Prerequisites
- Grafana Tempo 1.4+
- Network access from the OpenSRE environment to your Tempo instance
- Auth credentials only if your deployment requires them (many run without auth behind a gateway)
Setup
Option 1: Interactive CLI
Option 2: Environment variables
Add to your.env:
Option 3: Persistent store
Integrations are automatically persisted to~/.opensre/integrations.json:
Investigation tools
OpenSRE exposes a singlequery_tempo tool with an action parameter:
search
Searches traces by service, span name, duration, and tags using TraceQL. Returns one summary row per trace.get_trace
Fetches a full trace by ID and flattens its spans.list_services
Lists all services registered in Tempo.list_span_names
Lists all span names registered in Tempo.Verify
Troubleshooting
Security best practices
- Use a read-only token or service account if your Tempo deployment supports auth.
- Store credentials in
.env, never in code. - Restrict network access to Tempo — OpenSRE only needs the HTTP API port (
3200by default).