Fix enterprise-auth's Docker build context and ClickHouse admin access

enterprise/Dockerfile built from enterprise/ alone, too narrow for
enterprise/go.mod's replace ../api directive once enterprise-auth
started importing api/httpserver and (transitively) api/dashboards --
confirmed broken the first time this was built with real Docker access.
Fixed to build from the repo root, matching enterprise-api/
enterprise-ingest's Dockerfiles.

Also: ClickHouse's default admin user genuinely lacked CREATE USER
privilege in docker-compose.yml -- the official image needs
CLICKHOUSE_DEFAULT_ACCESS_MANAGEMENT=1 (not the more obvious-looking
CLICKHOUSE_ACCESS_MANAGEMENT, confirmed by reading the image's own
/entrypoint.sh), which this file never set. Every tenant-provisioning
code path was correct Go that had simply never been able to
authenticate its own admin connection strongly enough to run.
This commit is contained in:
2026-08-15 17:17:03 -07:00
parent 5a898cb43e
commit d9e4f22200
2 changed files with 34 additions and 6 deletions
+17 -4
View File
@@ -1,10 +1,23 @@
# Commercial-license module, built the same way as every other Go
# service here -- no /proto dependency, context is enterprise/ itself,
# same shape as cli/Dockerfile and alerting/Dockerfile.
# docker build -f enterprise/Dockerfile -t sentry-enterprise-auth enterprise/
# Commercial-license module, built like every other Go service here --
# context must be the repo root, not enterprise/ alone. enterprise/go.mod
# has replace directives for api/, ingest/, and proto/ (all resolved as
# sibling directories, e.g. ../api), and enterprise-auth needs api/
# specifically for two real reasons: cmd/enterprise-auth/main.go imports
# api/httpserver directly (WithCredentialedCORS, for the tenant-picker's
# credentialed cross-origin requests), and internal/rbacstore's
# DashboardPermissions adapter imports api/dashboards transitively.
# Go's module resolution needs the whole module's go.mod satisfied to
# build any one package in it, so this was never actually optional the
# way the old enterprise/-only context assumed -- confirmed broken the
# first time this was built with real Docker access after those two
# imports existed; the repo-root context below is the same shape
# enterprise-api's and enterprise-ingest's Dockerfiles already use for
# the identical reason.
# docker build -f enterprise/Dockerfile -t sentry-enterprise-auth .
FROM golang:1.25-alpine AS builder
WORKDIR /src
COPY . .
WORKDIR /src/enterprise
RUN CGO_ENABLED=0 GOOS=linux go build -o /out/enterprise-auth ./cmd/enterprise-auth
FROM gcr.io/distroless/static-debian12