Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 9 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -264,11 +264,15 @@ The `Image` workflow builds the image on each pull request and pushes it on

1. Make the package `ghcr.io/getsentry/roach` public once, after the first
push to `main`, so the VM can pull it without credentials.
2. Copy `deploy/gcp/roach.tfvars.example` to `roach.tfvars` and fill it in.
`allow` and `value_patterns` must cover the rules of every tenant.
3. Keep the Terraform state in a private bucket. It holds the CA key and the
write token. See the `backend "gcs"` comment in `versions.tf`.
4. Apply:
2. `deploy/gcp/roach.tfvars` has the values of the Sentry deployment: the
GCP project `roach-511216`, the domain, `allow`, and `value_patterns`.
`allow` and `value_patterns` must cover the rules of every tenant. Another
deployment changes these values.
3. The Terraform state is in the private bucket that `backend "gcs"` in
`versions.tf` names. The state holds the CA key and the write token, so
the bucket must stay private. Make the bucket before the first
`terraform init`.
4. Log in with `gcloud auth application-default login`, then apply:

```sh
cd deploy/gcp
Expand Down
1 change: 0 additions & 1 deletion deploy/gcp/.gitignore
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@
.terraform/
*.tfstate
*.tfstate.*
roach.tfvars
11 changes: 7 additions & 4 deletions deploy/gcp/roach.tfvars.example → deploy/gcp/roach.tfvars
Original file line number Diff line number Diff line change
@@ -1,7 +1,10 @@
# Copy to roach.tfvars, fill in, then:
# The production deployment of Roach for Sentry. Apply with:
# terraform init && terraform apply -var-file=roach.tfvars
project = "my-gcp-project"
domain = "roach.example.com"
# This file holds no secrets. Terraform makes the CA key and the write token,
# and keeps them only in the state bucket (see versions.tf).
project = "roach-511216"
# Point an A record of this name at the ip_address output.
domain = "roach-proxy.sentry.dev"

# The origins of Junior's evals (packages/junior-evals/src/recording-rules.ts).
allow = [
Expand All @@ -18,4 +21,4 @@ value_patterns = [
"(?<=event_id=)[0-9a-f]{32}(?![0-9A-Za-z])",
]

# sentry_dsn = "https://...@o1.ingest.sentry.io/..."
# To send metrics to Sentry, set TF_VAR_sentry_dsn when you apply.
12 changes: 6 additions & 6 deletions deploy/gcp/versions.tf
Original file line number Diff line number Diff line change
Expand Up @@ -14,12 +14,12 @@ terraform {
version = "~> 4.4"
}
}
# The state holds the CA key and the write token. Keep it in a private
# bucket, for example:
# backend "gcs" {
# bucket = "my-terraform-state"
# prefix = "roach"
# }
# The state holds the CA key and the write token. It is in a private
# bucket of the project. Another deployment changes the bucket here.
backend "gcs" {
bucket = "roach-511216-tfstate-dc-k4m9v2qx"
prefix = "roach"
}
}

provider "google" {
Expand Down
Loading