From 709aa97bade9734664272dc2aac41e9d5c88d98f Mon Sep 17 00:00:00 2001 From: engineer Date: Tue, 18 Aug 2026 23:16:52 -0700 Subject: [PATCH] chore(ci): remove the AGE-497 throwaway Sentry egress probe workflow MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Root cause found and fixed: the repo secret SENTRY_ORG (last set 2026-07-22, same day as the stale SENTRY_PRODUCT_INTELLIGENCE_TOKEN from AGE-497's root cause #1) held a stale org slug, not 'vibetechnologies'. Every org-scoped Sentry API call 403'd in CI while /auth/ (identity-only, not org-scoped) kept succeeding — which is what made it look like a network/IP-level block instead of a bad secret value. Confirmed by hardcoding org=vibetechnologies in the probe from the same runner/IP: 200. Fixed by resetting the SENTRY_ORG secret to vibetechnologies; the real 'Sentry noise-gate report' workflow now succeeds (run 32222675122). Co-Authored-By: Paperclip --- .github/workflows/debug-sentry-egress.yml | 117 ---------------------- 1 file changed, 117 deletions(-) delete mode 100644 .github/workflows/debug-sentry-egress.yml diff --git a/.github/workflows/debug-sentry-egress.yml b/.github/workflows/debug-sentry-egress.yml deleted file mode 100644 index ee5807d..0000000 --- a/.github/workflows/debug-sentry-egress.yml +++ /dev/null @@ -1,117 +0,0 @@ -name: "[debug] Sentry egress IP probe" - -# Throwaway diagnostic for AGE-497: the Sentry noise-gate report workflow gets -# a 403 from GitHub-hosted runners with a token verified 200 from a local -# machine at the same instant. This prints the runner's public egress IP and -# retries the exact failing call with verbose headers, so we can tell an -# Actions-IP block (Cloudflare/WAF style, still shaped as a DRF 403 JSON body) -# apart from a genuine token/scope problem. -# -# Delete this workflow once AGE-497 is resolved either way — it exists only to -# capture one diagnostic run. - -on: - workflow_dispatch: {} - -permissions: - contents: read - -jobs: - probe: - runs-on: ubuntu-latest - timeout-minutes: 5 - steps: - - name: Runner public egress IP - run: | - set -euo pipefail - { - echo "### Runner egress IP" - echo '```' - curl -s https://api.ipify.org || echo "(ipify lookup failed)" - echo '' - curl -s https://ifconfig.me || echo "(ifconfig.me lookup failed)" - echo '' - echo '```' - } | tee -a "$GITHUB_STEP_SUMMARY" - - - name: Verbose Sentry probe (same call the report step makes) - env: - SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_PRODUCT_INTELLIGENCE_TOKEN || secrets.SENTRY_AUTH_TOKEN }} - SENTRY_ORG: ${{ secrets.SENTRY_ORG || 'vibetechnologies' }} - run: | - set -euo pipefail - { - echo '' - echo '### Verbose probe: /organizations/{org}/projects/' - echo '```' - curl -sv -H "Authorization: Bearer ${SENTRY_AUTH_TOKEN}" \ - "https://sentry.io/api/0/organizations/${SENTRY_ORG}/projects/" \ - -o /tmp/projects.json -w "\nhttp_code=%{http_code}\n" 2>&1 | grep -v -i "^> authorization" || true - echo '```' - echo '' - echo '### Response body' - echo '```' - cat /tmp/projects.json - echo '```' - echo '' - echo '### Verbose probe: /auth/ (sanity check — same token, different endpoint)' - echo '```' - curl -sv -H "Authorization: Bearer ${SENTRY_AUTH_TOKEN}" \ - "https://sentry.io/api/0/auth/" \ - -o /tmp/auth.json -w "\nhttp_code=%{http_code}\n" 2>&1 | grep -v -i "^> authorization" || true - echo '```' - echo '' - echo '### Auth body' - echo '```' - cat /tmp/auth.json - echo '```' - echo '' - echo '### Same endpoint, org detail (not a listing) — /organizations/{org}/' - echo '```' - curl -s -H "Authorization: Bearer ${SENTRY_AUTH_TOKEN}" \ - "https://sentry.io/api/0/organizations/${SENTRY_ORG}/" \ - -o /tmp/orgdetail.json -w "http_code=%{http_code}\n" - echo '```' - } | tee -a "$GITHUB_STEP_SUMMARY" - - - uses: actions/setup-node@v6 - with: - node-version: 24 - - - name: Node fetch probe (matches scripts/sentry-volume-report.mjs exactly, no explicit User-Agent) - env: - SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_PRODUCT_INTELLIGENCE_TOKEN || secrets.SENTRY_AUTH_TOKEN }} - SENTRY_ORG: ${{ secrets.SENTRY_ORG || 'vibetechnologies' }} - run: | - { - echo '' - echo '### Node fetch probe (same client the failing script uses)' - echo '```' - node --input-type=module -e ' - const token = process.env.SENTRY_AUTH_TOKEN - const org = process.env.SENTRY_ORG - for (const path of ["/organizations/" + org + "/projects/", "/auth/"]) { - const res = await fetch("https://sentry.io/api/0" + path, { headers: { Authorization: "Bearer " + token } }) - const body = await res.text() - console.log(path, "->", res.status, body.slice(0, 200)) - } - ' 2>&1 || true - echo '```' - } | tee -a "$GITHUB_STEP_SUMMARY" - - - name: Node fetch probe with HARDCODED org=vibetechnologies (bypasses secrets.SENTRY_ORG) - env: - SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_PRODUCT_INTELLIGENCE_TOKEN || secrets.SENTRY_AUTH_TOKEN }} - run: | - { - echo '' - echo '### Hardcoded org=vibetechnologies probe (is secrets.SENTRY_ORG stale?)' - echo '```' - node --input-type=module -e ' - const token = process.env.SENTRY_AUTH_TOKEN - const res = await fetch("https://sentry.io/api/0/organizations/vibetechnologies/projects/", { headers: { Authorization: "Bearer " + token } }) - const body = await res.text() - console.log("/organizations/vibetechnologies/projects/ ->", res.status, body.slice(0, 200)) - ' 2>&1 || true - echo '```' - } | tee -a "$GITHUB_STEP_SUMMARY"