Skip to content

[DO NOT MERGE] build(sentry): Build sentry-self-hosted-local without a shell - #4543

Draft
oioki wants to merge 1 commit into
masterfrom
alextarasov/sentry-dockerfile-exec-form
Draft

oioki wants to merge 1 commit into
masterfrom
alextarasov/sentry-dockerfile-exec-form

Conversation

@oioki

@oioki oioki commented Oct 1, 2026

Copy link
Copy Markdown
Member

Do not merge: up for a closer look.

sentry/Dockerfile now uses only exec-form RUNs, so sentry-self-hosted-local also builds on a sentry image without a shell, such as ghcr.io/getsentry/sentry:nightly-distroless. The enhance-image.sh, requirements.txt and /etc/ssl/certs steps move into sentry/customize_image.py, unchanged in behavior on the regular image.

On an image without a shell, requirements.txt still works, but a non-empty enhance-image.sh fails the build with a clear message, since it's a shell script (and usually runs apt-get).

customize_image.py lives in ./sentry because that's the build context, so it also shows up in the /etc/sentry mount at runtime.

Part of making self-hosted run on the distroless sentry image by changing only SENTRY_IMAGE.

Use only exec-form RUNs in sentry/Dockerfile and move the enhance-image.sh, requirements.txt and /etc/ssl/certs steps into customize_image.py, so the image also builds on a sentry image without a shell (the distroless variant). enhance-image.sh still runs on images that have a shell and fails the build with a clear message on those that don't.
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Coverage Results 📊

✅ 22 passed | Total: 22 | Pass Rate: 100% | Execution Time: 10m 48s

All tests are passing successfully.

✅ Patch coverage is 100.00% (no changed executable lines found; target 50%).
Project statement coverage is 95.54% (unchanged from base (86b6d79) to head (f02914c)).

Coverage diff
@@            Coverage Diff             @@
##        master     #4543       +/-##
==========================================
  Coverage    95.54%    95.54%        —%
==========================================
  Files            5         5         —
  Tracked lines       336       336         —
  Branches         0         0         —
==========================================
  Hits           321       321         —
  Misses          15        15         —
  Partials         0         0         —

Generated by Coverage Action

@BYK

BYK commented Oct 1, 2026

Copy link
Copy Markdown
Member

On an image without a shell, requirements.txt still works, but a non-empty enhance-image.sh fails the build with a clear message, since it's a shell script (and usually runs apt-get).

Yeah this clearly is a breaking change and I'd say we need community feedback before making a move.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

2 participants