diff --git a/.env.example b/.env.example index 4a6f6d4..885a0c6 100644 --- a/.env.example +++ b/.env.example @@ -17,7 +17,11 @@ # the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod. # --- Sentry error and transaction monitoring --- -# Leave the DSN blank to keep telemetry inactive. Set the environment per deployment. +# The DSN is public ingestion configuration, not a secret. Leave it blank locally +# to keep telemetry inactive. AWS deployments receive SENTRY_DSN and +# SENTRY_ENVIRONMENT as Elastic Beanstalk environment settings managed by +# Terraform: dev is labeled "development", staging "staging". Future production +# wiring will pass the production DSN through the same sentry_dsn module variable. SENTRY_DSN= SENTRY_ENVIRONMENT=development diff --git a/terraform/README.md b/terraform/README.md index b982fa9..9821ba7 100644 --- a/terraform/README.md +++ b/terraform/README.md @@ -14,6 +14,13 @@ Secret metadata is managed, but secret values are never authored in Terraform configuration. Elastic Beanstalk receives secret values through `environmentsecrets` ARN/key references. +The Sentry DSN is public ingestion configuration, not a secret: each root passes +it through the required `sentry_dsn` module variable as the plain +`SENTRY_DSN` environment setting. `SENTRY_ENVIRONMENT` is `development` for the +dev root and the root environment name otherwise. Production has no Terraform +root yet; production Sentry wiring will reuse the same variable when one is +added. + ## HCP credentials Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their diff --git a/terraform/live/README.md b/terraform/live/README.md index 0d79f16..fe486cd 100644 --- a/terraform/live/README.md +++ b/terraform/live/README.md @@ -21,7 +21,12 @@ Secret values are not Terraform resources, variables, outputs, or managed EB settings. Terraform manages the app-config secret shell and maps approved JSON keys through `aws:elasticbeanstalk:application:environmentsecrets` using `secret-arn:json-key` references. Ordinary application environment settings are -limited to non-secret ASP.NET and webhook configuration. The pinned .NET 8 +limited to non-secret ASP.NET, webhook, and Sentry configuration. The Sentry +DSN is public ingestion configuration, delivered as the plain `SENTRY_DSN` +setting from the required `sentry_dsn` variable. `SENTRY_ENVIRONMENT` is +`development` for the dev root and the environment name (`staging`) otherwise. +No production root exists yet; production Sentry wiring will follow the same +variable when one is added. The pinned .NET 8 AL2023 platform 3.11.3 supports Secrets Manager JSON-key extraction. ## Mandatory live secret migration diff --git a/terraform/live/dev/main.tf b/terraform/live/dev/main.tf index c2ce71d..8d1ce47 100644 --- a/terraform/live/dev/main.tf +++ b/terraform/live/dev/main.tf @@ -61,6 +61,7 @@ module "environment" { webhook_decrypt_policy_sid = "DecryptWebhookSecretViaSecretsManager" dynamo_reader_role_arn = "arn:aws:iam::328440206208:role/shoc-dynamo-reader" dynamo_policy_sid = "AssumeDynamoReaderInMain" + sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592" github_repo = "Sea-Haven-Industries/shoc-backend" github_environment = "dev" github_deploy_role_name = "githubdeploy-shoc-backend-dev" diff --git a/terraform/live/modules/environment-owned/main.tf b/terraform/live/modules/environment-owned/main.tf index d31dc97..b01a830 100644 --- a/terraform/live/modules/environment-owned/main.tf +++ b/terraform/live/modules/environment-owned/main.tf @@ -408,6 +408,16 @@ locals { name = "WorkOrderWebhook__Region" value = var.aws_region }, + { + namespace = "aws:elasticbeanstalk:application:environment" + name = "SENTRY_DSN" + value = var.sentry_dsn + }, + { + namespace = "aws:elasticbeanstalk:application:environment" + name = "SENTRY_ENVIRONMENT" + value = var.environment == "dev" ? "development" : var.environment + }, ], var.instance_security_group_id == null ? [] : [ { diff --git a/terraform/live/modules/environment-owned/variables.tf b/terraform/live/modules/environment-owned/variables.tf index e3dfde6..8732d31 100644 --- a/terraform/live/modules/environment-owned/variables.tf +++ b/terraform/live/modules/environment-owned/variables.tf @@ -71,6 +71,11 @@ variable "shared_certificate_arn" { description = "Existing shared certificate for dev/staging" } +variable "sentry_dsn" { + type = string + description = "Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager." +} + variable "runtime_role_name" { type = string } diff --git a/terraform/live/staging/main.tf b/terraform/live/staging/main.tf index baa5f4b..7e875d3 100644 --- a/terraform/live/staging/main.tf +++ b/terraform/live/staging/main.tf @@ -51,6 +51,7 @@ module "environment" { "SendGrid__ApiKey", ] webhook_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB" + sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592" github_repo = "Sea-Haven-Industries/shoc-backend" github_environment = "staging" github_deploy_role_name = "githubdeploy-shoc-backend-staging"