Finish the Cairn OBS rename through services, docs, and assets

The rename commit before this one covered module paths and the obvious
user-facing strings; this is the rest of it -- the places where "sentry"
was a default value, a filename, or a picture rather than a word in a
sentence.

Defaults that changed: CLICKHOUSE_DATABASE (sentry -> cairnobs),
POSTGRES_DATABASE (sentry_metadata -> cairnobs_metadata), and
POSTGRES_USERNAME (sentry -> cairnobs), across api/alerting/ingest and
the enterprise binaries, plus the compose files and migrate scripts that
create those objects. These are *defaults*, so a deployment that sets
them explicitly is unaffected -- but any deployment relying on the old
defaults must have its environment updated before it picks this up, or
it will come up pointing at a database that doesn't exist.

Also: the light-mode logo variants (the dark ones existed alone, so the
landing page and sidebar rendered a dark mark on a light background),
regenerated favicons, and the docs/README/threat-model prose that still
said Sentry.
This commit is contained in:
2026-08-22 16:12:08 -07:00
parent 13cf9a30cb
commit c920e0f2c4
68 changed files with 242 additions and 186 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
# Build context must be the repo root (sentry/), not ingest/, since this
# needs both ingest/ and proto/:
# docker build -f ingest/Dockerfile -t sentry-ingest .
# docker build -f ingest/Dockerfile -t cairnobs-ingest .
FROM golang:1.25-alpine AS builder
WORKDIR /src
+7 -7
View File
@@ -86,13 +86,13 @@ full list and defaults) — no config file format for Phase 0:
| Var | Default | Purpose |
|---|---|---|
| `GRPC_LISTEN_ADDR` | `:4317` | Agent-facing gRPC listen address |
| `TLS_CERT_FILE` / `TLS_KEY_FILE` | `/etc/sentry-ingest/server{,-key}.pem` | ingest's own mTLS identity |
| `TLS_CLIENT_CA_FILE` | `/etc/sentry-ingest/ca.pem` | CA used to verify agent client certs |
| `TLS_CERT_FILE` / `TLS_KEY_FILE` | `/etc/cairnobs-ingest/server{,-key}.pem` | ingest's own mTLS identity |
| `TLS_CLIENT_CA_FILE` | `/etc/cairnobs-ingest/ca.pem` | CA used to verify agent client certs |
| `REDPANDA_BROKERS` | `localhost:9092` | Comma-separated broker list |
| `REDPANDA_TOPIC` | `sentry.logs.raw` | Must match the topic provisioned in `/transport` |
| `REDPANDA_CONSUMER_GROUP` | `sentry-ingest` | Consumer group id |
| `REDPANDA_TOPIC` | `cairnobs.logs.raw` | Must match the topic provisioned in `/transport` |
| `REDPANDA_CONSUMER_GROUP` | `cairnobs-ingest` | Consumer group id |
| `CLICKHOUSE_ADDR` | `localhost:9000` | Native protocol port, not HTTP |
| `CLICKHOUSE_DATABASE` / `_USERNAME` / `_PASSWORD` | `sentry` / `default` / `` | |
| `CLICKHOUSE_DATABASE` / `_USERNAME` / `_PASSWORD` | `cairnobs` / `default` / `` | |
| `CONSUMER_BATCH_MAX_SIZE` | `500` | Records per ClickHouse batch insert |
| `CONSUMER_BATCH_FLUSH_INTERVAL_MS` | `2000` | Max time a partial batch waits before flushing |
| `ENTERPRISE_AUTH_URL` | (empty) | Enables `internal/grpcserver.TenantResolver` -- empty means PushBatch never requires a bearer credential and no `tenant_id` header is ever attached, same as every Phase 0-3 deployment |
@@ -108,12 +108,12 @@ go test ./...
Requires `google.golang.org/protobuf/cmd/protoc-gen-go` and
`google.golang.org/grpc/cmd/protoc-gen-go-grpc` only if you're
regenerating `/proto`'s Go bindings — ingest itself just imports the
already-generated `github.com/sentry/sentry/proto` module (see the
already-generated `github.com/cairnobs/cairnobs/proto` module (see the
`replace` directive in `go.mod`, pointing at `../proto`).
```sh
# from the repo root, not ingest/
docker build -f ingest/Dockerfile -t sentry-ingest .
docker build -f ingest/Dockerfile -t cairnobs-ingest .
```
## Testing notes
@@ -1,7 +1,7 @@
// Package agentregistry is the Postgres-backed implementation of
// grpcserver.AgentRegistry -- ingest's half of agent inventory/remote
// config (see /docs/agent-management-design.md). Writes into the same
// sentry_metadata Postgres api reads/writes from for the web UI's
// cairnobs_metadata Postgres api reads/writes from for the web UI's
// inventory and edit-config views (api/agents), the same shared-schema-
// different-services shape alerting and api already use for dashboards/
// alert_rules.
+7 -7
View File
@@ -26,8 +26,8 @@ type Config struct {
// AgentRegistry enables agent inventory/remote config
// (internal/agentregistry, internal/grpcserver.AgentRegistry) when
// Postgres.Addr is set -- same "off unless configured" shape as
// EnterpriseAuthURL above. Writes into the same sentry_metadata
// database api/web already use, via the same shared "sentry" role
// EnterpriseAuthURL above. Writes into the same cairnobs_metadata
// database api/web already use, via the same shared "cairnobs" role
// every other non-audit table in this schema uses (unlike
// audit_log's dedicated restricted role -- agent inventory carries
// no tamper-evidence requirement).
@@ -110,12 +110,12 @@ func Load() (Config, error) {
},
Redpanda: RedpandaConfig{
Brokers: strings.Split(getenv("REDPANDA_BROKERS", "localhost:9092"), ","),
Topic: getenv("REDPANDA_TOPIC", "sentry.logs.raw"),
ConsumerGroup: getenv("REDPANDA_CONSUMER_GROUP", "sentry-ingest"),
Topic: getenv("REDPANDA_TOPIC", "cairnobs.logs.raw"),
ConsumerGroup: getenv("REDPANDA_CONSUMER_GROUP", "cairnobs-ingest"),
},
ClickHouse: ClickHouseConfig{
Addr: getenv("CLICKHOUSE_ADDR", "localhost:9000"),
Database: getenv("CLICKHOUSE_DATABASE", "sentry"),
Database: getenv("CLICKHOUSE_DATABASE", "cairnobs"),
Username: getenv("CLICKHOUSE_USERNAME", "default"),
Password: getenv("CLICKHOUSE_PASSWORD", ""),
},
@@ -123,8 +123,8 @@ func Load() (Config, error) {
AgentRegistry: AgentRegistryConfig{
Postgres: PostgresConfig{
Addr: getenv("AGENT_REGISTRY_POSTGRES_ADDR", ""),
Database: getenv("AGENT_REGISTRY_POSTGRES_DATABASE", "sentry_metadata"),
Username: getenv("AGENT_REGISTRY_POSTGRES_USERNAME", "sentry"),
Database: getenv("AGENT_REGISTRY_POSTGRES_DATABASE", "cairnobs_metadata"),
Username: getenv("AGENT_REGISTRY_POSTGRES_USERNAME", "cairnobs"),
Password: getenv("AGENT_REGISTRY_POSTGRES_PASSWORD", ""),
},
},
+2 -2
View File
@@ -10,8 +10,8 @@ func TestLoadDefaults(t *testing.T) {
if cfg.GRPC.ListenAddr != ":4317" {
t.Errorf("GRPC.ListenAddr = %q, want :4317", cfg.GRPC.ListenAddr)
}
if cfg.Redpanda.Topic != "sentry.logs.raw" {
t.Errorf("Redpanda.Topic = %q, want sentry.logs.raw", cfg.Redpanda.Topic)
if cfg.Redpanda.Topic != "cairnobs.logs.raw" {
t.Errorf("Redpanda.Topic = %q, want cairnobs.logs.raw", cfg.Redpanda.Topic)
}
if cfg.Batch.MaxSize != 500 {
t.Errorf("Batch.MaxSize = %d, want 500", cfg.Batch.MaxSize)