feat: activate Sentry deployment environments

This commit is contained in:
Alexandre Brandizzi 2026-09-03 15:10:01 -03:00
parent 8e4a5ed4d8
commit 60aa23769a
7 changed files with 35 additions and 2 deletions

View file

@ -17,7 +17,11 @@
# the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod.
# --- Sentry error and transaction monitoring ---
# Leave the DSN blank to keep telemetry inactive. Set the environment per deployment.
# The DSN is public ingestion configuration, not a secret. Leave it blank locally
# to keep telemetry inactive. AWS deployments receive SENTRY_DSN and
# SENTRY_ENVIRONMENT as Elastic Beanstalk environment settings managed by
# Terraform: dev is labeled "development", staging "staging". Future production
# wiring will pass the production DSN through the same sentry_dsn module variable.
SENTRY_DSN=
SENTRY_ENVIRONMENT=development

View file

@ -14,6 +14,13 @@ Secret metadata is managed, but secret values are never authored in Terraform
configuration. Elastic Beanstalk receives secret values through
`environmentsecrets` ARN/key references.
The Sentry DSN is public ingestion configuration, not a secret: each root passes
it through the required `sentry_dsn` module variable as the plain
`SENTRY_DSN` environment setting. `SENTRY_ENVIRONMENT` is `development` for the
dev root and the root environment name otherwise. Production has no Terraform
root yet; production Sentry wiring will reuse the same variable when one is
added.
## HCP credentials
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their

View file

@ -21,7 +21,12 @@ Secret values are not Terraform resources, variables, outputs, or managed EB
settings. Terraform manages the app-config secret shell and maps approved JSON
keys through `aws:elasticbeanstalk:application:environmentsecrets` using
`secret-arn:json-key` references. Ordinary application environment settings are
limited to non-secret ASP.NET and webhook configuration. The pinned .NET 8
limited to non-secret ASP.NET, webhook, and Sentry configuration. The Sentry
DSN is public ingestion configuration, delivered as the plain `SENTRY_DSN`
setting from the required `sentry_dsn` variable. `SENTRY_ENVIRONMENT` is
`development` for the dev root and the environment name (`staging`) otherwise.
No production root exists yet; production Sentry wiring will follow the same
variable when one is added. The pinned .NET 8
AL2023 platform 3.11.3 supports Secrets Manager JSON-key extraction.
## Mandatory live secret migration

View file

@ -61,6 +61,7 @@ module "environment" {
webhook_decrypt_policy_sid = "DecryptWebhookSecretViaSecretsManager"
dynamo_reader_role_arn = "arn:aws:iam::328440206208:role/shoc-dynamo-reader"
dynamo_policy_sid = "AssumeDynamoReaderInMain"
sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592"
github_repo = "Sea-Haven-Industries/shoc-backend"
github_environment = "dev"
github_deploy_role_name = "githubdeploy-shoc-backend-dev"

View file

@ -408,6 +408,16 @@ locals {
name = "WorkOrderWebhook__Region"
value = var.aws_region
},
{
namespace = "aws:elasticbeanstalk:application:environment"
name = "SENTRY_DSN"
value = var.sentry_dsn
},
{
namespace = "aws:elasticbeanstalk:application:environment"
name = "SENTRY_ENVIRONMENT"
value = var.environment == "dev" ? "development" : var.environment
},
],
var.instance_security_group_id == null ? [] : [
{

View file

@ -71,6 +71,11 @@ variable "shared_certificate_arn" {
description = "Existing shared certificate for dev/staging"
}
variable "sentry_dsn" {
type = string
description = "Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager."
}
variable "runtime_role_name" {
type = string
}

View file

@ -51,6 +51,7 @@ module "environment" {
"SendGrid__ApiKey",
]
webhook_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"
sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592"
github_repo = "Sea-Haven-Industries/shoc-backend"
github_environment = "staging"
github_deploy_role_name = "githubdeploy-shoc-backend-staging"