Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 15 additions & 4 deletions _integration-test/test_01_basics.py
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,17 @@
TIMEOUT_SECONDS = 120


def setup_sentry_trust_store():
subprocess.run(
[
"bash",
"-c",
"source install/_lib.sh && source install/dc-detect-version.sh && source install/setup-sentry-trust-store.sh",
],
check=True,
)


def poll_for_response(
request: str, client: httpx.Client, validator: Callable = None
) -> httpx.Response:
Expand Down Expand Up @@ -334,6 +345,7 @@ def test_custom_certificate_authorities():
# Create custom certs path and copy ca.crt
os.makedirs(custom_certs_path, exist_ok=True)
shutil.copyfile(ca_crt_path, f"{custom_certs_path}/test-custom-ca-roots.crt")
setup_sentry_trust_store()
# Generate server key and certificate

self_test_key_path = os.path.join(test_nginx_conf_path, "self.test.key")
Expand Down Expand Up @@ -503,6 +515,7 @@ def test_custom_certificate_authorities():
# Remove files
os.remove(f"{custom_certs_path}/test-custom-ca-roots.crt")
os.remove("sentry/test-custom-ca-roots.py")
setup_sentry_trust_store()

# Unset environment variable
if "COMPOSE_FILE" in os.environ:
Expand Down Expand Up @@ -680,9 +693,8 @@ def test_customizations():
"never",
"run",
"--no-deps",
"--entrypoint=/etc/sentry/entrypoint.sh",
"--entrypoint=python3",
"sentry-cleanup",
"python",
"-c",
"import os; assert os.path.exists('/created-by-enhance-image')",
],
Expand All @@ -705,9 +717,8 @@ def test_customizations():
"never",
"run",
"--no-deps",
"--entrypoint=/etc/sentry/entrypoint.sh",
"--entrypoint=python3",
"sentry-cleanup",
"python",
"-c",
"import ldap",
],
Expand Down
3 changes: 1 addition & 2 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,6 @@ x-sentry-defaults: &sentry_defaults
<<: *depends_on-default
symbolicator:
<<: *depends_on-default
entrypoint: "/etc/sentry/entrypoint.sh"
command: ["run", "web"]
environment:
PYTHONUSERBASE: "/data/custom-packages"
Expand Down Expand Up @@ -97,7 +96,7 @@ x-sentry-defaults: &sentry_defaults
- "sentry-data:/data"
- "./sentry:/etc/sentry"
- "./geoip:/geoip:ro"
- "./certificates:/usr/local/share/ca-certificates:ro"
- "./certificates/.generated/sentry/etc/ssl/certs:/etc/ssl/certs:ro"
- "./healthcheck:/healthcheck:ro"
x-snuba-defaults: &snuba_defaults
<<: [*restart_policy, *pull_policy]
Expand Down
1 change: 1 addition & 0 deletions install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ source install/check-memcached-backend.sh
source install/ensure-relay-credentials.sh
source install/generate-secret-key.sh
source install/build-docker-images.sh
source install/setup-sentry-trust-store.sh
source install/ensure-sentry-data-ownership.sh
source install/migrate-seaweedfs-kek.sh
source install/upgrade-postgres.sh
Expand Down
5 changes: 3 additions & 2 deletions install/setup-custom-ca-certificate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -53,8 +53,6 @@ if [[ "${SETUP_CUSTOM_CA_CERTIFICATE:-}" == "1" ]]; then
done
echo ""

# Wipe and recreate the generated directory for idempotency.
rm -rf "$GENERATED_DIR"
mkdir -p "$GENERATED_DIR"

# Pairs of service nickname and the env var that holds the image reference.
Expand Down Expand Up @@ -83,6 +81,9 @@ if [[ "${SETUP_CUSTOM_CA_CERTIFICATE:-}" == "1" ]]; then
fi

cert_out_dir="${GENERATED_DIR}/${nickname}/etc/ssl/certs"
# Wipe and recreate this service's directory for idempotency. Other
# directories in GENERATED_DIR (e.g. sentry's) belong to other steps.
rm -rf "${GENERATED_DIR:?}/${nickname}"
mkdir -p "$cert_out_dir"

echo "Generating trust store for ${nickname} (${image}) ..."
Expand Down
30 changes: 30 additions & 0 deletions install/setup-sentry-trust-store.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
echo "${_group}Setting up the CA trust store for Sentry ..."

# Sentry containers mount this directory read-only at /etc/ssl/certs. It holds
# the image's own CA certificates plus every certificates/*.crt, so changes to
# custom CAs take effect on the next ./install.sh.
trust_store="certificates/.generated/sentry/etc/ssl/certs"
rm -rf "$trust_store"
mkdir -p "$trust_store"

container=$($CONTAINER_ENGINE create sentry-self-hosted-local)
$CONTAINER_ENGINE cp "$container:/etc/ssl/certs/." "$trust_store/"
$CONTAINER_ENGINE rm "$container" >/dev/null

for cert in certificates/*.crt; do
[[ -f "$cert" ]] || continue
name=$(basename "$cert" .crt)
cp "$cert" "$trust_store/$name.pem"
cat "$cert" >>"$trust_store/ca-certificates.crt"
echo >>"$trust_store/ca-certificates.crt"
# Hash link for libraries that look certificates up by directory.
if command -v openssl &>/dev/null; then
hash=$(openssl x509 -hash -noout -in "$cert")
n=0
while [[ -e "$trust_store/$hash.$n" || -L "$trust_store/$hash.$n" ]]; do n=$((n + 1)); done
ln -s "$name.pem" "$trust_store/$hash.$n"
fi
echo "Added $cert"
done

echo "${_endgroup}"
5 changes: 0 additions & 5 deletions sentry/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,4 @@ RUN if [ -s /usr/src/sentry/requirements.txt ]; then \
pip install -r /usr/src/sentry/requirements.txt; \
fi

# Let the non-root sentry user run update-ca-certificates (sentry/entrypoint.sh)
# for custom CAs mounted from ./certificates. It only needs to create symlinks
# and replace the bundle in this directory.
RUN chown sentry:sentry /etc/ssl/certs

USER sentry
12 changes: 0 additions & 12 deletions sentry/entrypoint.sh

This file was deleted.

Loading