Central reference for all project URLs, system endpoints, and configuration settings. Nothing secret is listed here — credentials and tokens are managed through Vault .
All runtime configuration (URLs, credentials, account IDs) is loaded from HashiCorp Vault before running any CLI command.
Setting Value Env var Vault address https://vault.service.roche.comVAULT_ADDRVault namespace rdt-model-prdVAULT_NAMESPACESecret path (dev) secret/dev/ci— Secret path (test) secret/test/ci— Secret path (prod) secret/prod/ci— Auth method OIDC + AppRole — Service users RXPMODE1, RXPMODE2—
Load Vault secrets into your shell before running CLI commands:
source scripts/vault-env.sh dev # or test, prod
All URLs below are loaded from Vault at runtime. The env var column shows what to set for local overrides.
System Purpose Env var Config key RTiS Canonical data model, ontologies, terminologies RTIS_BASE_URLrtis.base_urlGUPRI Persistent identifier registration GUPRI_BASE_URLgupri.base_urlCollibra Data governance, stewardship, classification COLLIBRA_BASE_URLcollibra.base_urlMRHub Master data for G2 validity checks MRHUB_BASE_URLmrhub.base_urlAurora PostgreSQL Upstream table profiling AURORA_HOSTaurora.host
System Purpose Env var Config key Snowflake Data warehouse (Bronze/Silver/Gold/Semantic) SNOWFLAKE_URLsnowflake.urlSolace Enterprise event bus SOLACE_BROKER_URLsolace.broker_urlSolace topic SOLACE_TOPICsolace.topicClient certificate (PEM) SOLACE_CLIENT_CERTsolace.client_certClient private key (PEM) SOLACE_CLIENT_KEYsolace.client_keySinequa Enterprise search SINEQUA_BASE_URLsinequa.base_urlMulesoft API management (Anypoint) MULESOFT_BASE_URLmulesoft.base_urlServiceNow Change management (CIDM) SERVICENOW_BASE_URLservicenow.base_urlLeanIX Enterprise architecture catalog (stretch) LEANIX_BASE_URLleanix.base_urlData Marketplace Data product registry (stretch) DATA_MARKETPLACE_BASE_URLdata_marketplace.base_url
System Purpose Env var Config key CaaS (Rancher) Kubernetes hosting for OPA instances CAAS_NAMESPACEcaas.namespaceArtifactory Cargo crate registry — —
Setting Env var Config key Account SNOWFLAKE_ACCOUNTsnowflake.accountWarehouse SNOWFLAKE_WAREHOUSEsnowflake.warehouseDatabase SNOWFLAKE_DATABASEsnowflake.databaseSchema prefix SNOWFLAKE_SCHEMA_PREFIXsnowflake.schema_prefixRole SNOWFLAKE_ROLEsnowflake.roleUser SNOWFLAKE_USERsnowflake.userAuth method SNOWFLAKE_AUTH_METHODsnowflake.auth_methodOAuth token URL SNOWFLAKE_OAUTH_TOKEN_URLsnowflake.oauth_token_urlOAuth scope SNOWFLAKE_OAUTH_SCOPEsnowflake.oauth_scope
Environment Bronze Silver Gold Semantic Dev DEV_BRONZEDEV_SILVERDEV_GOLDDEV_SEMANTICTest TEST_BRONZETEST_SILVERTEST_GOLDTEST_SEMANTICProd PROD_BRONZEPROD_SILVERPROD_GOLDPROD_SEMANTIC
Context Method User CI/CD pipelines RSA key-pair S1DEINGILocal development External Browser SSO STREITS (personal)
PAT (Personal Access Token) is not approved at Roche for Snowflake.
Static ontology IDs configured in roche-data.toml. These change only when the RTiS model changes.
Entity Class ID Terminology ID organization-site ROX38275200443992329ROX38218176443982250waste-tracking TBD (pending RTiS class request) TBD
roche-data.toml (base) → [environments.{target}] overrides → env var overrides
Every rdt-model-* command requires --target dev|test|prod (or RDT_TARGET env var). There is no default.
Setting Env var Config key Base URL COLLIBRA_BASE_URLcollibra.base_urlClient ID MULESOFT_MODEL_CLIENT_IDcollibra.client_idClient secret MULESOFT_MODEL_CLIENT_SECRETcollibra.client_secretBridge key X-META-BRIDGE-KEYcollibra.bridge_key
Env var Purpose RDT_TARGETTarget environment (dev, test, prod) — set in shell profile RDT_PROJECT_NAMEProject name override RDT_DOMAINBusiness domain override RDT_REPORepository identifier override RDT_BOARDProject board URL override RDT_SRA_IDSecurity Risk Assessment ID RDT_SRA_STATUSSRA approval status GITHUB_ORGGitHub organization GITHUB_REPOGitHub repository name GITHUB_BOARD_URLProject board URL RUST_LOGOverride tracing verbosity (e.g. debug, rdt_model_pull=trace)
Access request status for each external system. See the platforms/ directory for details.
Platform Access task Issue Status RTiS A01 #15 Blocked — awaiting service account GUPRI A02 #16 Blocked — awaiting service account Snowflake A05, A06 #23 Not started MRHub A03, A04 #24 Not started Collibra A07, A08 #25 Not started Mulesoft A09 #26 Not started ServiceNow A12 #27 Not started CaaS A13 #28 Not started Vault A16 #70 Not started LeanIX A14 #29 Not started (stretch) Data Marketplace A15 #30 Not started (stretch) Aurora PostgreSQL A18 — Not started Snowflake WAM OAuth A19 — Not started