name: "[debug] Sentry egress IP probe" # Throwaway diagnostic for AGE-497: the Sentry noise-gate report workflow gets # a 403 from GitHub-hosted runners with a token verified 200 from a local # machine at the same instant. This prints the runner's public egress IP and # retries the exact failing call with verbose headers, so we can tell an # Actions-IP block (Cloudflare/WAF style, still shaped as a DRF 403 JSON body) # apart from a genuine token/scope problem. # # Delete this workflow once AGE-497 is resolved either way — it exists only to # capture one diagnostic run. on: workflow_dispatch: {} permissions: contents: read jobs: probe: runs-on: ubuntu-latest timeout-minutes: 5 steps: - name: Runner public egress IP run: | set -euo pipefail { echo "### Runner egress IP" echo '```' curl -s https://api.ipify.org || echo "(ipify lookup failed)" echo '' curl -s https://ifconfig.me || echo "(ifconfig.me lookup failed)" echo '' echo '```' } | tee -a "$GITHUB_STEP_SUMMARY" - name: Verbose Sentry probe (same call the report step makes) env: SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_PRODUCT_INTELLIGENCE_TOKEN || secrets.SENTRY_AUTH_TOKEN }} SENTRY_ORG: ${{ secrets.SENTRY_ORG || 'vibetechnologies' }} run: | set -euo pipefail { echo '' echo '### Verbose probe: /organizations/{org}/projects/' echo '```' curl -sv -H "Authorization: Bearer ${SENTRY_AUTH_TOKEN}" \ "https://sentry.io/api/0/organizations/${SENTRY_ORG}/projects/" \ -o /tmp/projects.json -w "\nhttp_code=%{http_code}\n" 2>&1 | grep -v -i "^> authorization" || true echo '```' echo '' echo '### Response body' echo '```' cat /tmp/projects.json echo '```' echo '' echo '### Verbose probe: /auth/ (sanity check — same token, different endpoint)' echo '```' curl -sv -H "Authorization: Bearer ${SENTRY_AUTH_TOKEN}" \ "https://sentry.io/api/0/auth/" \ -o /tmp/auth.json -w "\nhttp_code=%{http_code}\n" 2>&1 | grep -v -i "^> authorization" || true echo '```' echo '' echo '### Auth body' echo '```' cat /tmp/auth.json echo '```' echo '' echo '### Same endpoint, org detail (not a listing) — /organizations/{org}/' echo '```' curl -s -H "Authorization: Bearer ${SENTRY_AUTH_TOKEN}" \ "https://sentry.io/api/0/organizations/${SENTRY_ORG}/" \ -o /tmp/orgdetail.json -w "http_code=%{http_code}\n" echo '```' } | tee -a "$GITHUB_STEP_SUMMARY" - uses: actions/setup-node@v6 with: node-version: 24 - name: Node fetch probe (matches scripts/sentry-volume-report.mjs exactly, no explicit User-Agent) env: SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_PRODUCT_INTELLIGENCE_TOKEN || secrets.SENTRY_AUTH_TOKEN }} SENTRY_ORG: ${{ secrets.SENTRY_ORG || 'vibetechnologies' }} run: | { echo '' echo '### Node fetch probe (same client the failing script uses)' echo '```' node --input-type=module -e ' const token = process.env.SENTRY_AUTH_TOKEN const org = process.env.SENTRY_ORG for (const path of ["/organizations/" + org + "/projects/", "/auth/"]) { const res = await fetch("https://sentry.io/api/0" + path, { headers: { Authorization: "Bearer " + token } }) const body = await res.text() console.log(path, "->", res.status, body.slice(0, 200)) } ' 2>&1 || true echo '```' } | tee -a "$GITHUB_STEP_SUMMARY"