build(self-hosted): Run sentry image as non-root and drop gosu - #125848
Merged
Merged
Conversation
Set USER 999:999 in the image and remove gosu along with the entrypoint's root branch that chowned /data and stepped down to the sentry user. /data is now created and owned by sentry at build time, so fresh named volumes come up with the right ownership. This mirrors getsentry/snuba#2777. Production already runs getsentry as uid 999 via runAsUser. Removes a root-only code path and the gosu binary ahead of moving the image to a distroless base.
vgrozdanic
approved these changes
Sep 29, 2026
aldy505
approved these changes
Sep 29, 2026
oioki
added a commit
to getsentry/self-hosted
that referenced
this pull request
Sep 29, 2026
* build(sentry): Prepare for a non-root sentry image The upstream sentry image is moving to run as the non-root sentry user and will drop gosu (getsentry/sentry#125848). Make self-hosted work with both the current root image and the upcoming non-root one: - Run build customizations (nodestore-s3, enhance-image.sh, requirements.txt) as root, then switch to the sentry user. - Trust custom CAs without update-ca-certificates, which needs root: build a combined bundle in /tmp and point the TLS env vars at it. - Fix sentry-data ownership once during install instead of at every container start. - Install gosu in the cleanup image instead of relying on the sentry image. * fix(sentry): Keep update-ca-certificates for custom CAs Replace the /tmp CA bundle with making /etc/ssl/certs writable by the sentry user, so the existing entrypoint can run update-ca-certificates unchanged. The bundle approach left the standard bundle path and the hashed certs directory without the custom CAs, and did not apply to docker compose exec, so clients that don't read the TLS env vars (e.g. librdkafka, capath lookups, paths set in sentry.conf.py) would stop trusting them. * fix(install): Chown sentry-data bottom-up so interrupted runs resume Chown /data last, so if the walk is interrupted the ownership guard still triggers a full walk on the next install. * fix(install): Fail sentry-data ownership step on unreadable directories os.walk skips directories it cannot list by default, which would leave them root-owned without any error. Raise instead so install.sh stops, like the old entrypoint's find under set -e.
Member
Author
|
After this, the container starts as non-root Still possible to exec as root: Image size, before and after: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Run the self-hosted
sentryimage as thesentryuser (uid 999) instead of starting as root and stepping down withgosu, like getsentry/snuba#2777./datais created with the right owner at build time, so the entrypoint no longer needs tochownit. Production already runs getsentry as 999 viarunAsUser.Prep for moving the image to a distroless base.
Depends on getsentry/self-hosted#4535 being on self-hosted
master. Self-hosted master and relocation validation use:nightly, so they'd pick this up within a day of merging.