Sentry · Template docs

Configuration and variables

Understand generated credentials, shared references, retention and optional email.

Keep template references intact

The template's runtime/*/variables.json files define the Railway wiring. Generated credentials are per-install values. Shared service references should resolve to the same values across Web, consumers and tasks. Do not replace references with secrets in source files.

VariableSource or defaultPurpose
ADMIN_EMAILWeb default admin@sentry.localInitial administrator account
ADMIN_PASSWORDGenerated by RailwayInitial account password; not a password-reset mechanism
SENTRY_SYSTEM_SECRET_KEYGenerated by Railway, shared from WebStable application secret
RELAY_KEY_SEEDGenerated on RelayStable private ingestion identity
SENTRY_EVENT_RETENTION_DAYSWeb default 7, shared to workersIndexed event retention and raw object expiry fallback
PUBLIC_URLGateway public domain referenceCanonical interface URL
INGESTION_URLPrivate Gateway URL, port 8081Private SDK ingestion address
WEB_WORKERSWeb default 1Web worker count
TASKWORKER_CONCURRENCYTasks default 1Taskworker concurrency
KAFKA_LOG_RETENTION_HOURSKafka default 3Queue age policy

These are configuration defaults, not performance targets. Sources: Web variables, Relay variables, Tasks variables, Kafka variables.

Database and storage wiring

POSTGRES_HOST and POSTGRES_PASSWORD reference PostgreSQL. REDIS_HOST and REDIS_PASSWORD reference Valkey. KAFKA_BROKERS, SNUBA, SYMBOLICATOR_HOST, TASKBROKER_HOST and MEMCACHED_HOST connect private backend services.

NODE_* variables reference the Nodestore bucket. FILE_* variables reference Filestore. Their endpoint, bucket, region, access key and secret key references come from Railway. Keep the buckets separate and private. Protect actual generated values and backup copies.

Retention

Keep SENTRY_EVENT_RETENTION_DAYS consistent across the services that reference Web. Invalid retention aborts startup. Raw nodestore writes preserve expiry metadata. Legacy objects without authoritative age metadata remain retained until an operator can establish their age.

Raw expiry, relational cleanup and ClickHouse TTL are independent. Monitor cleanup status and consumer lag. Kafka's queue retention cannot recreate records already deleted. See operations.

Optional SMTP

Email remains disabled while SMTP_HOST is empty. Add these optional variables on Web:

VariableMeaning
SMTP_HOSTYour SMTP provider host
SMTP_PORTProvider port; configuration fallback 587
SMTP_USERProvider username
SMTP_PASSWORDProvider credential, stored only in Railway variables
SMTP_TLSWhether to use TLS; configuration fallback true
SMTP_FROMProvider-authorized sender; fallback to ADMIN_EMAIL

Add matching ${{web.SMTP_*}} references on sentry-consumers and sentry-tasks. Verify invitation and password-reset delivery with your provider. A fallback port does not prove provider compatibility.

Sources: runtime Sentry configuration, operations.

Reset an existing administrator password

Changing ADMIN_PASSWORD does not overwrite an existing user's password. An authenticated Railway operator can run:

railway ssh --service web -- /docker-entrypoint.sh django changepassword EMAIL

Replace EMAIL with the account email. Enter the new password interactively. Do not pass it as a command-line argument. Keep generated application secrets and Relay identity stable across redeploys.

Unofficial community template, not affiliated with or endorsed by Sentry.

Sentry is Fair Source (FSL-1.1-Apache-2.0), source-available software. Copyright Functional Software, Inc. dba Sentry.

For monitoring your own applications, not for offering Sentry as a hosted service to third parties.

Licensing · Upstream LICENSE.md

On this page