Repository navigation
feat: Add a GitHub Action and Craft releases, and remove the local proxy - #8
Merged
Merged
Conversation
A repository adds one step and a roach.json file. The action starts a run, runs the command with the proxy variables of the run, and ends the run. Only the command uses the proxy, so later steps such as cache and artifact uploads still work. The command does not get the write token. The client now keeps the certificates of NODE_EXTRA_CA_CERTS in the CA file that it writes. The deployed test runs the action in place of tests/ci-job.ts. Co-Authored-By: Junior <junior@sentry.io>
Roach is now only the shared service. Nothing outside this repository used the local proxy, and the GitHub Action replaces it for adopters. Removed spawnRoach, startRoach, the serve and prune commands, usedFile, missDirectory, and RoachConfig. Also removed the closest-recording hint for misses: the service never passed it through, and the GCS store cannot give it. Recording tests now run against the service. Co-Authored-By: Junior <junior@sentry.io>
The Release workflow runs the Craft workflow, as getsentry/warden does. A release makes the GitHub release v<version>, moves the v<major> tag for the action, and copies the image :<sha> to :<version>. CI and the Image workflow now run on release branches, so Craft can check them and find the image. The action needs no build, so unlike warden there is no dist commit and no -src tag. package.json has no version: the git tag is the version. Co-Authored-By: Junior <junior@sentry.io>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 231e32c. Configure here.
…tart Send cancel signals to the process group of the command, because bash does not pass them to its children. Also stop what the command leaves in the background before the run ends. If startRemoteRun cannot write the CA file, end the run on the service before it throws. Before, the run stayed open until the 6-hour timeout.
Co-Authored-By: David Cramer <david@sentry.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Roach is now only the shared service. This PR adds a GitHub Action, so a repository can adopt the service with one step and a
roach.jsonfile. It releases the action and the service image with Craft, and it removes the local proxy, which nothing used.The action (
action.yml,src/action.ts)GITHUB_REPOSITORY. It usesautomode with the token, andreplaymode without it, as for forks.runin bash with the proxy variables of the run. Only that command uses the proxy, so later steps such as cache saves and artifact uploads still work. The command never gets the write token, and the action masks the run token in logs.src/action.tsdirectly onnode24, so it needs no build step and no dependencies.Client changes (
src/client.ts)NODE_EXTRA_CA_CERTS, so a job keeps trusting its own CAs.startRemoteRuncannot write the CA file, it ends the run before it throws. Before, the run stayed open until the 6-hour timeout.Releases (
.craft.yml,.github/workflows/release.yml)Releaseworkflow calls the Craft release workflow, as ingetsentry/warden. A release manager accepts the release ingetsentry/publish.v<version>and moves thev<major>tag for the action. Warden needs adist/build and-srctags; Roach does not, because the action runs from source.ghcr.io/getsentry/roach:<sha>to:<version>. CI and the Image workflow now also run onrelease/**branches, so Craft can check the release and find its image.package.jsonhas noversion. The git tag is the version.Removed
spawnRoach,startRoach, the CLIserveandprunecommands,usedFile,missDirectory,RoachConfig,RoachAddressand the./serverexport. The CLI now has onlyservice.Tests
tests/deployed.test.tsruns the action against the production-shape service, in place oftests/ci-job.ts. It covers a run with the token that records, a run without it that replays, and a miss that fails the step.tests/recording.test.ts.pnpm checkpasses with 12 tests.Before the first release
SENTRY_RELEASE_BOT_CLIENT_IDvariable and theSENTRY_RELEASE_BOT_PRIVATE_KEYsecret.getsentry/publishneeds push access toghcr.io/getsentry/roach.Not covered yet
NODE_EXTRA_CA_CERTSworks only for Node.:main. Pinning a version is follow-up work.ROACH_TOKENcan write recordings for every tenant, so only trusted repos and workflows should get it.via David Cramer.
--
View Junior Session [Sentry]