Skip to content

Add Idira cloud connector - #26

Merged
OverOrion merged 1 commit into
mainfrom
feat/add-idirareceiver
Jul 30, 2026
Merged

OverOrion merged 1 commit into
mainfrom
feat/add-idirareceiver

Conversation

@OverOrion

@OverOrion OverOrion commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a cloud connector for the Idira SIEM integration stream API, following the same shape as the
Elasticsearch connector: an IDIRA_*-driven receiver config wired through the standard axoflow
processors to the otlp_grpc/axorouter exporter, provider auto-detection in entrypoint.sh, and
documentation of every variable in both READMEs.

The receiver authenticates with an OAuth 2 client credentials token from the Identity Administration
token endpoint plus the SIEM integration API key, opens a date-filtered query per poll and follows
the returned cursor page by page. The poll checkpoint is persisted to file_storage, so restarts
resume where they left off.

Based on axoflow/opentelemetry-collector-contrib#38.

Requires an image bump

The idira receiver is not in the current image
(axoflow-otel-collector:0.152.0-axoflow.2) — validating this config against it fails with
'receivers' unknown type: "idira". Merging axoflow/opentelemetry-collector-contrib#38 and bumping
the Dockerfile base image is a prerequisite for this connector to start.

Test plan

  • connectors/idira/config.yaml parses; entrypoint.sh detects IDIRA_* and routes to it
  • Verified ${env:IDIRA_APPLICATION_CODES:-[]} really expands to a YAML list (checked against
    the collector's resourcedetection.detectors with [system,env] vs a bare scalar)
  • axoflow-otel-collector validate on the full connector config — only remaining error is the
    missing idira receiver type
  • After the image bump: run against a live Idira tenant and confirm audit events reach Axorouter

🤖 Generated with Claude Code

https://claude.ai/code/session_01YAXW3c4FiPzXMxpigWx9sv

Summary by CodeRabbit

  • New Features
    • Added support for the Idira connector, including API polling, OAuth authentication, filtering, pagination, TLS, retries, and persistent checkpoints.
    • Added Docker and Helm deployment guidance for configuring the connector.
    • Added Idira provider detection through IDIRA_* environment variables.
  • Documentation
    • Added comprehensive Idira configuration, quickstart, deployment, and operational notes.
    • Documented Idira-specific environment variables and TLS settings.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new “Idira” cloud connector to the existing cloudconnectors bundle, matching the established connector pattern (provider auto-detection via env vars, per-connector collector config, and README-based env var documentation).

Changes:

  • Added a new Idira connector configuration (connectors/idira/config.yaml) that wires an idira receiver into the standard Axoflow processing pipeline and exports to otlp_grpc/axorouter.
  • Added Idira connector documentation (connectors/idira/README.md) plus root README environment variable documentation for IDIRA_*.
  • Updated entrypoint.sh and the root README.md connector list to support provider auto-detection and navigation for Idira.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.

File Description
README.md Adds Idira connector link and documents IDIRA_* environment variables.
entrypoint.sh Adds IDIRA_*-based provider auto-detection and help text.
connectors/idira/README.md New connector guide (Quickstart, Helm usage, notes).
connectors/idira/config.yaml New collector config using the idira receiver + standard Axoflow pipeline/exporter.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread README.md Outdated
Comment thread connectors/idira/README.md Outdated
Add a connector that reads audit events from the Idira SIEM integration
stream API via the idira receiver and forwards them to Axorouter.

- connectors/idira/config.yaml: IDIRA_*-driven receiver (OAuth 2 client
  credentials plus SIEM API key, cursor-paged two-step stream API, poll
  checkpoint persisted to file_storage) wired through the standard
  axoflow processors to the otlp_grpc/axorouter exporter
- entrypoint.sh: auto-detect the provider from IDIRA_* env vars
- README + connector README: document the provider and its variables

Note: requires the idira receiver to be present in the
axoflow-otel-collector image.

Signed-off-by: Szilard Parrag <szilard.parrag@axoflow.com>

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YAXW3c4FiPzXMxpigWx9sv
@OverOrion
OverOrion force-pushed the feat/add-idirareceiver branch from e087d0b to ed2632b Compare July 30, 2026 15:39

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds an Idira connector with OTLP pipeline configuration, provider detection, persistent polling support, TLS and authentication settings, and Docker/Helm deployment documentation.

Changes

Idira connector

Layer / File(s) Summary
Idira receiver pipeline
connectors/idira/config.yaml
Configures the Idira receiver, resource enrichment, persistent file storage, health checking, TLS, and OTLP gRPC export.
Provider detection
entrypoint.sh
Detects IDIRA_* configuration and lists Idira in provider setup guidance.
Quickstart and configuration documentation
README.md, connectors/idira/README.md
Documents Idira environment variables, TLS settings, authentication, polling behavior, Docker and Helm deployment, and operational notes.

Estimated code review effort: 2 (Simple) | ~10 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Entrypoint
  participant IdiraReceiver
  participant Processors
  participant OTLPExporter
  Entrypoint->>IdiraReceiver: select Idira from IDIRA_* configuration
  IdiraReceiver->>Processors: emit polled audit log records
  Processors->>OTLPExporter: enrich and export log records
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the main change: adding the Idira cloud connector.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/add-idirareceiver

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@connectors/idira/config.yaml`:
- Around line 82-84: The STORAGE_DIRECTORY default is inconsistent between
configuration and the Docker quickstart. In connectors/idira/config.yaml lines
82-84, add the documented fallback or explicitly fail when the variable is
absent; in connectors/idira/README.md lines 21-31, initialize STORAGE_DIRECTORY
to that same default before invoking Docker.
- Around line 51-53: The idira pipeline must use and validate a collector image
that contains the idira receiver, with a startup smoke test confirming it loads
successfully. Update connectors/idira/config.yaml:51-53 as needed for validation
and add the smoke test; update connectors/idira/README.md:32-32 to replace the
unverified :latest image reference with the verified receiver-bearing tag.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: ab629e18-881f-41a8-baba-b22b55402f07

📥 Commits

Reviewing files that changed from the base of the PR and between 6ed99e6 and ed2632b.

📒 Files selected for processing (4)
  • README.md
  • connectors/idira/README.md
  • connectors/idira/config.yaml
  • entrypoint.sh

Comment thread connectors/idira/config.yaml
Comment thread connectors/idira/config.yaml
@OverOrion
OverOrion merged commit 0bee085 into main Jul 30, 2026
3 checks passed
@OverOrion
OverOrion deleted the feat/add-idirareceiver branch July 30, 2026 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants