
Self-Hosted Sentry
Protect the interactive Self-Hosted Sentry application without blocking SDK or Relay ingestion.
Overview
Self-Hosted Sentry is the self-managed form of the Sentry application. It has an interactive web interface and API, plus SDK ingestion and Relay traffic. The machine ingestion paths cannot complete an interactive sign-in redirect.
Self-Hosted Sentry can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Self-Hosted Sentry. Self-Hosted Sentry remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Separate browser access from ingestion and machine API paths. Configure the Sentry public URL for the Pomerium origin and keep project authentication tokens active.
Example
Employees use a Pomerium route for the private Sentry web application. SDK and Relay ingestion use a separate compatible endpoint. Sentry keeps organization, project, team, issue, and event permissions.
Considerations
- The official project describes self-hosting as suitable for low-volume deployments and proofs of concept. Review that operating model.
- Do not place interactive redirects in front of SDK or Relay ingestion endpoints.
