syntax = "proto3"; package sentry.search.v1; option go_package = "github.com/sentry/sentry/proto/sentry/search/v1;searchv1"; // SearchService is the full-text search index (Tantivy-backed) that // `api` calls to resolve a free-text query into matching record_ids, // which `api` then joins back against ClickHouse. Internal service-to- // service call, same gRPC-first convention as agent<->ingest — see // /docs/architecture.md and /search/README.md. service SearchService { rpc Search(SearchRequest) returns (SearchResponse); } message SearchRequest { // Free-text query passed to Tantivy's query parser as-is. Supports // phrase queries ("exact phrase") and wildcards (foo*) per Tantivy's // own query syntax — see /search/README.md for exactly what that does // and doesn't support in Phase 1. string query = 1; // Max results to return. 0 (unset) uses the service's own default. uint32 limit = 2; // tenant_id (Phase 4) selects which per-tenant Tantivy index to search // -- resolved server-side by the caller (enterprise/internal/ // searchclient, from the authenticated identity in request context), // never a value a browser/client supplies directly. Empty selects the // single default index every Phase 0-3 deployment (and every // ingest-written record today, regardless of tenant -- see // /docs/security/threat-model.md's ingest-tenancy caveat) already // uses, so this field is purely additive: an old caller that never // sets it keeps today's behavior exactly. string tenant_id = 3; } message SearchResponse { // record_ids of matching logs, most-relevant first. Callers join these // back against ClickHouse's `logs.record_id` column to get full rows — // this service only ever returns IDs, never row data, so it stays a // pure text index rather than a second copy of the row. repeated string record_ids = 1; }