Skip to main content

Overview

Runlayer stores Sentry Relay credentials in WorkOS Vault under runlayer-sentry-credentials. Keep the credential source outside Git and deliver it through the deployment platform’s secret mechanism. Expected fields:

Kubernetes with Runlayer Operator

Sync Vault values into a Kubernetes Secret in the tenant namespace. The default Secret name is runlayer-sentry-relay; required keys are public_key, secret_key, and id. Enable the component in RunlayerInstance:
Use spec.components.sentryRelay.secretRef when the Secret name or key names differ. See Optional component Secrets. Do not place Relay credentials in instance values. Use External Secrets, Terraform, or the customer’s approved secret-delivery controller.

ECS with Terraform

The ECS module fetches Relay credentials through its WorkOS Vault integration and injects them into the Relay task. Configure the WorkOS API key through the module’s normal secret input; do not commit it. If credentials are unavailable, keep Relay disabled or provide an explicit Sentry DSN according to the ECS module contract.

Rotation

  1. Rotate the credential in WorkOS Vault.
  2. Sync the destination secret.
  3. Restart or roll out the affected workload.
  4. Verify Relay health and backend event delivery.

Troubleshooting

  • Missing Secret: confirm namespace, Secret name, and key selectors.
  • Relay disabled: confirm spec.components.sentryRelay.enabled.
  • Vault fetch failure: confirm the WorkOS API key can read the credential.
  • No events: verify outbound HTTPS to Sentry and the Relay configuration.

Security

  • Never commit credential values.
  • Restrict Secret read access to the Relay workload and deployment controller.
  • Rotate immediately after suspected exposure.
  • Audit Vault reads and Kubernetes Secret updates.