Skip to content

feat: Add a GitHub Action and Craft releases, and remove the local proxy - #8

Merged
dcramer merged 5 commits into
mainfrom
feat/github-action
Oct 11, 2026
Merged

dcramer merged 5 commits into
mainfrom
feat/github-action

Conversation

@sentry-junior

@sentry-junior sentry-junior Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
Contributor

Roach is now only the shared service. This PR adds a GitHub Action, so a repository can adopt the service with one step and a roach.json file. It releases the action and the service image with Craft, and it removes the local proxy, which nothing used.

- uses: getsentry/roach@v0
  with:
    token: ${{ secrets.ROACH_TOKEN }} # without it, the run can only replay
    run: pnpm test

The action (action.yml, src/action.ts)

  • Starts a run for the tenant GITHUB_REPOSITORY. It uses auto mode with the token, and replay mode without it, as for forks.
  • Runs run in bash with the proxy variables of the run. Only that command uses the proxy, so later steps such as cache saves and artifact uploads still work. The command never gets the write token, and the action masks the run token in logs.
  • Wraps the command in one session. When the command fails, the run drops its new recordings. A replay miss fails the step.
  • When the job is canceled, it stops all processes of the command, then ends the run.
  • Writes the stats and the first miss to the log and the job summary.
  • Runs src/action.ts directly on node24, so it needs no build step and no dependencies.

Client changes (src/client.ts)

  • The CA file also has the certificates of the job's NODE_EXTRA_CA_CERTS, so a job keeps trusting its own CAs.
  • If startRemoteRun cannot write the CA file, it ends the run before it throws. Before, the run stayed open until the 6-hour timeout.

Releases (.craft.yml, .github/workflows/release.yml)

  • The manual Release workflow calls the Craft release workflow, as in getsentry/warden. A release manager accepts the release in getsentry/publish.
  • Craft makes the GitHub release v<version> and moves the v<major> tag for the action. Warden needs a dist/ build and -src tags; Roach does not, because the action runs from source.
  • Craft copies the image ghcr.io/getsentry/roach:<sha> to :<version>. CI and the Image workflow now also run on release/** branches, so Craft can check the release and find its image.
  • package.json has no version. The git tag is the version.

Removed

  • The local proxy: spawnRoach, startRoach, the CLI serve and prune commands, usedFile, missDirectory, RoachConfig, RoachAddress and the ./server export. The CLI now has only service.
  • The "closest recording" hint for misses. The service never passed it through, and the GCS store can't produce it.

Tests

  • tests/deployed.test.ts runs the action against the production-shape service, in place of tests/ci-job.ts. It covers a run with the token that records, a run without it that replays, and a miss that fails the step.
  • The recording tests now run against the service, in tests/recording.test.ts.
  • pnpm check passes with 12 tests.

Before the first release

  • Roach needs the SENTRY_RELEASE_BOT_CLIENT_ID variable and the SENTRY_RELEASE_BOT_PRIVATE_KEY secret.
  • getsentry/publish needs push access to ghcr.io/getsentry/roach.

Not covered yet

  • The action and the release workflow have not run on GitHub. Cancellation was tested only locally.
  • Misses are named per job, not per test. A per-test Vitest hook is follow-up work.
  • NODE_EXTRA_CA_CERTS works only for Node.
  • Terraform still deploys :main. Pinning a version is follow-up work.
  • The shared ROACH_TOKEN can write recordings for every tenant, so only trusted repos and workflows should get it.

via David Cramer.

--

View Junior Session [Sentry]

sentry-junior Bot and others added 3 commits October 10, 2026 23:41
A repository adds one step and a roach.json file. The action starts a
run, runs the command with the proxy variables of the run, and ends the
run. Only the command uses the proxy, so later steps such as cache and
artifact uploads still work. The command does not get the write token.

The client now keeps the certificates of NODE_EXTRA_CA_CERTS in the CA
file that it writes. The deployed test runs the action in place of
tests/ci-job.ts.

Co-Authored-By: Junior <junior@sentry.io>
Roach is now only the shared service. Nothing outside this repository
used the local proxy, and the GitHub Action replaces it for adopters.

Removed spawnRoach, startRoach, the serve and prune commands, usedFile,
missDirectory, and RoachConfig. Also removed the closest-recording hint
for misses: the service never passed it through, and the GCS store
cannot give it. Recording tests now run against the service.

Co-Authored-By: Junior <junior@sentry.io>
The Release workflow runs the Craft workflow, as getsentry/warden does.
A release makes the GitHub release v<version>, moves the v<major> tag for
the action, and copies the image :<sha> to :<version>. CI and the Image
workflow now run on release branches, so Craft can check them and find
the image.

The action needs no build, so unlike warden there is no dist commit and no
-src tag. package.json has no version: the git tag is the version.

Co-Authored-By: Junior <junior@sentry.io>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 231e32c. Configure here.

Comment thread src/action.ts Outdated
Comment thread src/client.ts
…tart

Send cancel signals to the process group of the command, because bash
does not pass them to its children. Also stop what the command leaves in
the background before the run ends.

If startRemoteRun cannot write the CA file, end the run on the service
before it throws. Before, the run stayed open until the 6-hour timeout.
Co-Authored-By: David Cramer <david@sentry.io>
@sentry-junior sentry-junior Bot changed the title feat(action): Add a GitHub Action and remove the local proxy feat: Add a GitHub Action and Craft releases, and remove the local proxy Oct 11, 2026
@dcramer
dcramer merged commit 653c28e into main Oct 11, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant