mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 04:13:12 +00:00
Initialize the SDK on gunicorn and the SQS worker with afterhours-style scrubbing. Store the DSN in SSM and inject only the parameter name onto the live task.
39 lines
1.3 KiB
Python
39 lines
1.3 KiB
Python
"""Sentry DSN is an SSM SecureString; the task receives the parameter name."""
|
|
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
TERRAFORM = ROOT / "terraform"
|
|
|
|
|
|
def _read(name: str) -> str:
|
|
return (TERRAFORM / name).read_text()
|
|
|
|
|
|
def test_sentry_dsn_is_secure_string_stub():
|
|
ssm_tf = _read("ssm.tf")
|
|
assert 'resource "aws_ssm_parameter" "sentry_dsn"' in ssm_tf
|
|
assert 'name = "${local.ssm_prefix}/sentry-dsn"' in ssm_tf
|
|
assert 'type = "SecureString"' in ssm_tf
|
|
assert 'value = "unset"' in ssm_tf
|
|
assert "ignore_changes = [value]" in ssm_tf
|
|
assert 'data "aws_ssm_parameter" "sentry_dsn_value"' not in ssm_tf
|
|
|
|
|
|
def test_ecs_task_receives_sentry_dsn_parameter_name():
|
|
ecs_tf = _read("ecs.tf")
|
|
assert ecs_tf.count("SENTRY_DSN_PARAM") == 1
|
|
assert "aws_ssm_parameter.sentry_dsn.name" in ecs_tf
|
|
assert "SENTRY_DSN " not in ecs_tf
|
|
|
|
|
|
def test_terraform_does_not_embed_a_sentry_dsn():
|
|
for path in TERRAFORM.glob("*.tf"):
|
|
text = path.read_text()
|
|
assert "ingest.sentry.io" not in text
|
|
assert "SENTRY_DSN =" not in text
|
|
|
|
|
|
def test_deploy_api_injects_sentry_dsn_param():
|
|
workflow = (ROOT / ".github/workflows/deploy-api.yaml").read_text()
|
|
assert 'env["SENTRY_DSN_PARAM"] = "/meal-order-manager/sentry-dsn"' in workflow
|