mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 06:03:12 +00:00
feat: activate Sentry deployment environments
This commit is contained in:
parent
8e4a5ed4d8
commit
60aa23769a
7 changed files with 35 additions and 2 deletions
|
|
@ -17,7 +17,11 @@
|
|||
# the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod.
|
||||
|
||||
# --- Sentry error and transaction monitoring ---
|
||||
# Leave the DSN blank to keep telemetry inactive. Set the environment per deployment.
|
||||
# The DSN is public ingestion configuration, not a secret. Leave it blank locally
|
||||
# to keep telemetry inactive. AWS deployments receive SENTRY_DSN and
|
||||
# SENTRY_ENVIRONMENT as Elastic Beanstalk environment settings managed by
|
||||
# Terraform: dev is labeled "development", staging "staging". Future production
|
||||
# wiring will pass the production DSN through the same sentry_dsn module variable.
|
||||
SENTRY_DSN=
|
||||
SENTRY_ENVIRONMENT=development
|
||||
|
||||
|
|
|
|||
|
|
@ -14,6 +14,13 @@ Secret metadata is managed, but secret values are never authored in Terraform
|
|||
configuration. Elastic Beanstalk receives secret values through
|
||||
`environmentsecrets` ARN/key references.
|
||||
|
||||
The Sentry DSN is public ingestion configuration, not a secret: each root passes
|
||||
it through the required `sentry_dsn` module variable as the plain
|
||||
`SENTRY_DSN` environment setting. `SENTRY_ENVIRONMENT` is `development` for the
|
||||
dev root and the root environment name otherwise. Production has no Terraform
|
||||
root yet; production Sentry wiring will reuse the same variable when one is
|
||||
added.
|
||||
|
||||
## HCP credentials
|
||||
|
||||
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
|
||||
|
|
|
|||
|
|
@ -21,7 +21,12 @@ Secret values are not Terraform resources, variables, outputs, or managed EB
|
|||
settings. Terraform manages the app-config secret shell and maps approved JSON
|
||||
keys through `aws:elasticbeanstalk:application:environmentsecrets` using
|
||||
`secret-arn:json-key` references. Ordinary application environment settings are
|
||||
limited to non-secret ASP.NET and webhook configuration. The pinned .NET 8
|
||||
limited to non-secret ASP.NET, webhook, and Sentry configuration. The Sentry
|
||||
DSN is public ingestion configuration, delivered as the plain `SENTRY_DSN`
|
||||
setting from the required `sentry_dsn` variable. `SENTRY_ENVIRONMENT` is
|
||||
`development` for the dev root and the environment name (`staging`) otherwise.
|
||||
No production root exists yet; production Sentry wiring will follow the same
|
||||
variable when one is added. The pinned .NET 8
|
||||
AL2023 platform 3.11.3 supports Secrets Manager JSON-key extraction.
|
||||
|
||||
## Mandatory live secret migration
|
||||
|
|
|
|||
|
|
@ -61,6 +61,7 @@ module "environment" {
|
|||
webhook_decrypt_policy_sid = "DecryptWebhookSecretViaSecretsManager"
|
||||
dynamo_reader_role_arn = "arn:aws:iam::328440206208:role/shoc-dynamo-reader"
|
||||
dynamo_policy_sid = "AssumeDynamoReaderInMain"
|
||||
sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592"
|
||||
github_repo = "Sea-Haven-Industries/shoc-backend"
|
||||
github_environment = "dev"
|
||||
github_deploy_role_name = "githubdeploy-shoc-backend-dev"
|
||||
|
|
|
|||
|
|
@ -408,6 +408,16 @@ locals {
|
|||
name = "WorkOrderWebhook__Region"
|
||||
value = var.aws_region
|
||||
},
|
||||
{
|
||||
namespace = "aws:elasticbeanstalk:application:environment"
|
||||
name = "SENTRY_DSN"
|
||||
value = var.sentry_dsn
|
||||
},
|
||||
{
|
||||
namespace = "aws:elasticbeanstalk:application:environment"
|
||||
name = "SENTRY_ENVIRONMENT"
|
||||
value = var.environment == "dev" ? "development" : var.environment
|
||||
},
|
||||
],
|
||||
var.instance_security_group_id == null ? [] : [
|
||||
{
|
||||
|
|
|
|||
|
|
@ -71,6 +71,11 @@ variable "shared_certificate_arn" {
|
|||
description = "Existing shared certificate for dev/staging"
|
||||
}
|
||||
|
||||
variable "sentry_dsn" {
|
||||
type = string
|
||||
description = "Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager."
|
||||
}
|
||||
|
||||
variable "runtime_role_name" {
|
||||
type = string
|
||||
}
|
||||
|
|
|
|||
|
|
@ -51,6 +51,7 @@ module "environment" {
|
|||
"SendGrid__ApiKey",
|
||||
]
|
||||
webhook_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"
|
||||
sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592"
|
||||
github_repo = "Sea-Haven-Industries/shoc-backend"
|
||||
github_environment = "staging"
|
||||
github_deploy_role_name = "githubdeploy-shoc-backend-staging"
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue