Replacing the engine room in public: ten years of Sentry, read from its RFCs, releases and self-host floor
How Sentry replaced the components that receive, store and execute its work between roughly 2016 and 2026 without splitting the application, and how the free self-hosted edition acted as a constraint on each replacement, reconstructed from RFCs, release notes, three versions of one compose file, the installer's requirements file and operator-filed incident reports.
A decade of component replacement inside one product, measured in the artefact other people install: seven containers at the 9.1.2 tag, thirty by the end of 2020, fifty-one on master, and an enforced memory floor that went from 2,400 MB of advice to 14 GB of refusal. A reader leaves with the five-stage shape every one of these replacements followed and the observable signal at each stage, four decisions with the rejected option and its stated reason, two named failure classes from operator incident reports, and a six-rung ladder for rehearsing the same migration at a scale they can hold in their head.
The free self-hosted edition is not downstream of the architecture but a veto on it: RFC 0072 rejected a Kafka schema registry service partly because it would have to run "in all regions, open source, dev, CI and single tenant installations", and the 25.6.0 release notes announcing taskbroker as Celery's replacement were followed one release later by the changelog line "feat: Continue using celery in self-hosted for now".
What you get out of it
- Every replacement ran the same five stages, and stage four, removing the old component from the shipped artefact, is years after the internal cutover and is the stage nobody schedules.
- The two newest Rust services both carry an embedded SQLite store, Relay for envelopes and taskbroker for inflight tasks, because once a broker is the only durable thing in the middle, both ends need somewhere local to put work.
- The application was never split into services; it was split by jurisdiction in August 2022 into a control silo and cells grouped into localities, with monolith mode kept as "a dummy object" so single installs keep working.
- Architectural weight is measurable from outside the company: the installer's requirements file became a hard gate on 17 August 2024 and was relaxed six days later, and a reduced errors-only profile followed in March 2025 at roughly half the resources.
- All four operator incident reports describe an absence of data rather than an error, and two of them were closed or left unanswered without a root cause, so the only cheap end-to-end check this pipeline shape has is an accepted counter next to a stored counter.
Scope
Why this, now. The longest-running of the five replacements, moving asynchronous work off Celery, crossed into the shipped artefact between June and September 2025 and was still being extended in the 26.7.0 to 26.9.0 releases, so the whole arc including its unfinished end is visible at once.
What it does not cover. Any figure for the scale, cost or latency of sentry.io itself, the client-side SDKs where most of the public decision record actually lives, and the merits of the licence change, which appears only as a dated commit; no engineering blog, talk, paper or case study is cited because every host carrying them was blocked for this session.
Other field guides
Keeping the main branch green: thirteen years of merge queues, read from the repositories that ran them
The merge-queue pattern traced through its primary record: Rust's three generations of bors, Zuul's speculative gating, Kubernetes' Tide, GitLab's tr…
20 sources · 11 organisations · 2 postmortemsScaling without splitting: a decade of Shopify, read from the code it published
A decade of one company's architecture, reconstructed from the ring of repositories around a closed monolith: a boundary checker whose stricter half …
26 sources · 8 organisations · 4 postmortemsTwo hundred control planes per cluster: ten years of SAP's Gardener
A fleet platform has to give hundreds of teams their own cluster, on whichever infrastructure each product sells on, cheaply enough that asking for o…
34 sources · 4 organisations · 3 postmortems