Bypass scheme filtering for metric registrar - #728
Merged
Conversation
As the validation is done centrally, all schemes which are used by the downstream consumers of the Syslog Binding Cache have to be defined centrally. At the moment we have the Syslog Agent and the TAS Metric Registrar as consumers. All schemes a part from "secure-endpoint", "metrics-endpoint", "structured-format" belong to the Syslog Agent. If a particular downstream consumer doesn't support some scheme, it should handle the validation itself
c62111f added secure-endpoint/metrics-endpoint/structured-format to allowedSchemes so non-syslog CUPS bindings (e.g. TAS Metric Registrar's documented tagging convention) aren't dropped from the shared /v2/bindings store. However, checkBindings still ran the syslog-drain network validations (hostname presence, log type filters, DNS resolution, IP blacklist) on these bindings too, which don't apply since they're used as opaque discovery tags rather than real drain endpoints - e.g. "metrics-endpoint:///metrics" has no host at all, and "structured-format://DogStatsD"'s host segment is not a resolvable DNS name. Both still got rejected, just with a different error. Skip those network checks for schemes in the new nonNetworkSchemes list; credential validation still applies to all schemes. Adds regression tests reproducing the exact URL shapes from the bug report (cloudfoundry#727).
chombium
approved these changes
Aug 14, 2026
chombium
left a comment
Contributor
There was a problem hiding this comment.
Thanks for the fix @weili-broadcom
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Please include a summary of the change.
Fixes #727
Type of change
Testing performed?
Checklist:
mainbranch, or relevant version branchIf you have any questions, or want to get attention for a PR or issue please reach out on the #logging-and-metrics channel in the cloudfoundry slack