Files
supabase/apps/studio/turbo.jsonc
T
ad181489b1 feat(studio): adopt @sentry/tanstackstart-react server instrumentation on the TanStack build (#47724)
Stacked on #47666 (base `alaister/tanstack-sentry-init`; retarget to
`master` when that merges). **Supersedes #47721** (the manual
`@sentry/node` wrapper). Client stays on #47666's `@sentry/react` setup.

Adopts the official `@sentry/tanstackstart-react` SDK **on the server
only**, after a spike (#47723) evaluating the full unified client+server
SDK. The spike found the SDK's **browser**
`tanstackRouterBrowserTracingIntegration` is a broken no-op stub at
10.59.0/10.64.0 — so the client stays on `@sentry/react` (whose
equivalent integration is a real, working implementation, already
shipped in #47666). The **server** exports, however, are a clear upgrade
and slot in cleanly.

### What this adds (server-side, TanStack build only)
- **`instrument.server.mjs`** — `Sentry.init` from
`@sentry/tanstackstart-react`, mirroring `sentry.server.config.ts` +
`release: VERCEL_GIT_COMMIT_SHA`.
- **`start.ts`** — `sentryGlobalRequestMiddleware` +
`sentryGlobalFunctionMiddleware` at the front of the existing
`createStart(...)` middleware. **This is the win**: it captures request-
and server-function errors *including the ones swallowed into 500s* —
the exact class the manual wrapper (and the Next server SDK) miss.
- **`api/server.js` / `scripts/serve.js`** — gated
(`STUDIO_FRAMEWORK==='tanstack'`) instrument init +
`wrapFetchWithSentry` on the handler.
- **`vite.config.ts`** — `sentryTanstackStart({ …,
autoInstrumentMiddleware: false })` as the last plugin: source-map
upload + release injection (skips gracefully without an auth token).
Middleware is wired explicitly rather than via the plugin's
string-rewrite.

### Guarantees
- **Client untouched** — the `@sentry/nextjs`→`@sentry/react` alias and
#47666's client init are unchanged.
- **Next untouched** — `instrumentation.ts` / `sentry.server.config.ts`
etc. stay as-is; all new code is TanStack-gated.
- **No server SDK in the client bundle** — verified after build: no
`@sentry/node` / server middleware / `wrapFetchWithSentry` in
`dist/client/assets` (`start.ts`'s server import is tree-shaken out).

### Verified
TanStack build exit 0 (past `assertNoChunkCycles`), post-build server
boot served `/api/get-utc-time → 200`, `tsc --noEmit` clean,
prettier/eslint clean. Node smoke: no-DSN init is a clean no-op; wrapped
handler returns 200.

### To test (deploy with a server DSN)
Throw a server error from an `/api/*` route (or a `/_serverFn/*`) —
including one that gets turned into a 500 without rethrowing — and
confirm a server event in Sentry with `release` = the deploy SHA.
Compared to #47721, the swallowed-500 case should now be captured via
the middleware.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added Sentry integration for the Studio app’s TanStack Start runtime,
including request and server-function instrumentation.
* Wrapped server request handling to capture errors reliably, with
tracing enabled.
* Updated build tooling to conditionally upload source maps when
credentials are present.

* **Bug Fixes**
* Improved resilience by safely falling back to a no-op Sentry setup if
instrumentation cannot be loaded.
* Ensured existing request protection remains enabled while adding
observability middleware.

* **Chores / Config**
* Added `SKIP_ASSET_UPLOAD` to the build environment list to control
cache/build behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Alaister Young <10985857+alaister@users.noreply.github.com>
Co-authored-by: Joshen Lim <joshenlimek@gmail.com>
2026-07-10 16:52:07 +08:00

142 lines
4.8 KiB
JSON

{
"$schema": "./../../node_modules/turbo/schema.json",
"extends": ["//"],
"tasks": {
"build": {
"dependsOn": ["^build"],
"env": [
"ANALYZE",
"CI",
"NEXT_PUBLIC_SUPPORT_API_URL",
"NEXT_PUBLIC_CONTENT_API_URL",
"NEXT_PUBLIC_BASE_PATH",
"NEXT_PUBLIC_STRIPE_PUBLIC_KEY",
"NEXT_PUBLIC_SUPPORT_ANON_KEY",
"NEXT_PUBLIC_ENVIRONMENT",
"NEXT_PUBLIC_IS_PLATFORM",
"NEXT_PUBLIC_SITE_URL",
"NEXT_PUBLIC_API_URL",
"NEXT_PUBLIC_DOCS_URL",
"NEXT_PUBLIC_CONFIGCAT_SDK_KEY",
"NEXT_PUBLIC_CONFIGCAT_PROXY_URL",
"NEXT_PUBLIC_HCAPTCHA_SITE_KEY",
"NEXT_PUBLIC_SUPABASE_URL",
"NEXT_PUBLIC_SUPABASE_ANON_KEY",
"NEXT_PUBLIC_NODE_ENV",
"NEXT_PUBLIC_GOTRUE_URL",
"NEXT_PUBLIC_VERCEL_BRANCH_URL",
"NEXT_PUBLIC_GOOGLE_MAPS_KEY",
"NEXT_RUNTIME",
"NIMBUS_PROD_PROJECTS_URL",
"NIMBUS_PROD_PROJECTS_URL_WS",
"NODE_ENV",
"SUPABASE_URL",
"VERCEL",
"VERCEL_ENV",
"MAINTENANCE_MODE",
// These envs are used in the packages
"NEXT_PUBLIC_STORAGE_KEY",
"NEXT_PUBLIC_AUTH_DEBUG_KEY",
"NEXT_PUBLIC_AUTH_PERSISTED_KEY",
"NEXT_PUBLIC_AUTH_NAVIGATOR_LOCK_KEY",
"NEXT_PUBLIC_AUTH_DETECT_SESSION_IN_URL",
"NEXT_PUBLIC_GOOGLE_TAG_MANAGER_ID",
"NEXT_PUBLIC_VERCEL_ENV",
"NEXT_PUBLIC_USERCENTRICS_RULESET_ID",
"NEXT_PUBLIC_MCP_URL",
"NEXT_PUBLIC_IS_NIMBUS",
"NEXT_PUBLIC_ONGOING_INCIDENT",
// These envs are technically passthrough env vars because they're only used on the server side of Nextjs
"PLATFORM_PG_META_URL",
"STUDIO_PG_META_URL",
"PG_META_CRYPTO_KEY",
"PGRST_DB_SCHEMAS",
"PGRST_DB_MAX_ROWS",
"PGRST_DB_EXTRA_SEARCH_PATH",
"POSTGRES_PASSWORD",
"POSTGRES_HOST",
"POSTGRES_USER_READ_WRITE",
"POSTGRES_USER_READ_ONLY",
"POSTGRES_DB",
"POSTGRES_PORT",
"READ_ONLY_URL",
"READ_ONLY_API_KEY",
"SUPABASE_SERVICE_KEY",
"SUPABASE_ANON_KEY",
"SUPABASE_PUBLISHABLE_KEY",
"SUPABASE_SECRET_KEY",
"SUPABASE_PUBLIC_URL",
"DEFAULT_PROJECT_NAME",
"DEFAULT_ORGANIZATION_NAME",
"OPENAI_API_KEY",
"BRAINTRUST_API_KEY",
"BRAINTRUST_PROJECT_ID",
// Gates the dashboard assistant between the remote MCP server and the
// legacy in-process one (see lib/ai/tools/mcp-tools.ts).
"USE_REMOTE_MCP",
"AUTH_JWT_SECRET",
"LOGFLARE_API_KEY",
"LOGFLARE_PUBLIC_ACCESS_TOKEN",
"LOGFLARE_PRIVATE_ACCESS_TOKEN",
"LOGFLARE_URL",
"SENTRY_ORG",
"SENTRY_PROJECT",
"SENTRY_AUTH_TOKEN",
"SKIP_ASSET_UPLOAD",
"NEXT_PUBLIC_SENTRY_DSN",
"AWS_BEDROCK_PROFILE",
"AWS_BEDROCK_ROLE_ARN",
"AWS_ACCESS_KEY_ID",
"AWS_SECRET_ACCESS_KEY",
"FORCE_ASSET_CDN",
"ASSET_CDN_S3_ENDPOINT",
"SITE_NAME",
"VERCEL_URL",
"IS_BRAINTRUST_PUSH",
"GITHUB_HEAD_REF",
"GITHUB_REF_NAME",
"GITHUB_PR_NUMBER",
"IS_THROTTLED",
"AI_PRO_MODEL",
"AI_NORMAL_MODEL",
"SUPPORT_SUPABASE_SECRET_KEY",
"STATUSPAGE_API_KEY",
"STATUSPAGE_PAGE_ID",
"INCIDENT_IO_API_KEY",
"LIVE_SUPABASE_SECRET_KEY",
// Selects the build mode for the studio's `build`/`start` scripts
// (e.g. e2e sets `MODE=test`). Listed so turbo invalidates the
// cache when it changes — without this, switching between test and
// production builds reuses a stale cached output.
"MODE",
// Read by scripts/serve.js (the Node host for `pnpm start`).
// Declared here so the studio-package turbo env lint rule passes
// even though turbo doesn't directly drive `start`.
"PORT",
// Gates the TanStack vs Next path in api/server.js, vercel.ts,
// and scripts/dispatch.js (the dev/build/start dispatcher).
"STUDIO_FRAMEWORK",
// Vite's built-in `import.meta.env.SSR` flag (used in ConnectStepsSection
// to gate Vite-only `import.meta.glob`). Not a real process env var
// but turbo's `no-undeclared-env-vars` lint flags any `env.SSR` access.
"SSR",
],
"passThroughEnv": [
"CURRENT_CLI_VERSION",
"VERCEL_GIT_COMMIT_REF",
"VERCEL_GIT_COMMIT_SHA",
"SNIPPETS_MANAGEMENT_FOLDER",
"EDGE_FUNCTIONS_MANAGEMENT_FOLDER",
"S3_PROTOCOL_ACCESS_KEY_ID",
"S3_PROTOCOL_ACCESS_KEY_SECRET",
],
"outputs": [
".next/**",
"!.next/cache/**",
"!.next/dev/**/*",
"dist/**",
],
},
},
}