Skip to content

ref(certificates): Build the Sentry CA trust store at install time - #4545

Draft
oioki wants to merge 1 commit into
masterfrom
alextarasov/sentry-ca-trust-store-at-install
Draft

oioki wants to merge 1 commit into
masterfrom
alextarasov/sentry-ca-trust-store-at-install

Conversation

@oioki

@oioki oioki commented Oct 1, 2026

Copy link
Copy Markdown
Member

Replace the runtime custom-CA handling for the sentry services with an install-time trust store. install/setup-sentry-trust-store.sh copies the sentry image's own /etc/ssl/certs and adds every certificates/*.crt (appended to the bundle, plus the file and its hash link), and the sentry services mount the result read-only at /etc/ssl/certs. The entrypoint: /etc/sentry/entrypoint.sh override (bash + update-ca-certificates) and the /etc/ssl/certs chown go away, so sentry services run the image's own entrypoint, including on images without a shell.

Behavior changes worth a look:

  • After changing files in ./certificates, re-run ./install.sh (previously a restart was enough).
  • Only top-level certificates/*.crt are used, like SETUP_CUSTOM_CA_CERTIFICATE; update-ca-certificates also picked up subdirectories.
  • The store exists only after ./install.sh; starting the stack without it mounts an empty /etc/ssl/certs.

setup-custom-ca-certificate.sh used to rm -rf certificates/.generated, which would now delete the sentry store; it only wipes the per-service directories it generates.

Overlaps with #4543 (moves the chown into customize_image.py) — whichever lands second drops it.

Part of making self-hosted run on the distroless sentry image by changing only SENTRY_IMAGE.

Instead of running update-ca-certificates in a bash entrypoint at every container start, install.sh copies the sentry image's /etc/ssl/certs, adds certificates/*.crt (bundle, file and hash link), and the sentry services mount the result read-only at /etc/ssl/certs. This removes the entrypoint override and the /etc/ssl/certs chown, so sentry services use the image's own entrypoint and also work on images without a shell. setup-custom-ca-certificate.sh now only wipes the directories it generates, so it no longer deletes the sentry trust store.
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Coverage Results 📊

✅ 22 passed | Total: 22 | Pass Rate: 100% | Execution Time: 10m 37s

All tests are passing successfully.

✅ Patch coverage is 100.00% (4 of 4 changed executable lines covered; target 50%).
Project statement coverage is 95.59%.

Changed files with executable lines (1)
File Patch coverage Changed executable lines
_integration-test/test_01_basics.py 100.00% 4/4 covered

Generated by Coverage Action

@BYK BYK left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

My only worry is this being a potentially breaking change for existing users.

@aldy505

aldy505 commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

My only worry is this being a potentially breaking change for existing users.

True.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

3 participants