From 47fd2d197559c2a243308b3ee4eaf60508e54457 Mon Sep 17 00:00:00 2001 From: "sentry-junior[bot]" <264270552+sentry-junior[bot]@users.noreply.github.com> Date: Sat, 10 Oct 2026 16:50:06 +0000 Subject: [PATCH] chore(deploy): Configure the Sentry GCP deployment Commit the Terraform state backend and the tfvars of the Sentry deployment, so applying needs no local setup beyond gcloud login. Co-Authored-By: David Cramer --- README.md | 14 +++++++++----- deploy/gcp/.gitignore | 1 - deploy/gcp/{roach.tfvars.example => roach.tfvars} | 11 +++++++---- deploy/gcp/versions.tf | 12 ++++++------ 4 files changed, 22 insertions(+), 16 deletions(-) rename deploy/gcp/{roach.tfvars.example => roach.tfvars} (59%) diff --git a/README.md b/README.md index a91c048..aefe809 100644 --- a/README.md +++ b/README.md @@ -264,11 +264,15 @@ The `Image` workflow builds the image on each pull request and pushes it on 1. Make the package `ghcr.io/getsentry/roach` public once, after the first push to `main`, so the VM can pull it without credentials. -2. Copy `deploy/gcp/roach.tfvars.example` to `roach.tfvars` and fill it in. - `allow` and `value_patterns` must cover the rules of every tenant. -3. Keep the Terraform state in a private bucket. It holds the CA key and the - write token. See the `backend "gcs"` comment in `versions.tf`. -4. Apply: +2. `deploy/gcp/roach.tfvars` has the values of the Sentry deployment: the + GCP project `roach-511216`, the domain, `allow`, and `value_patterns`. + `allow` and `value_patterns` must cover the rules of every tenant. Another + deployment changes these values. +3. The Terraform state is in the private bucket that `backend "gcs"` in + `versions.tf` names. The state holds the CA key and the write token, so + the bucket must stay private. Make the bucket before the first + `terraform init`. +4. Log in with `gcloud auth application-default login`, then apply: ```sh cd deploy/gcp diff --git a/deploy/gcp/.gitignore b/deploy/gcp/.gitignore index f8d2ff9..bdb1beb 100644 --- a/deploy/gcp/.gitignore +++ b/deploy/gcp/.gitignore @@ -1,4 +1,3 @@ .terraform/ *.tfstate *.tfstate.* -roach.tfvars diff --git a/deploy/gcp/roach.tfvars.example b/deploy/gcp/roach.tfvars similarity index 59% rename from deploy/gcp/roach.tfvars.example rename to deploy/gcp/roach.tfvars index 84fc894..d7589a5 100644 --- a/deploy/gcp/roach.tfvars.example +++ b/deploy/gcp/roach.tfvars @@ -1,7 +1,10 @@ -# Copy to roach.tfvars, fill in, then: +# The production deployment of Roach for Sentry. Apply with: # terraform init && terraform apply -var-file=roach.tfvars -project = "my-gcp-project" -domain = "roach.example.com" +# This file holds no secrets. Terraform makes the CA key and the write token, +# and keeps them only in the state bucket (see versions.tf). +project = "roach-511216" +# Point an A record of this name at the ip_address output. +domain = "roach-proxy.sentry.dev" # The origins of Junior's evals (packages/junior-evals/src/recording-rules.ts). allow = [ @@ -18,4 +21,4 @@ value_patterns = [ "(?<=event_id=)[0-9a-f]{32}(?![0-9A-Za-z])", ] -# sentry_dsn = "https://...@o1.ingest.sentry.io/..." +# To send metrics to Sentry, set TF_VAR_sentry_dsn when you apply. diff --git a/deploy/gcp/versions.tf b/deploy/gcp/versions.tf index 573c32c..794b208 100644 --- a/deploy/gcp/versions.tf +++ b/deploy/gcp/versions.tf @@ -14,12 +14,12 @@ terraform { version = "~> 4.4" } } - # The state holds the CA key and the write token. Keep it in a private - # bucket, for example: - # backend "gcs" { - # bucket = "my-terraform-state" - # prefix = "roach" - # } + # The state holds the CA key and the write token. It is in a private + # bucket of the project. Another deployment changes the bucket here. + backend "gcs" { + bucket = "roach-511216-tfstate-dc-k4m9v2qx" + prefix = "roach" + } } provider "google" {