Remove a Sentry option or FlagPole feature flag whose rollout is finished, in the correct PR order across sentry, getsentry, and sentry-options-automator. Use when deleting an option from defaults.py, removing a flag from temporary.py, cleaning up a flag that reached 100%, unsetting a value in the options automator, or diagnosing an automator run that reports an unregistered option. Trigger on "remove this feature flag", "delete this option", "clean up the flag", "the flag is fully rolled out", "deprecate an option", "unregistered option", "options drift on main".
Removal takes three PRs in a fixed order, each deployed — not merely merged — before the next one merges. sentry and getsentry roll out region-by-region via GoCD; the automator runs its own pipeline. Wrong order either flips production behavior or turns the automator red on main for everyone.
FlagPole flags use the same order, for a different reason. Flag definitions no longer go through configoptions: the automator symlinks options/default/flagpole.yaml into the getsentry-features sentry-options namespace, and getsentry evaluates flags from that namespace. manager.add(..., FeatureHandlerStrategy.FLAGPOLE) only puts the name in features.default_manager.flagpole_features; nothing registers a feature.<name> option or checks the YAML against registrations. So a wrong order silently changes flag results rather than turning CI red, and a forgotten YAML block stays behind unnoticed.
| # | Repo | Change | Merge only after |
|---|---|---|---|
| 1 | sentry / getsentry | Collapse every read to the outcome that won; delete the dead branch | — |
| 2 | sentry-options-automator | Remove the value / flag block from YAML | step 1 deployed to all regions |
| 3 | sentry | Remove the registration (defaults.py / temporary.py) | step 2 deployed, automator run green |
Step 1 is usually two PRs when a flag is read in both static/ and src/ — frontend and backend are not atomically deployed. That is the repo-wide rule in AGENTS.md, not an options-specific one; "step 1 deployed" therefore means both PRs are out.
| Check | Command / location | What it means |
|---|---|---|
| Is it automator-managed? | Option has FLAG_AUTOMATOR_MODIFIABLE in defaults.py; flags always are | Options with FLAG_PRIORITIZE_DISK or without FLAG_AUTOMATOR_MODIFIABLE come from ops config, not this workflow |
| Should it be deleted at all? | A flag gating a plan/tier entitlement is permanent | Move manager.add(...) from temporary.py to permanent.py; keep the automator entry |
| Where is it read? | rg -n '<name>' src/ static/ tests/ in sentry and getsentry | Every hit is step-1 work, including with self.feature(...) in tests |
| Where is it set, and to what? | Automator at HEAD: rg -n '<name>' options/ | Every hit is step-2 work; together they are the outcome step 1 collapses to |
Read the value from automator main at HEAD — not from the rollout PR, the ticket, or the registered default; it may have moved since.
Stop and ask the user if either holds. Report the values you found and let them decide — do not pick a value and proceed:
options/default/ and the region files hold different values, so there is no single rolled-out outcome to collapse to. Which one wins, or whether the option should stay, is a product decision.[DRIFT] in the automator run). The live value differs from the file, so the file is not the truth. Someone changed it through another channel, and the why matters before anything is deleted.Otherwise collapse each call site to the outcome that won. Do not leave the value behind as an if True or a lone constant — that is the dead code the flag was supposed to retire. Two safe variants:
options.get(...) / features.has(...) / organization.features.includes(...) condition, keep the branch that won, delete the branch that lost.default= in defaults.py to the rolled-out value and deploy that before step 2, then collapse the call sites. Use when the option must stay readable during a longer transition.Doing neither is the common mistake: step 2 then changes production behavior.
The losing branch is rarely the only thing that dies. Delete:
with self.feature(...) blocks and mocked responses that now assert nothingThe gate for step 2 is only that no read of the option remains. If the sweep is large, land the collapse first and the deletions right behind it — a follow-up PR that touches no reads does not affect the ordering.
What removal actually falls back to:
| Kind | Falls back to | Risk if usage still exists |
|---|---|---|
| Option | registered default in src/sentry/options/defaults.py | prod reverts to the pre-rollout default |
| FlagPole flag | no feature.<name> key in getsentry-features → getsentry's FlagPole handler abstains → settings.SENTRY_FEATURES[name], i.e. the default= kwarg on manager.add (normally False). features.batch_has (and so the org serializer's features array) omits the flag instead of using default=, so default=True flags read true in features.has but false in the frontend | flag turns off for everyone, not "stays at 100%" |
Check every file that sets it:
options/default/<file>.yaml and every options/regions/*/<file>.yaml. Region values clobber the default, so a leftover region entry keeps the option set there and breaks step 3.options/default/flagpole.yaml. There are no per-region flagpole files.default=True on the flag registration — that keeps it on after the YAML is gone.Merge, then confirm the deploy is green in #feed-options-automator before step 3.
Delete the options.register(...) line from defaults.py, or the manager.add(...) line from temporary.py. For an api_expose=True flag this also drops it from the org serializer's features array, so any surviving frontend check silently evaluates false rather than erroring — which is why step 1's frontend PR must already be deployed.
For flags, step 2 is what keeps flagpole.yaml clean: automator CI no longer rejects a flag block whose registration is gone, so if step 2 is skipped the YAML block stays forever. Before merging step 3, confirm rg -n '<name>' options/default/flagpole.yaml is empty on automator main.
| Symptom | Cause | Fix |
|---|---|---|
[ERROR] ... unregistered in automator CI; options-drift job red on automator main | an option's registration removed while its value is still in the automator (flags cannot cause this; generate.py skips flagpole.yaml) | land the step-2 removal; Trigger: Override Options Validation unblocks an unrelated PR meanwhile, but it bypasses the gate — ask the user first |
Value stuck in sentry_option with no way to unset | same inversion for an option — configoptions sync only iterates registered FLAG_AUTOMATOR_MODIFIABLE options, so nothing can ever delete the row | re-register the option, let the automator unset it, then remove the registration |
Flag block left in flagpole.yaml after the registration is gone | step 2 skipped for a flag; nothing validates flag YAML against registrations | remove the block from options/default/flagpole.yaml; it is loaded but never evaluated, so removal has no runtime effect |
| Behavior flipped right after the automator PR | step 2 landed before step 1 finished deploying everywhere | revert the automator PR — Trigger: Revert label |
Automator PR CI green but main red after merge | the PR check only fails on errors new vs. its base; the push-to-main drift job fails on any error | fix the pre-existing error, or land the missing step |
9bd646d
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.