diff --git a/deploy/sentry-slack-alert.sh b/deploy/sentry-slack-alert.sh new file mode 100755 index 0000000..54ddc56 --- /dev/null +++ b/deploy/sentry-slack-alert.sh @@ -0,0 +1,90 @@ +#!/bin/bash +# Route every wizwar issue to a Slack channel: new issues (any level or +# priority), regressions, and reappearances. Creates one Sentry workflow +# via the alerts API. The token never leaves your shell: +# SENTRY_TOKEN=sntryu_... deploy/sentry-slack-alert.sh [#channel] +# The token needs the alerts:write scope (an org auth token from +# https://locallygrownnet.sentry.io/settings/auth-tokens/), and Slack must +# already be connected to the org under Settings → Integrations. +set -euo pipefail +: "${SENTRY_TOKEN:?SENTRY_TOKEN=sntryu_... is required (alerts:write)}" +ORG="${SENTRY_ORG:-locallygrownnet}" +PROJECT="${SENTRY_PROJECT:-wizwar}" +CHANNEL="${1:-#wizwar-notifications}" +API="https://us.sentry.io/api/0/organizations/$ORG" +AUTH="Authorization: Bearer $SENTRY_TOKEN" + +echo "looking up the Slack integration…" +SLACK_ID=$(curl -s "$API/integrations/?provider_key=slack" -H "$AUTH" | python3 -c ' +import json, sys +rows = json.load(sys.stdin) +rows = rows if isinstance(rows, list) else [] +for i in rows: + if i.get("provider", {}).get("key") == "slack" and i.get("status") == "active": + print(i["id"]); break') +if [ -z "$SLACK_ID" ]; then + echo "no active Slack integration on the org — connect Slack first at https://$ORG.sentry.io/settings/integrations/slack/" >&2 + exit 1 +fi +echo "Slack integration $SLACK_ID; project $PROJECT; channel $CHANNEL" + +PROJECT_ID=$(curl -s "$API/projects/" -H "$AUTH" | python3 -c ' +import json, sys +for p in json.load(sys.stdin): + if p.get("slug") == sys.argv[1]: print(p["id"]); break' "$PROJECT") +[ -n "$PROJECT_ID" ] || { echo "project $PROJECT not found in $ORG" >&2; exit 1; } + +PAYLOAD=$(CHANNEL="$CHANNEL" SLACK_ID="$SLACK_ID" python3 -c ' +import json, os +print(json.dumps({ + "name": "Wiz-War → Slack", + "enabled": True, + "environment": None, + "config": {"frequency": 0}, + "triggers": { + "logicType": "any-short", + "conditions": [ + {"type": "first_seen_event", "comparison": True, "conditionResult": True}, + {"type": "regression_event", "comparison": True, "conditionResult": True}, + {"type": "reappeared_event", "comparison": True, "conditionResult": True}, + ], + "actions": [], + }, + "actionFilters": [{ + "logicType": "all", + "conditions": [], + "actions": [{ + "type": "slack", + "integrationId": int(os.environ["SLACK_ID"]), + "data": {}, + "config": {"targetType": "specific", "targetIdentifier": None, "targetDisplay": os.environ["CHANNEL"]}, + "status": "active", + }], + }], +}))') + +echo "creating the workflow…" +RESPONSE=$(curl -s -w "\n%{http_code}" -X POST "$API/workflows/" -H "$AUTH" -H "Content-Type: application/json" -d "$PAYLOAD") +CODE=$(printf '%s' "$RESPONSE" | tail -1) +BODY=$(printf '%s' "$RESPONSE" | sed '$d') +if [ "$CODE" != "201" ]; then + echo "Sentry answered $CODE:" >&2; echo "$BODY" >&2; exit 1 +fi +WORKFLOW_ID=$(printf '%s' "$BODY" | python3 -c 'import json,sys; print(json.load(sys.stdin).get("id",""))') +echo "created workflow $WORKFLOW_ID" + +# Bind it to the project's issues via a detector connection, so it fires +# for wizwar rather than sitting unattached. +echo "connecting it to $PROJECT's issues…" +DETECTOR_ID=$(curl -s "$API/detectors/?project=$PROJECT_ID&type=error" -H "$AUTH" | python3 -c ' +import json, sys +rows = json.load(sys.stdin) +rows = rows if isinstance(rows, list) else [] +for d in rows: + if d.get("type") in ("error", "issue"): print(d["id"]); break') +if [ -n "$DETECTOR_ID" ]; then + curl -s -o /dev/null -w "detector link: %{http_code}\n" -X PUT "$API/detectors/$DETECTOR_ID/workflows/" -H "$AUTH" -H "Content-Type: application/json" -d "{\"workflowIds\": [$WORKFLOW_ID]}" +else + echo "no error detector found for $PROJECT; connect the workflow to the project in the Alerts UI" >&2 +fi +echo "done: https://$ORG.sentry.io/monitors/alerts/$WORKFLOW_ID/"