Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .craft.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
minVersion: "2.21.0"
changelog:
policy: auto
# Nothing reads a version from a file. The git tag is the version.
preReleaseCommand: ""
artifactProvider:
name: none
targets:
# The service image. The Image workflow pushes `:<sha>` for the release
# branch, and Craft copies it to `:<version>`.
- name: docker
source: ghcr.io/getsentry/roach
target: ghcr.io/getsentry/roach
# The action. Repositories use `getsentry/roach@v<major>`.
- name: github
tagPrefix: v
floatingTags:
- "v{major}"
3 changes: 2 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@ name: CI

on:
push:
branches: [main]
# Craft publishes a release only when the checks of its branch pass.
branches: [main, "release/**"]
pull_request:

permissions:
Expand Down
14 changes: 8 additions & 6 deletions .github/workflows/image.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,12 @@
name: Image

# Build the service image on each pull request. On main, also push it to
# ghcr.io/getsentry/roach, where deploy/gcp pulls it from.
# Build the service image on each pull request. On main and release
# branches, also push it to ghcr.io/getsentry/roach as `:<sha>`. On main,
# also push `:main`, which deploy/gcp pulls. A release copies `:<sha>` to
# `:<version>` (`.craft.yml`).
on:
push:
branches: [main]
branches: [main, "release/**"]
pull_request:

permissions:
Expand All @@ -27,7 +29,7 @@ jobs:
with:
persist-credentials: false
- uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1
- if: github.ref == 'refs/heads/main'
- if: github.event_name == 'push'
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
Expand All @@ -36,10 +38,10 @@ jobs:
- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
with:
context: .
push: ${{ github.ref == 'refs/heads/main' }}
push: ${{ github.event_name == 'push' }}
tags: |
ghcr.io/getsentry/roach:main
ghcr.io/getsentry/roach:${{ github.sha }}
${{ github.ref == 'refs/heads/main' && 'ghcr.io/getsentry/roach:main' || '' }}

terraform:
name: terraform
Expand Down
32 changes: 32 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: Release

# Craft makes a release branch, and a release manager accepts it in
# getsentry/publish. See "Release" in README.md.
on:
workflow_dispatch:
inputs:
version:
description: Version bump type
required: true
type: choice
default: minor
options:
- minor
- patch
- major
force:
description: Force release (bypass blockers)
required: false
type: boolean
default: false

jobs:
release:
# The Craft workflow pushes the release branch.
permissions:
contents: write
uses: getsentry/craft/.github/workflows/release.yml@3f2abdc5703191d12ef2cc013f792f1bd220f44d # v2
with:
version: ${{ inputs.version }}
force: ${{ inputs.force && 'true' || 'false' }}
secrets: inherit
24 changes: 12 additions & 12 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,16 +7,16 @@

## Commands

| Task | Command |
| ---------------- | ------------------------------------------------- |
| Test file | `pnpm exec vitest run tests/roach.test.ts` |
| Test case | `pnpm exec vitest run tests/roach.test.ts -t "…"` |
| Lint file | `pnpm exec oxlint --deny-warnings src/server.ts` |
| Format | `pnpm format` |
| Typecheck | `pnpm typecheck` |
| Deployed shape | `pnpm exec vitest run tests/deployed.test.ts` |
| Unused code/deps | `pnpm knip` |
| Everything (CI) | `pnpm check` |
| Task | Command |
| ---------------- | ----------------------------------------------------- |
| Test file | `pnpm exec vitest run tests/recording.test.ts` |
| Test case | `pnpm exec vitest run tests/recording.test.ts -t "…"` |
| Lint file | `pnpm exec oxlint --deny-warnings src/server.ts` |
| Format | `pnpm format` |
| Typecheck | `pnpm typecheck` |
| Deployed shape | `pnpm exec vitest run tests/deployed.test.ts` |
| Unused code/deps | `pnpm knip` |
| Everything (CI) | `pnpm check` |

## External References

Expand All @@ -29,14 +29,14 @@

## Key Conventions

- Use Node built-ins and the `openssl` command. The only runtime dependency is `@sentry/node`, and only `src/service.ts` imports it. The local proxy and the client must not load it.
- Use Node built-ins and the `openssl` command. The only runtime dependency is `@sentry/node`, and only `src/service.ts` imports it. The client and the action must not load it.
- `deploy/gcp/` is the production setup (Terraform). Change it in the same change when the service config (`RoachServiceConfig`) changes. CI runs `terraform validate` on it.
- Node runs `src/` as TypeScript with type stripping. Use only erasable syntax, and import local files with the `.ts` extension.
- Use functions and plain objects, not classes.
- Start each source file with a comment that says what the file owns. Give each export a short JSDoc.
- Update `README.md` in the same change when behavior, config, or the control API changes.
- Test through a real proxy and a local upstream server in `tests/`. Do not mock modules. Do not reach the internet.
- The proxy decrypts HTTPS. Never write a credential: every recording and miss file goes through `src/secrets.ts`.
- The proxy decrypts HTTPS. Never write a credential: every recording goes through `src/secrets.ts`.
- The upstream host always comes from `allow`, never from the client.
- Write docs in ASD-STE100 English: common words, active voice, short sentences.

Expand Down
Loading
Loading