Skip to content

Sentry DSN Usage Simplification #5004

Description

@feoh

Description/Context

We currently have cargo-culted, hard-coded Sentry DSNs scattered across several of our projects. These should instead be regularly-named, defined outputs from the Sentry Pulumi stack, rather than values that get copy-pasted and stored as secrets in Vault.

Standardizing DSN provisioning as Pulumi stack outputs will let us delete the corresponding hard-coded DSN secrets from Vault, reducing secret sprawl and the risk of stale/incorrect DSNs being used.

Plan/Design

  • Audit projects for hard-coded Sentry DSNs and identify which Sentry projects/stacks they correspond to.
  • Define a consistent naming convention for Sentry DSN outputs in the Sentry Pulumi stack.
  • Update the Sentry Pulumi stack to expose DSNs as stack outputs using that convention.
  • Migrate consuming projects to read the DSN from the Pulumi stack output instead of a hard-coded value or ad hoc Vault secret.
  • Remove the now-redundant DSN secrets from Vault.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions