sentry: tunnel client events through the app to dodge Cloudflare's 503

GlitchTip is behind Cloudflare, which answers the browser's cross-site ingest
POSTs with 503 (no CORS headers -> 'Failed to fetch'); server-side requests
pass. The browser SDK now posts envelopes same-origin to /sentry-tunnel, and
the server forwards them to GlitchTip:
- imports/startup/server/sentryTunnel.js: WebApp handler that relays the raw
  envelope to <dsn>/api/<project>/envelope/?sentry_key=<key> over IPv4
  (family:4 avoids Happy-Eyeballs picking Cloudflare's unroutable IPv6 on
  IPv4-only hosts). GlitchTip authenticates by the sentry_key query, so the
  key is derived from the DSN and passed explicitly.
- client ravenLogger: tunnel: '/sentry-tunnel'.
Verified: POST /sentry-tunnel -> 200 (envelope reaches GlitchTip).
This commit is contained in:
vjrj 2026-07-17 18:17:47 +02:00
parent 696789e2b1
commit 62ac2fbd9c
3 changed files with 135 additions and 1 deletions

View file

@ -13,7 +13,13 @@ if (enabled) {
Sentry.init({
dsn,
environment: Meteor.isDevelopment ? 'development' : 'production',
tracesSampleRate: 0
tracesSampleRate: 0,
// Send events same-origin to our own server, which forwards them to
// GlitchTip. GlitchTip is fronted by Cloudflare, whose bot protection
// returns 503 to the browser's cross-site ingest beacons (server-side
// requests pass fine). The tunnel sidesteps that entirely (and ad-blockers).
// See imports/startup/server/sentryTunnel.js.
tunnel: '/sentry-tunnel'
});
}