mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-04 21:52:12 +00:00
feat: activate Sentry deployment environments
This commit is contained in:
parent
8e4a5ed4d8
commit
60aa23769a
7 changed files with 35 additions and 2 deletions
|
|
@ -17,7 +17,11 @@
|
||||||
# the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod.
|
# the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod.
|
||||||
|
|
||||||
# --- Sentry error and transaction monitoring ---
|
# --- Sentry error and transaction monitoring ---
|
||||||
# Leave the DSN blank to keep telemetry inactive. Set the environment per deployment.
|
# The DSN is public ingestion configuration, not a secret. Leave it blank locally
|
||||||
|
# to keep telemetry inactive. AWS deployments receive SENTRY_DSN and
|
||||||
|
# SENTRY_ENVIRONMENT as Elastic Beanstalk environment settings managed by
|
||||||
|
# Terraform: dev is labeled "development", staging "staging". Future production
|
||||||
|
# wiring will pass the production DSN through the same sentry_dsn module variable.
|
||||||
SENTRY_DSN=
|
SENTRY_DSN=
|
||||||
SENTRY_ENVIRONMENT=development
|
SENTRY_ENVIRONMENT=development
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -14,6 +14,13 @@ Secret metadata is managed, but secret values are never authored in Terraform
|
||||||
configuration. Elastic Beanstalk receives secret values through
|
configuration. Elastic Beanstalk receives secret values through
|
||||||
`environmentsecrets` ARN/key references.
|
`environmentsecrets` ARN/key references.
|
||||||
|
|
||||||
|
The Sentry DSN is public ingestion configuration, not a secret: each root passes
|
||||||
|
it through the required `sentry_dsn` module variable as the plain
|
||||||
|
`SENTRY_DSN` environment setting. `SENTRY_ENVIRONMENT` is `development` for the
|
||||||
|
dev root and the root environment name otherwise. Production has no Terraform
|
||||||
|
root yet; production Sentry wiring will reuse the same variable when one is
|
||||||
|
added.
|
||||||
|
|
||||||
## HCP credentials
|
## HCP credentials
|
||||||
|
|
||||||
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
|
Org-baseline CloudFormation owns the HCP Terraform plan/apply roles and their
|
||||||
|
|
|
||||||
|
|
@ -21,7 +21,12 @@ Secret values are not Terraform resources, variables, outputs, or managed EB
|
||||||
settings. Terraform manages the app-config secret shell and maps approved JSON
|
settings. Terraform manages the app-config secret shell and maps approved JSON
|
||||||
keys through `aws:elasticbeanstalk:application:environmentsecrets` using
|
keys through `aws:elasticbeanstalk:application:environmentsecrets` using
|
||||||
`secret-arn:json-key` references. Ordinary application environment settings are
|
`secret-arn:json-key` references. Ordinary application environment settings are
|
||||||
limited to non-secret ASP.NET and webhook configuration. The pinned .NET 8
|
limited to non-secret ASP.NET, webhook, and Sentry configuration. The Sentry
|
||||||
|
DSN is public ingestion configuration, delivered as the plain `SENTRY_DSN`
|
||||||
|
setting from the required `sentry_dsn` variable. `SENTRY_ENVIRONMENT` is
|
||||||
|
`development` for the dev root and the environment name (`staging`) otherwise.
|
||||||
|
No production root exists yet; production Sentry wiring will follow the same
|
||||||
|
variable when one is added. The pinned .NET 8
|
||||||
AL2023 platform 3.11.3 supports Secrets Manager JSON-key extraction.
|
AL2023 platform 3.11.3 supports Secrets Manager JSON-key extraction.
|
||||||
|
|
||||||
## Mandatory live secret migration
|
## Mandatory live secret migration
|
||||||
|
|
|
||||||
|
|
@ -61,6 +61,7 @@ module "environment" {
|
||||||
webhook_decrypt_policy_sid = "DecryptWebhookSecretViaSecretsManager"
|
webhook_decrypt_policy_sid = "DecryptWebhookSecretViaSecretsManager"
|
||||||
dynamo_reader_role_arn = "arn:aws:iam::328440206208:role/shoc-dynamo-reader"
|
dynamo_reader_role_arn = "arn:aws:iam::328440206208:role/shoc-dynamo-reader"
|
||||||
dynamo_policy_sid = "AssumeDynamoReaderInMain"
|
dynamo_policy_sid = "AssumeDynamoReaderInMain"
|
||||||
|
sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592"
|
||||||
github_repo = "Sea-Haven-Industries/shoc-backend"
|
github_repo = "Sea-Haven-Industries/shoc-backend"
|
||||||
github_environment = "dev"
|
github_environment = "dev"
|
||||||
github_deploy_role_name = "githubdeploy-shoc-backend-dev"
|
github_deploy_role_name = "githubdeploy-shoc-backend-dev"
|
||||||
|
|
|
||||||
|
|
@ -408,6 +408,16 @@ locals {
|
||||||
name = "WorkOrderWebhook__Region"
|
name = "WorkOrderWebhook__Region"
|
||||||
value = var.aws_region
|
value = var.aws_region
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
namespace = "aws:elasticbeanstalk:application:environment"
|
||||||
|
name = "SENTRY_DSN"
|
||||||
|
value = var.sentry_dsn
|
||||||
|
},
|
||||||
|
{
|
||||||
|
namespace = "aws:elasticbeanstalk:application:environment"
|
||||||
|
name = "SENTRY_ENVIRONMENT"
|
||||||
|
value = var.environment == "dev" ? "development" : var.environment
|
||||||
|
},
|
||||||
],
|
],
|
||||||
var.instance_security_group_id == null ? [] : [
|
var.instance_security_group_id == null ? [] : [
|
||||||
{
|
{
|
||||||
|
|
|
||||||
|
|
@ -71,6 +71,11 @@ variable "shared_certificate_arn" {
|
||||||
description = "Existing shared certificate for dev/staging"
|
description = "Existing shared certificate for dev/staging"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
variable "sentry_dsn" {
|
||||||
|
type = string
|
||||||
|
description = "Sentry DSN for error and transaction monitoring. The DSN is public ingestion configuration, not a secret: it is safe to expose and is delivered as a plain Elastic Beanstalk environment setting instead of Secrets Manager."
|
||||||
|
}
|
||||||
|
|
||||||
variable "runtime_role_name" {
|
variable "runtime_role_name" {
|
||||||
type = string
|
type = string
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -51,6 +51,7 @@ module "environment" {
|
||||||
"SendGrid__ApiKey",
|
"SendGrid__ApiKey",
|
||||||
]
|
]
|
||||||
webhook_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"
|
webhook_secret_arn = "arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB"
|
||||||
|
sentry_dsn = "https://15aef90a0e14b5b7c12ec5824b978979@o4511989453029376.ingest.de.sentry.io/4511990377152592"
|
||||||
github_repo = "Sea-Haven-Industries/shoc-backend"
|
github_repo = "Sea-Haven-Industries/shoc-backend"
|
||||||
github_environment = "staging"
|
github_environment = "staging"
|
||||||
github_deploy_role_name = "githubdeploy-shoc-backend-staging"
|
github_deploy_role_name = "githubdeploy-shoc-backend-staging"
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue