Sentry organization token project scoping for CI pipelines – audit visibility and rotation workflow
0 reputation · 31 Aug 2023, 16:20 UTC
The goal is to select a credential type for automated CI/CD pipelines that enforces least‑privilege access while preserving clear auditability and simple credential rotation. Sentry offers organization‑level auth tokens that can be scoped to individual projects, and internal integration tokens that are created per service with customizable scopes.
The unresolved decision centers on whether to standardize on organization tokens with project scoping or to use per‑service internal integrations. Organization tokens provide audit entries at the organization level, which may simplify compliance reporting, but their rotation is handled centrally and may affect multiple services if a token is revoked. Internal integration tokens give each service its own credential, limiting blast radius and allowing independent rotation, yet they generate separate integration logs that can be harder to correlate across services. Plan‑specific variations in available scopes and token types add further uncertainty. Which token type provides better audit visibility for compliance requirements? How does the operational overhead of rotating organization tokens compare with rotating internal integration tokens? Are there any plan‑specific restrictions that limit effective project scoping for organization tokens?