Skip to content

Feat/siem s3 dual sink - #219

Closed
gitteroy wants to merge 6 commits into
grafana:mainfrom
rswiftoffice:feat/siem-s3-dual-sink
Closed

gitteroy wants to merge 6 commits into
grafana:mainfrom
rswiftoffice:feat/siem-s3-dual-sink

Conversation

@gitteroy

Copy link
Copy Markdown

No description provided.

…tput

ScratchBuilder.Labels() returns labels in Go map iteration order (random),
but relabel.Process requires sorted input. Without builder.Sort(), relabel
rules match non-deterministically and ~40-50% of entries reach Loki with
renamed labels missing. Adds builder.Sort() plus a 1000-iteration regression
test that fails without the fix.
A multi-record S3 source (e.g. CloudTrail) whose total size is a clean
multiple of batchSize leaves an empty final batch. Sending an empty
PushRequest makes Loki return a non-retryable 422, sending the whole SQS
message to the DLQ. Guards sendToPromtail to skip zero-entry batches. Adds
a behavioral test asserting no HTTP request is issued for an empty batch
(fails if the guard is removed).
fork-release.yml builds the linux/amd64 bootstrap binary, packages a
Lambda-ready zip + sha256, and publishes a GitHub release on v*-sortfix.*
tags. Upstream release.yml is switched to workflow_dispatch-only because it
pushes to grafanalabs S3 buckets we can't access and would otherwise fire on
our v* tags.
Add an S3 sink (pkg/s3_sink.go) that, when SIEM_S3_BUCKET is set, writes each
batch's raw log lines (gzipped, time-partitioned) to a central SIEM bucket IN
ADDITION to the Loki push. Implemented via a multiSink wrapping the existing
promtailClient: Loki stays the primary/authoritative sink (governs retry/DLQ),
the S3 sink is best-effort so a SIEM-side failure never blocks Loki delivery.

Opt-in: no SIEM_S3_BUCKET = unchanged Loki-only behavior. Uses ambient IRSA
credentials. No new dependencies (aws-sdk-go-v2 config+s3 already vendored).
@github-actions

Copy link
Copy Markdown

Signed commits report

6 of 6 commits between main and feat/siem-s3-dual-sink could not be fully verified:

Commit Author Reason Message
d4b5dcb1 gitteroy unsigned fix(relabel): sort labels before relabel.Process for deterministic output
97ee2d98 gitteroy unsigned fix(s3): skip empty batch send to prevent CloudTrail 422 DLQ failures
5715481d gitteroy unsigned ci: add fork-release workflow; disable upstream release.yml
0956e50b gitteroy unsigned test(s3): rename unused RoundTrip param to _ (revive lint)
89e67cc0 gitteroy unsigned ci: add upstream-drift check that opens a rebase issue on new upstream releases
fcafef3c gitteroy unsigned feat(siem): optional S3 dual-sink for security log feed

This repository requires all commits to be signed. See GitHub docs on commit signature verification.

@gitteroy gitteroy closed this Sep 25, 2026
@cla-assistant

cla-assistant Bot commented Sep 25, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

1 similar comment
@cla-assistant

cla-assistant Bot commented Sep 25, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant