Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
*
!package.json
!pnpm-lock.yaml
!pnpm-workspace.yaml
!src
58 changes: 58 additions & 0 deletions .github/workflows/image.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
name: Image

# Build the service image on each pull request. On main, also push it to
# ghcr.io/getsentry/roach, where deploy/gcp pulls it from.
on:
push:
branches: [main]
pull_request:

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}

jobs:
image:
name: image
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- if: github.ref == 'refs/heads/main'
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
push: ${{ github.ref == 'refs/heads/main' }}
tags: |
ghcr.io/getsentry/roach:main
ghcr.io/getsentry/roach:${{ github.sha }}

terraform:
name: terraform
runs-on: ubuntu-latest
timeout-minutes: 10
defaults:
run:
working-directory: deploy/gcp
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
- run: terraform fmt -check
- run: terraform init -backend=false
- run: terraform validate
15 changes: 9 additions & 6 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,20 +14,23 @@
| Lint file | `pnpm exec oxlint --deny-warnings src/server.ts` |
| Format | `pnpm format` |
| Typecheck | `pnpm typecheck` |
| Deployed shape | `pnpm exec vitest run tests/deployed.test.ts` |
| Unused code/deps | `pnpm knip` |
| Everything (CI) | `pnpm check` |

## External References

| Need | File |
| -------------------------------------- | ---------------------- |
| Usage, config, recordings, control API | `README.md` |
| Public types | `src/types.ts` |
| Map of source files | "Files" in `README.md` |
| Need | File |
| -------------------------------------- | ------------------------------------- |
| Usage, config, recordings, control API | `README.md` |
| Service access, limits, and deploy | "Service" and "Deploy" in `README.md` |
| Public types | `src/types.ts` |
| Map of source files | "Files" in `README.md` |

## Key Conventions

- Add no runtime dependencies. Use Node built-ins and the `openssl` command only.
- Use Node built-ins and the `openssl` command. The only runtime dependency is `@sentry/node`, and only `src/service.ts` imports it. The local proxy and the client must not load it.
- `deploy/gcp/` is the production setup (Terraform). Change it in the same change when the service config (`RoachServiceConfig`) changes. CI runs `terraform validate` on it.
- Node runs `src/` as TypeScript with type stripping. Use only erasable syntax, and import local files with the `.ts` extension.
- Use functions and plain objects, not classes.
- Start each source file with a comment that says what the file owns. Give each export a short JSDoc.
Expand Down
13 changes: 13 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
# The image of the Roach service. deploy/gcp runs it with the config file
# at /config/roach.json. See "Deploy" in README.md.
FROM node:24-alpine
# Roach signs a certificate for each intercepted host with openssl.
RUN apk add --no-cache openssl && corepack enable
WORKDIR /app
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
RUN pnpm install --prod --frozen-lockfile --ignore-scripts
COPY src ./src
USER node
EXPOSE 8080
ENTRYPOINT ["node", "src/cli.ts"]
CMD ["service", "/config/roach.json"]
Loading
Loading