Platform & Infrastructure 04 Oct 2026 32 min read

Replacing the engine room in public: ten years of Sentry, read from its RFCs, releases and self-host floor

How Sentry replaced the components that receive, store and execute its work between roughly 2016 and 2026 without splitting the application, and how the free self-hosted edition acted as a constraint on each replacement, reconstructed from RFCs, release notes, three versions of one compose file, the installer's requirements file and operator-filed incident reports.

A decade of component replacement inside one product, measured in the artefact other people install: seven containers at the 9.1.2 tag, thirty by the end of 2020, fifty-one on master, and an enforced memory floor that went from 2,400 MB of advice to 14 GB of refusal. A reader leaves with the five-stage shape every one of these replacements followed and the observable signal at each stage, four decisions with the rejected option and its stated reason, two named failure classes from operator incident reports, and a six-rung ladder for rehearsing the same migration at a scale they can hold in their head.

The finding that surprised me

The free self-hosted edition is not downstream of the architecture but a veto on it: RFC 0072 rejected a Kafka schema registry service partly because it would have to run "in all regions, open source, dev, CI and single tenant installations", and the 25.6.0 release notes announcing taskbroker as Celery's replacement were followed one release later by the changelog line "feat: Continue using celery in self-hosted for now".

What you get out of it

  • Every replacement ran the same five stages, and stage four, removing the old component from the shipped artefact, is years after the internal cutover and is the stage nobody schedules.
  • The two newest Rust services both carry an embedded SQLite store, Relay for envelopes and taskbroker for inflight tasks, because once a broker is the only durable thing in the middle, both ends need somewhere local to put work.
  • The application was never split into services; it was split by jurisdiction in August 2022 into a control silo and cells grouped into localities, with monolith mode kept as "a dummy object" so single installs keep working.
  • Architectural weight is measurable from outside the company: the installer's requirements file became a hard gate on 17 August 2024 and was relaxed six days later, and a reduced errors-only profile followed in March 2025 at roughly half the resources.
  • All four operator incident reports describe an absence of data rather than an error, and two of them were closed or left unanswered without a root cause, so the only cheap end-to-end check this pipeline shape has is an accepted counter next to a stored counter.

Scope

Why this, now. The longest-running of the five replacements, moving asynchronous work off Celery, crossed into the shipped artefact between June and September 2025 and was still being extended in the 26.7.0 to 26.9.0 releases, so the whole arc including its unfinished end is visible at once.

What it does not cover. Any figure for the scale, cost or latency of sentry.io itself, the client-side SDKs where most of the public decision record actually lives, and the merits of the licence change, which appears only as a dated commit; no engineering blog, talk, paper or case study is cited because every host carrying them was blocked for this session.

Open the field guide → Self-contained: it loads nothing at read time, follows your system theme, and prints cleanly.