Skip to main content
See All Integrations

Self-Hosted Sentry

Protect the interactive Self-Hosted Sentry application without blocking SDK or Relay ingestion.

Standard protected service pattern

Categories
Developer Tools, Monitoring and Observability, Upstream Applications

Overview

Self-Hosted Sentry is the self-managed form of the Sentry application. It has an interactive web interface and API, plus SDK ingestion and Relay traffic. The machine ingestion paths cannot complete an interactive sign-in redirect.

Self-Hosted Sentry can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Self-Hosted Sentry. Self-Hosted Sentry remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.

Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.

Separate browser access from ingestion and machine API paths. Configure the Sentry public URL for the Pomerium origin and keep project authentication tokens active.

Example

Employees use a Pomerium route for the private Sentry web application. SDK and Relay ingestion use a separate compatible endpoint. Sentry keeps organization, project, team, issue, and event permissions.

Considerations

  • The official project describes self-hosting as suitable for low-volume deployments and proofs of concept. Review that operating model.
  • Do not place interactive redirects in front of SDK or Relay ingestion endpoints.

Sources and official resources

  • Protect access to Grafana Loki HTTP endpoints as upstream web applications.

  • Protect access to Prometheus metrics and administration as an upstream web application.

  • Protect access to SonarQube Server while keeping scanners, webhooks, and automation on compatible noninteractive paths.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo