fix: correct 8 group-scoped resource API paths - #2
Merged
Merged
Conversation
Eight group-scoped resources used endpoint paths that return HTTP 404 on Cribl 4.17.1 (verified live against a real Leader). The originals were inconsistent — some under system/, one with no library prefix, two with a nested lib/sds/... segment, and several with abbreviated names — so the commands built from them could never reach the API. parsers system/parsers -> lib/parsers schemas schemas -> lib/schemas db-connections lib/db-connections -> lib/database-connections conditions lib/conditions -> conditions sds-rules lib/sds/rules -> lib/sds-rules sds-rulesets lib/sds/rulesets -> lib/sds-rulesets appscope lib/appscope -> lib/appscope-configs hmac-functions lib/hmac -> lib/hmac-functions registry.py drives every factory-generated CRUD command, so this also repairs the existing `cribl parsers list`, `schemas`, `sds-rules`, `appscope`, etc. commands — not just the new group export/import that surfaced the problem.
JacobPEvans-personal
force-pushed
the
fix/registry-group-paths
branch
from
June 21, 2026 18:20
fd97bfb to
f9beae9
Compare
JacobPEvans-personal
added a commit
that referenced
this pull request
Jun 21, 2026
Add a `groups` command that moves an entire worker group's or edge fleet's config between groups (a fleet is the same API object with `isFleet: true`, so both flow through one path): - `groups export <group>` pulls every group-scoped resource to stdout, or `--out-dir` writes one file per resource type (dir/files locked to 0700/0600). - `groups import <group>` upserts the config back. It is staged, never deployed: routes are skipped unless `--with-routes`, and `--deploy` requires `--yes`. - Secrets, credentials, and certificates are excluded unless `--include-sensitive`; everything skipped or failed is reported in `_meta`. - Import honors each resource type's registry operations: read-only types (executors, hmac-functions, functions) are skipped and create-only types without `update` (certificates, samples, scripts) are created, not PATCHed. The resource list is derived from `commands/registry.py` plus the hand-written sources/destinations/pipelines/packs/routes, so it never drifts from the rest of the CLI. Route import uses a new public `replace_route_table()` helper in `api/endpoints/routes.py` (wholesale swap, preserving edge/stream format). Depends on the registry path corrections in #2 (the export/import surfaced the 404s those fix).
JacobPEvans-personal
marked this pull request as draft
June 21, 2026 18:32
There was a problem hiding this comment.
Pull request overview
Fixes incorrect Cribl API endpoint paths for several group-scoped factory-generated CRUD commands by updating commands/registry.py to use paths that are valid on Cribl 4.17.1 (per PR description), preventing 404s for affected commands.
Changes:
- Corrected registry endpoint paths for 8 group-scoped resources (e.g.,
parsers,schemas,sds-rules,appscope,hmac-functions). - Standardized several paths under the appropriate
lib/…namespace and corrected resource naming (e.g.,database-connections,appscope-configs).
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
JacobPEvans-personal
marked this pull request as ready for review
June 21, 2026 22:25
werd-drew
approved these changes
Jun 25, 2026
werd-drew
left a comment
Contributor
There was a problem hiding this comment.
Approved. Verified live against our Leader (Cribl Cloud, group default): all 8 affected commands returned 404 on main and 200 on this branch — parsers, schemas, db-connections, conditions, sds-rules, sds-rulesets, appscope, hmac-functions. Tight, registry-only change that repairs genuinely broken CRUD commands. 🚢
werd-drew
added a commit
that referenced
this pull request
Jun 25, 2026
…#1) * fix: correct 8 group-scoped resource API paths Eight group-scoped resources used endpoint paths that return HTTP 404 on Cribl 4.17.1 (verified live against a real Leader). The originals were inconsistent — some under system/, one with no library prefix, two with a nested lib/sds/... segment, and several with abbreviated names — so the commands built from them could never reach the API. parsers system/parsers -> lib/parsers schemas schemas -> lib/schemas db-connections lib/db-connections -> lib/database-connections conditions lib/conditions -> conditions sds-rules lib/sds/rules -> lib/sds-rules sds-rulesets lib/sds/rulesets -> lib/sds-rulesets appscope lib/appscope -> lib/appscope-configs hmac-functions lib/hmac -> lib/hmac-functions registry.py drives every factory-generated CRUD command, so this also repairs the existing `cribl parsers list`, `schemas`, `sds-rules`, `appscope`, etc. commands — not just the new group export/import that surfaced the problem. * feat: add whole-group export/import for worker groups and edge fleets Add a `groups` command that moves an entire worker group's or edge fleet's config between groups (a fleet is the same API object with `isFleet: true`, so both flow through one path): - `groups export <group>` pulls every group-scoped resource to stdout, or `--out-dir` writes one file per resource type (dir/files locked to 0700/0600). - `groups import <group>` upserts the config back. It is staged, never deployed: routes are skipped unless `--with-routes`, and `--deploy` requires `--yes`. - Secrets, credentials, and certificates are excluded unless `--include-sensitive`; everything skipped or failed is reported in `_meta`. - Import honors each resource type's registry operations: read-only types (executors, hmac-functions, functions) are skipped and create-only types without `update` (certificates, samples, scripts) are created, not PATCHed. The resource list is derived from `commands/registry.py` plus the hand-written sources/destinations/pipelines/packs/routes, so it never drifts from the rest of the CLI. Route import uses a new public `replace_route_table()` helper in `api/endpoints/routes.py` (wholesale swap, preserving edge/stream format). Depends on the registry path corrections in #2 (the export/import surfaced the 404s those fix). * fix: address Copilot review on group export/import - write_dir() clears stale *.json from a prior export before writing, so a secrets.json left by an earlier --include-sensitive run can't linger and be re-imported by read_input(). - Narrow the "never replace the route table wholesale" rule in CLAUDE.md to note that `groups import --with-routes` is the deliberate, gated exception. - Add unit tests for replace_route_table() (stream + edge wrapper) and for write_dir() stale-file cleanup. * feat(groups): drop built-in and pack-owned resources from export Whole-group export captured Cribl-shipped library content (lib == "cribl"), built-in system objects (destroyable false), and pack-owned items (id prefixed "pack:") because they appear in list responses. None are writable as standalone group config, so importing them produced hundreds of 4xx/5xx errors. Filter them at export so the payload is only user-authored config. Verified live: a real group's import failures dropped from ~300 to ~14 (the remainder being pack archives, which need the .crbl, and read-only system conditions). The dropped count is reported in _meta.skipped.builtin. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Ahendrix9624 <33384698+Ahendrix9624@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Eight group-scoped resources in
commands/registry.pyused endpoint paths thatreturn HTTP 404 on Cribl 4.17.1 (verified live against a real Leader). The
original paths were inconsistent — some under
system/, one with no libraryprefix, two with a nested
lib/sds/...segment, and several with abbreviatednames — so any command built from them could never reach the API.
Changes
system/parserslib/parsersschemaslib/schemaslib/db-connectionslib/database-connectionslib/conditionsconditionslib/sds/ruleslib/sds-ruleslib/sds/rulesetslib/sds-rulesetslib/appscopelib/appscope-configslib/hmaclib/hmac-functionsregistry.pydrives every factory-generated CRUD command, so this also repairsthe existing
cribl parsers list,schemas,sds-rules,appscope, etc.commands — not just the new group export/import (#1) that surfaced the problem.
Test Plan
pytest -m "not integration"— 133 unit tests pass (no regression).--dry-run(no live creds needed), e.g.cribl --dry-run parsers list -g GRPnow emitsGET /api/v1/m/GRP/lib/parsers; confirmed for all eight.cribl parsers list,cribl schemas list,cribl sds-rules listandverify they return 200, not 404. (This repo has no CI.)
🤖 Generated with Claude Code