Description/Context
We currently have cargo-culted, hard-coded Sentry DSNs scattered across several of our projects. These should instead be regularly-named, defined outputs from the Sentry Pulumi stack, rather than values that get copy-pasted and stored as secrets in Vault.
Standardizing DSN provisioning as Pulumi stack outputs will let us delete the corresponding hard-coded DSN secrets from Vault, reducing secret sprawl and the risk of stale/incorrect DSNs being used.
Plan/Design
- Audit projects for hard-coded Sentry DSNs and identify which Sentry projects/stacks they correspond to.
- Define a consistent naming convention for Sentry DSN outputs in the Sentry Pulumi stack.
- Update the Sentry Pulumi stack to expose DSNs as stack outputs using that convention.
- Migrate consuming projects to read the DSN from the Pulumi stack output instead of a hard-coded value or ad hoc Vault secret.
- Remove the now-redundant DSN secrets from Vault.
Description/Context
We currently have cargo-culted, hard-coded Sentry DSNs scattered across several of our projects. These should instead be regularly-named, defined outputs from the Sentry Pulumi stack, rather than values that get copy-pasted and stored as secrets in Vault.
Standardizing DSN provisioning as Pulumi stack outputs will let us delete the corresponding hard-coded DSN secrets from Vault, reducing secret sprawl and the risk of stale/incorrect DSNs being used.
Plan/Design