Skip to content

build(self-hosted): Run sentry image as non-root and drop gosu - #125848

Merged
oioki merged 2 commits into
masterfrom
build/self-hosted-run-as-non-root
Sep 29, 2026
Merged

oioki merged 2 commits into
masterfrom
build/self-hosted-run-as-non-root

Conversation

@oioki

@oioki oioki commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Run the self-hosted sentry image as the sentry user (uid 999) instead of starting as root and stepping down with gosu, like getsentry/snuba#2777. /data is created with the right owner at build time, so the entrypoint no longer needs to chown it. Production already runs getsentry as 999 via runAsUser.

Prep for moving the image to a distroless base.

Depends on getsentry/self-hosted#4535 being on self-hosted master. Self-hosted master and relocation validation use :nightly, so they'd pick this up within a day of merging.

Set USER 999:999 in the image and remove gosu along with the entrypoint's root branch that chowned /data and stepped down to the sentry user. /data is now created and owned by sentry at build time, so fresh named volumes come up with the right ownership. This mirrors getsentry/snuba#2777. Production already runs getsentry as uid 999 via runAsUser.

Removes a root-only code path and the gosu binary ahead of moving the image to a distroless base.
@github-actions github-actions Bot added the Scope: Backend Automatically applied to PRs that change backend components label Sep 29, 2026
@oioki
oioki marked this pull request as ready for review September 29, 2026 09:11
@oioki
oioki requested a review from a team as a code owner September 29, 2026 09:11
Comment thread self-hosted/docker-entrypoint.sh
oioki added a commit to getsentry/self-hosted that referenced this pull request Sep 29, 2026
* build(sentry): Prepare for a non-root sentry image

The upstream sentry image is moving to run as the non-root sentry user and will drop gosu (getsentry/sentry#125848). Make self-hosted work with both the current root image and the upcoming non-root one:

- Run build customizations (nodestore-s3, enhance-image.sh, requirements.txt) as root, then switch to the sentry user.
- Trust custom CAs without update-ca-certificates, which needs root: build a combined bundle in /tmp and point the TLS env vars at it.
- Fix sentry-data ownership once during install instead of at every container start.
- Install gosu in the cleanup image instead of relying on the sentry image.

* fix(sentry): Keep update-ca-certificates for custom CAs

Replace the /tmp CA bundle with making /etc/ssl/certs writable by the sentry user, so the existing entrypoint can run update-ca-certificates unchanged. The bundle approach left the standard bundle path and the hashed certs directory without the custom CAs, and did not apply to docker compose exec, so clients that don't read the TLS env vars (e.g. librdkafka, capath lookups, paths set in sentry.conf.py) would stop trusting them.

* fix(install): Chown sentry-data bottom-up so interrupted runs resume

Chown /data last, so if the walk is interrupted the ownership guard still triggers a full walk on the next install.

* fix(install): Fail sentry-data ownership step on unreadable directories

os.walk skips directories it cannot list by default, which would leave them root-owned without any error. Raise instead so install.sh stops, like the old entrypoint's find under set -e.
@oioki
oioki merged commit 852c706 into master Sep 29, 2026
72 checks passed
@oioki
oioki deleted the build/self-hosted-run-as-non-root branch September 29, 2026 10:34
@oioki

oioki commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

After this, the container starts as non-root sentry user:

root@83734c9810e3:/usr/src/sentry# ps aux
USER         PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
sentry         1  0.0  0.0   2480    88 ?        Ss   11:50   0:00 tini -- sentry run web
sentry       778  3.5  0.8 784184 295364 ?       Sl   11:51   0:11 sentry
sentry       814  3.2  1.1 1499984 375376 ?      Sl   11:51   0:09 sentry worker-1
sentry       816  3.1  1.1 1580000 378192 ?      Sl   11:51   0:08 sentry worker-2
sentry       818  2.8  1.1 1576984 369416 ?      Sl   11:51   0:07 sentry worker-3

Still possible to exec as root:

root@dogfood:~# docker exec -it --user root sentry-self-hosted-web-1 /bin/bash
root@83734c9810e3:/usr/src/sentry# whoami
root

Image size, before and after:

$ docker image inspect \
  ghcr.io/getsentry/sentry:{06253865cc5efcccc81ba36e58218660fc8a54ad,852c7068eef29ef6827bd60a037b6ff5adf9538e} \
  --format '{{.Size}}  {{.RepoTags}}'
1425912544  [ghcr.io/getsentry/sentry:06253865cc5efcccc81ba36e58218660fc8a54ad]
1423394257  [ghcr.io/getsentry/sentry:852c7068eef29ef6827bd60a037b6ff5adf9538e]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Scope: Backend Automatically applied to PRs that change backend components

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants