Skip to content

fix: correct 8 group-scoped resource API paths - #2

Merged
werd-drew merged 1 commit into
mainfrom
fix/registry-group-paths
Jun 25, 2026
Merged

werd-drew merged 1 commit into
mainfrom
fix/registry-group-paths

Conversation

@JacobPEvans-personal

Copy link
Copy Markdown
Contributor

Summary

Eight group-scoped resources in commands/registry.py used endpoint paths that
return HTTP 404 on Cribl 4.17.1 (verified live against a real Leader). The
original paths were inconsistent — some under system/, one with no library
prefix, two with a nested lib/sds/... segment, and several with abbreviated
names — so any command built from them could never reach the API.

Changes

resource before after
parsers system/parsers lib/parsers
schemas schemas lib/schemas
db-connections lib/db-connections lib/database-connections
conditions lib/conditions conditions
sds-rules lib/sds/rules lib/sds-rules
sds-rulesets lib/sds/rulesets lib/sds-rulesets
appscope lib/appscope lib/appscope-configs
hmac-functions lib/hmac lib/hmac-functions

registry.py drives every factory-generated CRUD command, so this also repairs
the existing cribl parsers list, schemas, sds-rules, appscope, etc.
commands — not just the new group export/import (#1) that surfaced the problem.

Test Plan

  • pytest -m "not integration" — 133 unit tests pass (no regression).
  • Runtime path proof via --dry-run (no live creds needed), e.g.
    cribl --dry-run parsers list -g GRP now emits
    GET /api/v1/m/GRP/lib/parsers; confirmed for all eight.
  • Please confirm against your live Leader before merging: run
    cribl parsers list, cribl schemas list, cribl sds-rules list and
    verify they return 200, not 404. (This repo has no CI.)

🤖 Generated with Claude Code

Eight group-scoped resources used endpoint paths that return HTTP 404 on Cribl
4.17.1 (verified live against a real Leader). The originals were inconsistent —
some under system/, one with no library prefix, two with a nested lib/sds/...
segment, and several with abbreviated names — so the commands built from them
could never reach the API.

  parsers          system/parsers       -> lib/parsers
  schemas          schemas              -> lib/schemas
  db-connections   lib/db-connections   -> lib/database-connections
  conditions       lib/conditions       -> conditions
  sds-rules        lib/sds/rules        -> lib/sds-rules
  sds-rulesets     lib/sds/rulesets     -> lib/sds-rulesets
  appscope         lib/appscope         -> lib/appscope-configs
  hmac-functions   lib/hmac             -> lib/hmac-functions

registry.py drives every factory-generated CRUD command, so this also repairs
the existing `cribl parsers list`, `schemas`, `sds-rules`, `appscope`, etc.
commands — not just the new group export/import that surfaced the problem.
JacobPEvans-personal added a commit that referenced this pull request Jun 21, 2026
Add a `groups` command that moves an entire worker group's or edge fleet's
config between groups (a fleet is the same API object with `isFleet: true`, so
both flow through one path):

- `groups export <group>` pulls every group-scoped resource to stdout, or
  `--out-dir` writes one file per resource type (dir/files locked to 0700/0600).
- `groups import <group>` upserts the config back. It is staged, never deployed:
  routes are skipped unless `--with-routes`, and `--deploy` requires `--yes`.
- Secrets, credentials, and certificates are excluded unless
  `--include-sensitive`; everything skipped or failed is reported in `_meta`.
- Import honors each resource type's registry operations: read-only types
  (executors, hmac-functions, functions) are skipped and create-only types
  without `update` (certificates, samples, scripts) are created, not PATCHed.

The resource list is derived from `commands/registry.py` plus the hand-written
sources/destinations/pipelines/packs/routes, so it never drifts from the rest
of the CLI. Route import uses a new public `replace_route_table()` helper in
`api/endpoints/routes.py` (wholesale swap, preserving edge/stream format).

Depends on the registry path corrections in #2 (the export/import surfaced the
404s those fix).
@JacobPEvans-personal
JacobPEvans-personal marked this pull request as draft June 21, 2026 18:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes incorrect Cribl API endpoint paths for several group-scoped factory-generated CRUD commands by updating commands/registry.py to use paths that are valid on Cribl 4.17.1 (per PR description), preventing 404s for affected commands.

Changes:

  • Corrected registry endpoint paths for 8 group-scoped resources (e.g., parsers, schemas, sds-rules, appscope, hmac-functions).
  • Standardized several paths under the appropriate lib/… namespace and corrected resource naming (e.g., database-connections, appscope-configs).

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@JacobPEvans-personal
JacobPEvans-personal marked this pull request as ready for review June 21, 2026 22:25

@werd-drew werd-drew left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Verified live against our Leader (Cribl Cloud, group default): all 8 affected commands returned 404 on main and 200 on this branch — parsers, schemas, db-connections, conditions, sds-rules, sds-rulesets, appscope, hmac-functions. Tight, registry-only change that repairs genuinely broken CRUD commands. 🚢

@werd-drew
werd-drew merged commit c12cd04 into main Jun 25, 2026
1 check passed
@werd-drew
werd-drew deleted the fix/registry-group-paths branch June 25, 2026 04:50
werd-drew added a commit that referenced this pull request Jun 25, 2026
…#1)

* fix: correct 8 group-scoped resource API paths

Eight group-scoped resources used endpoint paths that return HTTP 404 on Cribl
4.17.1 (verified live against a real Leader). The originals were inconsistent —
some under system/, one with no library prefix, two with a nested lib/sds/...
segment, and several with abbreviated names — so the commands built from them
could never reach the API.

  parsers          system/parsers       -> lib/parsers
  schemas          schemas              -> lib/schemas
  db-connections   lib/db-connections   -> lib/database-connections
  conditions       lib/conditions       -> conditions
  sds-rules        lib/sds/rules        -> lib/sds-rules
  sds-rulesets     lib/sds/rulesets     -> lib/sds-rulesets
  appscope         lib/appscope         -> lib/appscope-configs
  hmac-functions   lib/hmac             -> lib/hmac-functions

registry.py drives every factory-generated CRUD command, so this also repairs
the existing `cribl parsers list`, `schemas`, `sds-rules`, `appscope`, etc.
commands — not just the new group export/import that surfaced the problem.

* feat: add whole-group export/import for worker groups and edge fleets

Add a `groups` command that moves an entire worker group's or edge fleet's
config between groups (a fleet is the same API object with `isFleet: true`, so
both flow through one path):

- `groups export <group>` pulls every group-scoped resource to stdout, or
  `--out-dir` writes one file per resource type (dir/files locked to 0700/0600).
- `groups import <group>` upserts the config back. It is staged, never deployed:
  routes are skipped unless `--with-routes`, and `--deploy` requires `--yes`.
- Secrets, credentials, and certificates are excluded unless
  `--include-sensitive`; everything skipped or failed is reported in `_meta`.
- Import honors each resource type's registry operations: read-only types
  (executors, hmac-functions, functions) are skipped and create-only types
  without `update` (certificates, samples, scripts) are created, not PATCHed.

The resource list is derived from `commands/registry.py` plus the hand-written
sources/destinations/pipelines/packs/routes, so it never drifts from the rest
of the CLI. Route import uses a new public `replace_route_table()` helper in
`api/endpoints/routes.py` (wholesale swap, preserving edge/stream format).

Depends on the registry path corrections in #2 (the export/import surfaced the
404s those fix).

* fix: address Copilot review on group export/import

- write_dir() clears stale *.json from a prior export before writing, so a
  secrets.json left by an earlier --include-sensitive run can't linger and be
  re-imported by read_input().
- Narrow the "never replace the route table wholesale" rule in CLAUDE.md to note
  that `groups import --with-routes` is the deliberate, gated exception.
- Add unit tests for replace_route_table() (stream + edge wrapper) and for
  write_dir() stale-file cleanup.

* feat(groups): drop built-in and pack-owned resources from export

Whole-group export captured Cribl-shipped library content (lib == "cribl"),
built-in system objects (destroyable false), and pack-owned items (id prefixed
"pack:") because they appear in list responses. None are writable as standalone
group config, so importing them produced hundreds of 4xx/5xx errors.

Filter them at export so the payload is only user-authored config. Verified
live: a real group's import failures dropped from ~300 to ~14 (the remainder
being pack archives, which need the .crbl, and read-only system conditions).
The dropped count is reported in _meta.skipped.builtin.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Ahendrix9624 <33384698+Ahendrix9624@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants