Repository navigation
Add Idira cloud connector - #26
Conversation
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
Pull request overview
Adds a new “Idira” cloud connector to the existing cloudconnectors bundle, matching the established connector pattern (provider auto-detection via env vars, per-connector collector config, and README-based env var documentation).
Changes:
- Added a new Idira connector configuration (
connectors/idira/config.yaml) that wires anidirareceiver into the standard Axoflow processing pipeline and exports tootlp_grpc/axorouter. - Added Idira connector documentation (
connectors/idira/README.md) plus root README environment variable documentation forIDIRA_*. - Updated
entrypoint.shand the rootREADME.mdconnector list to support provider auto-detection and navigation for Idira.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 2 comments.
| File | Description |
|---|---|
| README.md | Adds Idira connector link and documents IDIRA_* environment variables. |
| entrypoint.sh | Adds IDIRA_*-based provider auto-detection and help text. |
| connectors/idira/README.md | New connector guide (Quickstart, Helm usage, notes). |
| connectors/idira/config.yaml | New collector config using the idira receiver + standard Axoflow pipeline/exporter. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Add a connector that reads audit events from the Idira SIEM integration stream API via the idira receiver and forwards them to Axorouter. - connectors/idira/config.yaml: IDIRA_*-driven receiver (OAuth 2 client credentials plus SIEM API key, cursor-paged two-step stream API, poll checkpoint persisted to file_storage) wired through the standard axoflow processors to the otlp_grpc/axorouter exporter - entrypoint.sh: auto-detect the provider from IDIRA_* env vars - README + connector README: document the provider and its variables Note: requires the idira receiver to be present in the axoflow-otel-collector image. Signed-off-by: Szilard Parrag <szilard.parrag@axoflow.com> Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YAXW3c4FiPzXMxpigWx9sv
e087d0b to
ed2632b
Compare
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
📝 WalkthroughWalkthroughAdds an Idira connector with OTLP pipeline configuration, provider detection, persistent polling support, TLS and authentication settings, and Docker/Helm deployment documentation. ChangesIdira connector
Estimated code review effort: 2 (Simple) | ~10 minutes Sequence Diagram(s)sequenceDiagram
participant Entrypoint
participant IdiraReceiver
participant Processors
participant OTLPExporter
Entrypoint->>IdiraReceiver: select Idira from IDIRA_* configuration
IdiraReceiver->>Processors: emit polled audit log records
Processors->>OTLPExporter: enrich and export log records
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@connectors/idira/config.yaml`:
- Around line 82-84: The STORAGE_DIRECTORY default is inconsistent between
configuration and the Docker quickstart. In connectors/idira/config.yaml lines
82-84, add the documented fallback or explicitly fail when the variable is
absent; in connectors/idira/README.md lines 21-31, initialize STORAGE_DIRECTORY
to that same default before invoking Docker.
- Around line 51-53: The idira pipeline must use and validate a collector image
that contains the idira receiver, with a startup smoke test confirming it loads
successfully. Update connectors/idira/config.yaml:51-53 as needed for validation
and add the smoke test; update connectors/idira/README.md:32-32 to replace the
unverified :latest image reference with the verified receiver-bearing tag.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: ab629e18-881f-41a8-baba-b22b55402f07
📒 Files selected for processing (4)
README.mdconnectors/idira/README.mdconnectors/idira/config.yamlentrypoint.sh
Summary
Adds a cloud connector for the Idira SIEM integration stream API, following the same shape as the
Elasticsearch connector: an
IDIRA_*-driven receiver config wired through the standard axoflowprocessors to the
otlp_grpc/axorouterexporter, provider auto-detection inentrypoint.sh, anddocumentation of every variable in both READMEs.
The receiver authenticates with an OAuth 2 client credentials token from the Identity Administration
token endpoint plus the SIEM integration API key, opens a date-filtered query per poll and follows
the returned cursor page by page. The poll checkpoint is persisted to
file_storage, so restartsresume where they left off.
Based on axoflow/opentelemetry-collector-contrib#38.
Requires an image bump
The
idirareceiver is not in the current image(
axoflow-otel-collector:0.152.0-axoflow.2) — validating this config against it fails with'receivers' unknown type: "idira". Merging axoflow/opentelemetry-collector-contrib#38 and bumpingthe
Dockerfilebase image is a prerequisite for this connector to start.Test plan
connectors/idira/config.yamlparses;entrypoint.shdetectsIDIRA_*and routes to it${env:IDIRA_APPLICATION_CODES:-[]}really expands to a YAML list (checked againstthe collector's
resourcedetection.detectorswith[system,env]vs a bare scalar)axoflow-otel-collector validateon the full connector config — only remaining error is themissing
idirareceiver type🤖 Generated with Claude Code
https://claude.ai/code/session_01YAXW3c4FiPzXMxpigWx9sv
Summary by CodeRabbit
IDIRA_*environment variables.