Skip to content

fix(evals): Use account-backed Cloudflare tunnels in CI - #1918

Draft
sentry-junior[bot] wants to merge 6 commits into
mainfrom
fix/ci-cloudflare-tunnels
Draft

sentry-junior[bot] wants to merge 6 commits into
mainfrom
fix/ci-cloudflare-tunnels

Conversation

@sentry-junior

@sentry-junior sentry-junior Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Replace anonymous CI Quick Tunnels with a separate remotely managed tunnel and DNS record for each eval invocation. One runner-side script installs the latest official cloudflared release with SHA-256 verification, runs the command, and removes its resources. Run, attempt, job, shard, and a random value determine the hostname; jobs never share a tunnel.

Use sentry-ci-<hash>.sentry.cool so the zone's standard Universal SSL wildcard covers CI. Set CLOUDFLARE_TUNNEL_BASE_DOMAIN to sentry.cool, not a deeper subdomain. No advanced certificate is required.

Keep Cloudflare credentials out of the eval command and Sandboxes. Preserve proxy and fixture-control authentication. Verify public HTTPS reaches this exact proxy before starting evals, using normal system DNS. Stop child process groups on failure or cancellation, and retain exact cleanup state for an always() fallback step. Local evals still use Quick Tunnels.

Document the actual dashboard labels—Argo Tunnel (Legacy) → Edit and DNS → Edit—alongside permission IDs, resource scopes, GitHub bindings, TLS setup, token rotation, and manual cleanup after runner loss. No eval inputs, thresholds, or reply budgets change.

This remains a draft until CI proves real routing and cleanup. Set CLOUDFLARE_ACCOUNT_ID and CLOUDFLARE_ZONE_ID to their hexadecimal IDs as repository variables, and bind CLOUDFLARE_API_TOKEN as a repository secret. Confirm Universal SSL is active. Offline coverage cannot prove Cloudflare permissions, DNS, certificates, or GitHub cancellation behavior.

Fixes #1914

via David Cramer.

--

View Junior Session [Sentry]

Co-Authored-By: David Cramer <david@sentry.io>
@vercel

vercel Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
junior-docs Ready Ready Preview Sep 24, 2026 5:09pm UTC

Request Review

Co-Authored-By: David Cramer <david@sentry.io>
Comment thread packages/junior-evals/scripts/cloudflare-tunnel.mjs
Comment thread packages/junior-evals/scripts/cloudflare-tunnel.mjs
Co-Authored-By: David Cramer <david@sentry.io>
@github-actions

Copy link
Copy Markdown

1 screenshot change — 1 changed · 0 added · 0 removed

Review screenshots in Frameshift

Automations List · Desktop
Automations List · Desktop
Changed

This branch was successfully deployed

1 active deployment
Preview – junior-docs — 1521a099 Deployed Sep 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Authenticate eval Cloudflare tunnels using the current recommended approach

0 participants