Conversation
Instead of running update-ca-certificates in a bash entrypoint at every container start, install.sh copies the sentry image's /etc/ssl/certs, adds certificates/*.crt (bundle, file and hash link), and the sentry services mount the result read-only at /etc/ssl/certs. This removes the entrypoint override and the /etc/ssl/certs chown, so sentry services use the image's own entrypoint and also work on images without a shell. setup-custom-ca-certificate.sh now only wipes the directories it generates, so it no longer deletes the sentry trust store.
Coverage Results 📊✅ 22 passed | Total: 22 | Pass Rate: 100% | Execution Time: 10m 37s All tests are passing successfully. ✅ Patch coverage is 100.00% (4 of 4 changed executable lines covered; target 50%). Changed files with executable lines (1)
Generated by Coverage Action |
BYK
approved these changes
Oct 1, 2026
BYK
left a comment
Member
There was a problem hiding this comment.
My only worry is this being a potentially breaking change for existing users.
Collaborator
True. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replace the runtime custom-CA handling for the sentry services with an install-time trust store.
install/setup-sentry-trust-store.shcopies the sentry image's own/etc/ssl/certsand adds everycertificates/*.crt(appended to the bundle, plus the file and its hash link), and the sentry services mount the result read-only at/etc/ssl/certs. Theentrypoint: /etc/sentry/entrypoint.shoverride (bash +update-ca-certificates) and the/etc/ssl/certschown go away, so sentry services run the image's own entrypoint, including on images without a shell.Behavior changes worth a look:
./certificates, re-run./install.sh(previously a restart was enough).certificates/*.crtare used, likeSETUP_CUSTOM_CA_CERTIFICATE;update-ca-certificatesalso picked up subdirectories../install.sh; starting the stack without it mounts an empty/etc/ssl/certs.setup-custom-ca-certificate.shused torm -rf certificates/.generated, which would now delete the sentry store; it only wipes the per-service directories it generates.Overlaps with #4543 (moves the chown into
customize_image.py) — whichever lands second drops it.Part of making self-hosted run on the distroless sentry image by changing only
SENTRY_IMAGE.