Every source behind this page, graded. Filter by kind. The blog, talk,
paper and case-study tiers are empty because every host carrying them was blocked for this
session; that absence is the biggest limitation of this guide.
Decision record
Sentry2022-07
RFC 0002: Sentry Architecture Vision (Living Document)
Opens by naming a scaling limit as the trigger for the decade's architecture work, then
lists the workstreams that followed: extracting Celery tasks, leaving pickle, moving from
RabbitMQ to Kafka, and phasing out buffers in favour of Kafka and ClickHouse.
Carry forwardA living architecture document that names the constraint, not the target state, is the one that still reads correctly four years later.
github.com/getsentry/rfcs · text/0002-new-architecture.md
Decision record
Sentry2023-02
RFC 0072: Centralized Schema Repository for Kafka Topics
Records that schema disagreements had already caused production incidents, chooses a
schema library for Python and Rust, and rejects a registry service because of what it
would cost to run in every deployment flavour including open source.
Carry forwardWhen a broker becomes the contract surface, the schema question arrives with it; answer it in the artefact your smallest deployment can carry.
github.com/getsentry/rfcs · text/0072-kafka-schema-registry.md
Decision record
Sentry2023-10
RFC 0119: Make it easier to use Rust code from Sentry/Python
Chooses one private bindings package built with PyO3 and maturin over per-crate public
wheels, with the rejection resting on the cost of maintaining a public SemVer API.
Carry forwardThe cheapest way to adopt a second language inside a monolith is one internal extension module, because the expensive part is the public interface you did not need.
github.com/getsentry/rfcs · text/0119-rust-in-sentry.md
Source
Sentry2026-10
getsentry/rfcs, closed-unmerged pull requests
Twenty withdrawn proposals, including custom metrics in SDKs, combined dynamic sampling
and per-category abuse rate limiting. The gaps in the numbering of the accepted set are
visible here.
Carry forwardRead the withdrawn RFCs before the accepted ones: they show what an organisation tried and could not sustain.
github.com/getsentry/rfcs · closed unmerged
Source
Sentry2024-11
RFC pull request 115: Custom Metrics in SDKs
Opened October 2023, closed unmerged thirteen months later with "We can close this as we
haven't moved forward with metrics in the SDKs". The proposal required every SDK to
aggregate locally over ten-second windows.
Carry forwardAn ingestion path that depends on work inside every client library is the most expensive kind to add and the hardest to withdraw.
github.com/getsentry/rfcs · pull 115
Source
Sentry2026-10
getsentry/rfcs text directory
Seventy-one files numbered up to 0157. The large majority concern SDKs, spans, replays
and symbolication rather than server architecture, which is where the four decisions in
section 3 had to be found.
Carry forwardA public RFC set is shaped by who needs to be convinced; server decisions get made where the arguing happens, which may not be the RFC repository.
github.com/getsentry/rfcs · text
Source
Sentry2026-10
getsentry/relay README
Describes the edge process as pushing functionality out of both the SDKs and the server,
and documents that in processing mode it produces to Kafka instead of forwarding to an
upstream Sentry.
Carry forwardPushing per-event work to a separate edge binary also moves your rate limiting to the only place that can enforce it for free.
github.com/getsentry/relay · README.md
Source
Sentry2024-11
Relay changelog, versions 24.8.0 to 24.11.2
Tracks an experimental envelope buffer becoming a SQLite-backed store loaded on startup,
then the deletion of the previous spooling implementation and its configuration options.
Carry forwardAn edge that accepts data on behalf of an unavailable broker needs durable local storage; expect to build it twice before the shape is right.
github.com/getsentry/relay · CHANGELOG.md
Source
Sentry2026-10
getsentry/snuba README
States in one sentence that the service was built to replace Postgres and Redis for
search and aggregation over errors, which dates and motivates the move to a columnar
store.
Carry forwardPut a service in front of the new store before you migrate onto it; the indirection is what makes the next store swap possible.
github.com/getsentry/snuba · README.rst
Source
Sentry2026-10
Snuba architecture overview
Gives the reason ClickHouse was chosen, states that Kafka topics are the only ingestion
input, and notes that no table is written by more than one consumer.
Carry forwardOne writer per table is the constraint that keeps a columnar ingestion pipeline debuggable; it is also what forces a consumer per dataset.
github.com/getsentry/snuba · docs/source/architecture/overview.rst
Source
Sentry2026-10
getsentry/taskbroker README
Names the three design purposes of the Celery replacement: no head-of-line blocking,
out-of-order execution, per-task acknowledgement, with inflight state in SQLite and
workers served over gRPC.
Carry forwardIf your queue problem is described as head-of-line blocking, the fix is per-task acknowledgement, not more workers.
github.com/getsentry/taskbroker · README.md
Source
Sentry2025-06
self-hosted release 25.6.0
Announces taskbroker to operators as the service that "aims to replace Celery" and says
the next release will have it take over the worker and cron containers.
Carry forwardAnnounce a replacement to your operators one release before you depend on it, and expect to need that slack.
github.com/getsentry/self-hosted · releases/tag/25.6.0
Source
Sentry2026-09
self-hosted CHANGELOG
Carries the whole arc of the task migration in four lines across fifteen months, from
adding taskbroker, to "Continue using celery in self-hosted for now", to removing the
option override, to porting individual consumers to tasks in 2026.
Carry forwardA changelog is the only honest record of how long a replacement really took, because it has to tell operators the truth about what is still dual-running.
github.com/getsentry/self-hosted · CHANGELOG.md
Source
Sentry2025-08
self-hosted release 25.8.0
Tells operators to set taskworker.enabled to false if they want their jobs
to keep running on Celery, which is the dual-run switch stated as an operator-facing
option.
Carry forwardGive the old path an explicit off switch that an operator can set, and the migration stops being a release-day gamble.
github.com/getsentry/self-hosted · releases/tag/25.8.0
Source
Sentrytag 9.1.2
docker-compose.yml at tag 9.1.2
Seven services. The entire product shipped as a web process, a cron, a Celery worker,
Postgres, Redis, memcached and an SMTP relay.
Carry forwardKeep a copy of your deployment manifest from five years ago; it is the cheapest measure of what your architecture has cost your operators.
github.com/getsentry/self-hosted · 9.1.2/docker-compose.yml
Source
Sentrytag 20.12.1
docker-compose.yml at tag 20.12.1
Thirty services, including Zookeeper, Kafka, ClickHouse, the first Snuba consumers,
Symbolicator and Relay, alongside the cron and worker pair that were still there.
Carry forwardThe dual-run period shows up as both generations sitting in the same manifest, and that snapshot is what dates the migration.
github.com/getsentry/self-hosted · 20.12.1/docker-compose.yml
Source
Sentry2026-10
docker-compose.yml on master
Fifty-one services. Zookeeper, cron and worker are gone; eighteen Snuba consumers, the
taskbroker trio, pgbouncer, an object store and an uptime checker have arrived.
Carry forwardCount the services in your shipped manifest once a year. It is the number your smallest customer experiences as your architecture.
github.com/getsentry/self-hosted · docker-compose.yml
Source
Sentrytag 20.12.1
self-hosted README at tag 20.12.1
States the memory requirement of the era in six words: at least 2400 MB of RAM, with
Docker and Compose version minimums alongside it.
Carry forwardThe requirements line in an old README is a dated, unarguable measurement of architectural weight.
github.com/getsentry/self-hosted · 20.12.1/README.md
Source
Sentry2026-10
install/_min-requirements.sh
The current floor as code: 14,000 MB and four CPUs by default, 7,000 MB and two CPUs
under the errors-only profile, with a comment reminding the author to update the docs
when the values change.
Carry forwardPut the resource floor in a file the installer reads, not in prose. Prose drifts and nobody notices.
github.com/getsentry/self-hosted · install/_min-requirements.sh
Source
Sentry2025-08
Commit history of install/_min-requirements.sh
Nine commits across four years. The floor became mandatory on 17 August 2024, was
relaxed six days later, and acquired a reduced profile in March 2025.
Carry forwardThe history of the requirements file dates every step-change in architectural cost, and a relaxation six days after a tightening tells you the first number was wrong.
github.com/getsentry/self-hosted · commits for install/_min-requirements.sh
Source
community contributor2025-03
Pull request 3634: Minimum requirements for the errors-only profile
A contributor measures the reduced profile at roughly half the resources, a reviewer
objects that Kafka and ClickHouse still dominate, and the numbers go in after screenshots
of a running stack.
Carry forwardIf your product has a reduced mode, publish its floor separately; a single number makes the whole architecture look heavier than the part most users need.
github.com/getsentry/self-hosted · pull 3634
Source
Sentry2026-10
install/check-minimum-requirements.sh
The installer refuses to continue below the floor and separately requires SSE 4.2 on
x86_64 for ClickHouse unless the check is explicitly skipped.
Carry forwardAn instruction-set requirement is the kind of dependency a storage choice adds to your install base without appearing anywhere in the architecture diagram.
github.com/getsentry/self-hosted · install/check-minimum-requirements.sh
Source
Sentry2026-10
src/sentry/silo/base.py
The enum that lets one codebase act as a monolith, a control silo or a cell, with the
monolith documented as the default that "allows access to all tables and endpoints". The
member reads CELL = "REGION".
Carry forwardWhen you rename a deployment concept, the old name survives in the values; plan for the wire format to outlive the vocabulary.
github.com/getsentry/sentry · src/sentry/silo/base.py
Source
Sentry2026-10
src/sentry/types/cell.py
Defines cells hosted by a region silo and localities grouping them, with 'us' containing
'us1' and 'us2', and keeps the monolith alive as a synthetic region that is "a dummy
object".
Carry forwardA residency boundary is cheapest to add as a naming layer above your existing deployment unit, with the single-instance case preserved as a degenerate one.
github.com/getsentry/sentry · src/sentry/types/cell.py
Source
Sentry2022-08
Oldest pull requests mentioning silo modes
Work starts on 31 August 2022 with CI jobs for silo modes and a change that standardises
"nomenclature around silos", both labelled hybrid.
Carry forwardA topology change begins in the test harness. If CI cannot run both topologies, the migration has not started.
github.com/getsentry/sentry · silo pull requests, oldest first
Source
Sentry2024-02
Commit history of LICENSE.md
Relicensed under FSL-1.0-Apache-2.0 in November 2023 and upgraded to FSL-1.1 in February
2024, in the middle of the topology and task work.
Carry forwardLicence terms are part of the architecture of a shipped product: they set who may run the thing whose resource floor you keep raising.
github.com/getsentry/sentry · commits for LICENSE.md
Source
Sentry2026-10
getsentry/sentry repository
111,734 commits on master and 45.3k stars, for a product that grew five new runtime
components without ever splitting its application repository.
Carry forwardComponent replacement and repository splitting are independent decisions, and this is the case study for doing the first without the second.
github.com/getsentry/sentry
Postmortem
self-hosted operator2026-03
Issue 4240: Relay stopped processing new metrics and events
Produce timeouts to Kafka across multiple topics, with ingestion stopping after the stack
has been running for a while. Open and labelled as waiting on a product owner when
checked.
Carry forwardExport local buffer depth and age from any process that accepts data on behalf of a broker it cannot reach.
github.com/getsentry/self-hosted · issues/4240
Postmortem
self-hosted operator2026-08
Issue 4485: consumers repeatedly unhealthy on coordinator timeouts
Eight unrelated consumer groups time out against the group coordinator at once, with
NOT_COORDINATOR and COORDINATOR_LOAD_IN_PROGRESS in the logs.
Carry forwardCount blast radius by coordinator, not by topic: consumer-group coordination is shared even when the data is not.
github.com/getsentry/self-hosted · issues/4485
Postmortem
self-hosted operator2023-01
Issue 1894: Kafka error after update to 22.12.0 from 22.11.0
Snuba consumers crash-loop on offsets that are no longer available on the broker after a
one-month version bump.
Carry forwardState what an upgrade assumes about committed consumer state, and check it in the installer rather than in the release notes.
github.com/getsentry/self-hosted · issues/1894
Postmortem
self-hosted operator2024-03
Issue 2876: Sentry stopped accepting transaction data
Every transaction counted and dropped, with ClickHouse socket errors in the logs. Closed
as not planned with no root cause recorded.
Carry forwardShow accepted and stored as two counters. The gap between them is the only cheap end-to-end check this pipeline shape has.
github.com/getsentry/self-hosted · issues/2876
Postmortem
Sentry2025-06
self-hosted release 25.6.2
Advises operators coming from 25.5.1 to skip two releases entirely and upgrade straight
to this one, after a Postgres migration failure.
Carry forwardFor software other people install, a published skip-list is a rollback mechanism, and it costs one line of release notes.
github.com/getsentry/self-hosted · releases/tag/25.6.2