.js`<br>`lib/openllm/providers.js` |
| `OPENLLM_OPENAI_URL` | No | `https://api.openai.com/v1').replace(/\/+$/` | process.env | `lib/openllm/providers.js` |
| `OPENLLM_OPENBUS_SCHEMA` | No | `opensof.openbus.event/1.0` | process.env | `lib/openllm.js` |
| `OPENLLM_OPENWEBUI_API_KEY` | Yes | `[REDACTED]` | process.env | `server.js`<br>`lib/openllm/providers.js` |
| `OPENLLM_OPENWEBUI_CHAT_PATH` | No | `/api/chat/completions` | process.env | `lib/openllm/providers.js` |
| `OPENLLM_OPENWEBUI_HEALTH_PATH` | No | `/health` | process.env | `lib/openllm/providers.js` |
| `OPENLLM_OPENWEBUI_MODELS_PATH` | No | `/api/models` | process.env | `lib/openllm/providers.js` |
| `OPENLLM_OPENWEBUI_URL` | No | `process.env.OPENWEBUI_URL \|\|` | process.env | `server.js`<br>`lib/openllm/providers.js` |
| `OPENLLM_OPERATOR_TOKEN` | Yes | `[REDACTED]` | process.env | `server.js`<br>`lib/openllm.js` |
| `OPENLLM_PROVIDER_TIMEOUT_MS` | No | — | process.env | `lib/openllm/providers.js` |
| `OPENLLM_QWEN_BIN` | No | `qwen` | process.env | `lib/openllm/agents.js` |
| `OPENLLM_SANDBOX_CPUS` | No | `2` | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_SANDBOX_IMAGE` | No | `openc5isr-openllm-sandbox:0.1.0` | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_SANDBOX_MEMORY` | No | `2g` | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_SANDBOX_PIDS` | No | `256` | process.env | `lib/openllm/pipeline-engine.js` |
| `OPENLLM_WORKSPACES_DIR` | No | `path.join(ROOT` | process.env | `server.js` |
| `OPENLVC_FEDERATE` | No | — | interpolation | `edge/openlvc/systemd/openlvc-rti-gateway.service` |
| `OPENLVC_FEDERATION` | No | — | interpolation | `edge/openlvc/systemd/openlvc-rti-gateway.service` |
| `OPENLVC_HEALTH_URL` | No | — | process.env | `server.js`<br>`tools/integrate_opensof_service_entries.py` |
| `OPENLVC_PUBLIC_URL` | No | — | process.env | `tools/integrate_opensof_service_entries.py` |
| `OPENLVC_RTI_SIDECAR_COMMAND` | No | — | interpolation | `edge/openlvc/systemd/openlvc-rti-gateway.service` |
| `OPENLVC_SERVICE_URL` | No | — | process.env | `server.js` |
| `OPENMAIL_HEALTH_URL` | No | — | process.env | `server.js`<br>`tools/integrate_opensof_service_entries.py` |
| `OPENMAIL_PUBLIC_URL` | No | — | process.env | `tools/integrate_opensof_service_entries.py` |
| `OPENMAIL_SERVICE_URL` | No | — | process.env | `server.js` |
| `OPENNETWORKS_AGENT_SOCKET` | No | `/run/opennetworks/agent.sock` | process.env | `lib/open-networks/agent-client.js`<br>`modules/open-networks/integration/native-server-example.js` |
| `OPENNETWORKS_AGENT_TIMEOUT_MS` | No | `120000` | process.env | `lib/open-networks/agent-client.js`<br>`modules/open-networks/integration/native-server-example.js` |
| `OPENNETWORKS_BODY_LIMIT_BYTES` | No | `2 * 1024 * 1024` | process.env | `lib/open-networks/index.js` |
| `OPENNETWORKS_DATA_DIR` | No | `path.join(this.rootDir` | process.env | `lib/open-networks/service.js`<br>`modules/open-networks/integration/native-server-example.js` |
| `OPENNETWORKS_EXECUTION_MODE` | No | `simulate` | process.env | `lib/open-networks/service.js`<br>`modules/open-networks/integration/native-server-example.js` |
| `OPENPNT_AGENT_TOKEN` | Yes | `[REDACTED]` | os.getenv, process.env | `drivers/openpnt_agent.py`<br>`lib/openpnt.js` |
| `OPENPNT_BUILD_JOBS` | No | `$(getconf _NPROCESSORS_ONLN 2>/dev/null \|\| echo 2` | interpolation | `edge/openpnt-linuxptp/install-linuxptp.sh` |
| `OPENPNT_CLOCK_STALE_AFTER_S` | No | — | process.env | `lib/openpnt-timing.js` |
| `OPENPNT_LINUXPTP_BIN_DIR` | No | — | os.getenv | `drivers/openpnt_agent.py`<br>`drivers/openpnt_linuxptp.py` |
| `OPENPNT_NODE_ID` | No | — | os.getenv | `drivers/openpnt_agent.py`<br>`drivers/openpnt_linuxptp.py` |
| `OPENPNT_POLL_SECONDS` | No | — | os.getenv | `drivers/openpnt_agent.py` |
| `OPENPNT_POSITION_MAX_AGE_S` | No | — | process.env | `lib/openpnt.js` |
| `OPENPNT_PTP_CONFIG` | No | — | os.getenv | `drivers/openpnt_agent.py` |
| `OPENPNT_PTP_INSTANCE` | No | — | os.getenv | `drivers/openpnt_agent.py` |
| `OPENPNT_PTP_INTERFACE` | No | — | os.getenv | `drivers/openpnt_agent.py` |
| `OPENPNT_SERVER` | No | — | os.getenv | `drivers/openpnt_agent.py` |
| `OPENPNT_SPOOL_FILE` | No | — | os.getenv | `drivers/openpnt_agent.py` |
| `OPENPNT_TAI_UTC_OFFSET_S` | No | — | process.env | `lib/openpnt.js` |
| `OPENPNT_TDOA_MAX_UNCERTAINTY_NS` | No | — | process.env | `lib/openpnt-timing.js` |
| `OPENPNT_TDOA_MIN_SENSORS` | No | — | process.env | `lib/openpnt-timing.js` |
| `OPENPNT_TOKEN` | Yes | — | os.getenv | `drivers/openpnt_agent.py` |
| `OPENRF_5G_CORE_DIR` | No | `$HOME/5g/magic-core` | interpolation | `openrf/agent/functions/start-5g-core.sh`<br>`openrf/agent/functions/status-5g-core.sh` |
| `OPENRF_AGENT_OFFLINE_SECONDS` | No | `70` | process.env | `lib/openrf-controller/server.js` |
| `OPENRF_AGENT_TOKEN` | Yes | `[REDACTED]` | process.env, shell | `server.js`<br>`lib/openrf-controller/server.js`<br>`openrf/API.md` |
| `OPENRF_BASE_PATH` | No | `/open-rf` | process.env | `lib/openrf-controller/server.js` |
| `OPENRF_DATA_DIR` | No | `path.join(DATA` | process.env | `server.js`<br>`lib/openrf-controller/server.js` |
| `OPENRF_DISPATCH_LEASE_SECONDS` | No | `90` | process.env | `lib/openrf-controller/server.js` |
| `OPENRF_OPERATOR_TOKEN` | Yes | `[REDACTED]` | process.env, shell | `server.js`<br>`lib/openrf-controller/server.js`<br>`openrf/API.md`<br>`openrf/README-UPSTREAM-v0.3.0.md` |
| `OPENRF_PYTHON` | No | `/usr/bin/python3` | os.getenv | `openrf/agent/src/openrf_agent/util.py` |
| `OPENRF_RADIO_ADDRESS` | No | `192.168.20.2` | interpolation | `openrf/agent/functions/probe-n310.sh` |
| `OPENRF_RADIO_ID` | No | `N310-01` | interpolation | `openrf/agent/functions/start-5g-ran-n78-n310.sh` |
| `OPENRF_READ_TOKEN` | Yes | — | process.env, shell | `server.js`<br>`lib/openrf-controller/server.js`<br>`openrf/API.md` |
| `OPENSOF_BASE` | No | `http://127.0.0.1:3000` | os.getenv | `scenarios/run_openeyes_demo.py` |
| `OPENSOF_EVENT_URL` | No | `http://127.0.0.1:3000/api/event` | os.getenv | `demo_simulator.py` |
| `OPENSOF_ROOT` | No | `https://wallacecorptech.com/live/opensof` | interpolation | `examples/opencybersec/ingest-examples.sh` |
| `OPENSOF_URL` | No | `http://127.0.0.1:3000` | shell, os.getenv, getenv, interpolation | `OPENLVC-DEMO.md`<br>`edge/openlvc/README.md`<br>`edge/openlvc/dis_udp_bridge.py`<br>`edge/openlvc/rti_openbus_gateway.py`<br>`edge/openlvc/systemd/openlvc-ais-bridge.service`<br>`edge/openlvc/systemd/openlvc-dis-bridge.service` |
| `OPENSSA_ACTIVE_TIMEOUT_S` | No | `900` | process.env | `server.js`<br>`edge/openssa-sensor/SERVER_INTEGRATION.md`<br>`edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `OPENSSA_EMITTER_HISTORY_LIMIT` | No | `2000` | process.env | `edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `OPENSSA_EMITTER_SIGHTING_LIMIT` | No | `500` | process.env | `edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `OPENSSA_GEOLOCATION_HISTORY_LIMIT` | No | `100` | process.env | `edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `OPENSSA_ITU_REGION` | No | `2` | process.env | `server.js`<br>`edge/openssa-sensor/SERVER_INTEGRATION.md`<br>`edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `OPENSSA_LOCATION_PROFILE` | No | — | os.getenv | `edge/openssa-sensor/drivers/ssa_sensor.py` |
| `OPENSSA_SENSOR_TOKEN` | Yes | `[REDACTED]` | process.env, os.getenv | `server.js`<br>`edge/openssa-sensor/SERVER_INTEGRATION.md`<br>`edge/openssa-sensor/local_server.js`<br>`edge/openssa-sensor/demo/run_streaming_demo.py`<br>`edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `OPENSSA_UHD_SPECTRUM_ENGINE` | No | — | os.getenv | `edge/openssa-sensor/drivers/ssa_sensor.py` |
| `OPENWEBUI_API_KEY` | Yes | `[REDACTED]` | process.env | `server.js`<br>`lib/openllm/providers.js` |
| `OPENWEBUI_CHAT_PATH` | No | `/api/chat/completions` | process.env | `server.js` |
| `OPENWEBUI_DEFAULT_MODEL` | No | — | process.env | `server.js` |
| `OPENWEBUI_HEALTH_PATH` | No | `/health` | process.env | `server.js` |
| `OPENWEBUI_MODELS_PATH` | No | `/api/models` | process.env | `server.js` |
| `OPENWEBUI_URL` | No | `).replace(/\/+$/` | process.env | `server.js` |
| `OPEN_EYES_API_BASE` | No | — | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_EYES_ASSET_ID` | No | `ISAC-RASPBOT-01` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_EYES_DEFAULT_ASSET` | No | `ISAC-RASPBOT-01` | process.env | `server.js` |
| `OPEN_EYES_HTTP_TIMEOUT` | No | `3` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_EYES_LOG_LEVEL` | No | `INFO` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_EYES_RECONNECT_DELAY` | No | `2` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_EYES_STATUS_INTERVAL` | No | `0.25` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_EYES_VERIFY_TLS` | No | `true` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_EYES_VIDEO_FPS` | No | `15` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `OPEN_SOF` | No | — | shell | `OPENKNOWLEDGE-OPENTASK.md` |
| `OWHG` | No | — | shell | `third_party/ontowiki/application/scripts/makeRelease.sh` |
| `PATH` | No | `/usr/sbin:/usr/bin:/sbin:/bin` | os.getenv, process.env, shell | `edge/opencybersec/opencybersec_agent.py`<br>`lib/openllm/pipeline-engine.js`<br>`lib/openllm/util.js`<br>`tests/openpnt_agent_smoke_test.py`<br>`tests/openpnt_linuxptp_wrapper_smoke_test.py`<br>`third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `PHPVERSION` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-extensions.sh` |
| `PHP_` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-extensions.sh` |
| `PORT` | No | `3000` | process.env, interpolation | `server.js`<br>`edge/openssa-sensor/local_server.js`<br>`lib/openrf-controller/server.js` |
| `PUBLIC_BASE_URL` | No | `COMPILED_DEPLOYMENT.publicBaseUrl).replace(/\/+$/` | process.env, interpolation | `server.js` |
| `PWD` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `PYTHONUNBUFFERED` | No | `1` | systemd | `openrf/agent/systemd/openrf-agent.service` |
| `RASPBOT_BROWSER_WS_URL` | No | — | process.env | `server.js` |
| `RASPBOT_CONTROL_URL` | No | — | process.env | `server.js` |
| `RASPBOT_LOCAL_URL` | No | `http://127.0.0.1:6001` | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `RASPBOT_STREAM_URL` | No | — | process.env | `server.js` |
| `RASPBOT_WS_URL` | No | — | os.getenv | `drivers/raspbot_openeyes_agent.py` |
| `RES` | No | — | interpolation | `lib/openiia.js` |
| `RESULTFILE` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `ROCKETCHAT_AUTH_TOKEN` | Yes | `[REDACTED]` | process.env | `server.js` |
| `ROCKETCHAT_BOT_USERNAME` | No | `openc5.bot` | process.env | `server.js` |
| `ROCKETCHAT_EMBED_URL` | No | — | process.env | `server.js` |
| `ROCKETCHAT_INCOMING_WEBHOOK_URL` | No | — | process.env | `server.js` |
| `ROCKETCHAT_OUTGOING_TOKEN` | Yes | `[REDACTED]` | process.env, interpolation | `server.js`<br>`rocketchat/outgoing-webhook-test.sh` |
| `ROCKETCHAT_PUBLIC_URL` | No | `ROCKETCHAT_URL \|\| '').replace(/\/+$/` | process.env | `server.js` |
| `ROCKETCHAT_URL` | No | `).replace(/\/+$/` | process.env, interpolation | `server.js` |
| `ROCKETCHAT_USER_ID` | No | — | process.env | `server.js` |
| `ROLE` | No | — | shell | `edge/openssa-sensor/install-demo-sensor.sh` |
| `ROOT` | No | — | shell | `edge/opencybersec/install.sh`<br>`edge/openpnt-linuxptp/SELF-TEST.sh`<br>`edge/openpnt-linuxptp/install-linuxptp.sh`<br>`edge/openssa-sensor/install-demo-sensor.sh`<br>`edge/openssa-sensor/install/install-native-uhd.sh`<br>`edge/openssa-sensor/install/install-sensor.sh` |
| `RUN_GROUP` | No | — | shell | `openrf/agent/install.sh` |
| `RUN_ID` | No | — | shell | `OPENCYBERSEC.md` |
| `RUN_USER` | No | — | shell | `openrf/agent/install.sh` |
| `SERVICE` | No | — | shell | `edge/opencybersec/install.sh` |
| `SERVICE_GROUP` | No | — | shell | `edge/openssa-sensor/install/install-sensor.sh`<br>`edge/openssa-sensor/install/update-existing-sensor.sh` |
| `SERVICE_USER` | No | — | shell | `edge/openssa-sensor/install/install-sensor.sh`<br>`edge/openssa-sensor/install/update-existing-sensor.sh` |
| `SESAME` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `SITE_ID` | No | `COMPILED_DEPLOYMENT.siteId` | process.env | `server.js`<br>`edge/openssa-sensor/lib/openssa.js`<br>`lib/openssa.js` |
| `SOURCE` | No | — | shell | `edge/openpnt-linuxptp/install-linuxptp.sh` |
| `SOURCE_ROOT` | No | — | shell | `modules/open-networks/integration/install-module-files.sh` |
| `SRC` | No | — | shell | `drivers/install_openpnt_agent.sh` |
| `SSA_API` | No | — | interpolation | `edge/openssa-sensor/public/open-ssa/app.js`<br>`open-ssa/app.js`<br>`public/open-ssa/app.js` |
| `STAMP` | No | — | shell | `modules/open-networks/integration/install-module-files.sh` |
| `STICKER` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `STICKERBEGIN` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `SUDO_USER` | No | `$USER` | interpolation | `edge/openssa-sensor/install/install-sensor.sh`<br>`edge/openssa-sensor/install/update-existing-sensor.sh`<br>`openrf/agent/install.sh` |
| `SUITE_VERSION` | No | — | interpolation | `server.js`<br>`tools/integrate_opensof_service_entries.py` |
| `TARGET_ROOT` | No | — | shell | `modules/open-networks/integration/install-module-files.sh` |
| `TASK` | No | — | shell | `rocketchat/outgoing-webhook-test.sh` |
| `TOKEN` | Yes | — | shell | `edge/openssa-sensor/install-demo-sensor.sh`<br>`rocketchat/outgoing-webhook-test.sh` |
| `TOMCAT_VERSION` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `TRACK_API` | No | — | interpolation | `integrations/opencop-openeyes/patched-static/map.js` |
| `TRAVIS_PHP_VERSION` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-extensions.sh`<br>`third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `UHD_INCLUDE_DIRS` | No | — | interpolation | `edge/openssa-sensor/native/uhd_spectrum_engine/CMakeLists.txt` |
| `UHD_LIBRARIES` | No | — | interpolation | `edge/openssa-sensor/native/uhd_spectrum_engine/CMakeLists.txt` |
| `USER` | No | — | shell | `edge/openssa-sensor/SENSOR_INSTALL.md`<br>`edge/openssa-sensor/install-demo-sensor.sh`<br>`edge/openssa-sensor/install/install-sensor.sh`<br>`edge/openssa-sensor/install/update-existing-sensor.sh`<br>`openrf/README-UPSTREAM-v0.3.0.md`<br>`third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `VIRTTMP` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `VIRTUOSO` | No | — | shell | `third_party/ontowiki/application/scripts/travis/install-services.sh` |
| `VIRTUOSO_T` | No | — | shell | `third_party/ontowiki/application/scripts/vad/prepare.sh` |
| `WORK` | No | — | shell | `edge/openssa-sensor/install-demo-sensor.sh` |

## Configuration policy

- Store edition-specific configuration outside the immutable release directory.
- Do not store passwords, tokens, private keys or complete credentials in BookStack, source control, command history or URLs.
- Document variable purpose, valid values, default behavior, reload/restart requirement and owning service.
- Use separate secrets per distribution/instance and rotate them through a recorded procedure.
- Validate required variables before service start and fail clearly instead of silently selecting unsafe defaults.
<!-- BOOKSTACK-DOCUMENT-RELEASE:END -->

---

## Maintainer Notes

<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-BEGIN -->
Add human-reviewed deployment notes, corrections, decisions, screenshots, and links here. Content outside the generated block is preserved on future runs.
<!-- BOOKSTACK-DOCUMENT-RELEASE:NOTES-END -->