brexhq / substation

Substation is a toolkit for routing, normalizing, and enriching security event and audit logs.
https://substation.readme.io
MIT License
330 stars 21 forks source link

feat: add support for formatting jsonnet with substation cli #250

Closed brittonhayes closed 1 month ago

brittonhayes commented 1 month ago

Description

This change adds support for running substation fmt against jsonnet and libsonnet files, automatically normalizing the format of substation configurations.

Motivation and Context

This change was added to continue making substation more approachable and easy to work with by enhancing the CLI that is used to manage and develop configurations. Right now the CLI supports building and testing. The addition of substation fmt adds a very small piece of that puzzle which is ensuring that all configuration is formatted the same way - this improves quality of life for teams managing many configs that are written by multiple developers.

How Has This Been Tested?

The CLI has been locally built and tested on example jsonnet and libsonnet files to verify functionality.

When running substation fmt, the output styling mimics that of go fmt, for consistency with the stylistic choices in substation test.

Write formatted changes to stdout.

> substation fmt examples/transform/aggregate/sample/config.jsonnet
// This example samples data by aggregating events into an array, then
// selecting the first event in the array as a sample. The sampling rate
// is 1/N, where N is the count of events in the buffer.
local sub = import '../../../../substation.libsonnet';

{
  tests: [
    {
      name: 'sample',
      transforms: [
        sub.tf.test.message({ value: { a: 'b' } }),
        sub.tf.test.message({ value: { c: 'd' } }),
        sub.tf.test.message({ value: { e: 'f' } }),
        sub.tf.test.message({ value: { g: 'h' } }),
        sub.tf.test.message({ value: { i: 'j' } }),
        sub.tf.test.message({ value: { k: 'l' } }),
        sub.tf.test.message({ value: { m: 'n' } }),
        sub.tf.test.message({ value: { o: 'p' } }),
        sub.tf.test.message({ value: { q: 'r' } }),
        sub.tf.test.message({ value: { s: 't' } }),
        sub.tf.test.message({ value: { u: 'v' } }),
        sub.tf.test.message({ value: { w: 'x' } }),
        sub.tf.test.message({ value: { y: 'z' } }),
        sub.tf.test.message({ value: ' ' }),
        sub.tf.send.stdout(),
      ],
      // Asserts that the message is '{"c":"d"}'.
      condition: sub.cnd.num.len.greater_than({ value: 0 }),
    },
  ],
  transforms: [
    // Events are aggregated into an array. This example has a sample
    // rate of up to 1/5. By default, the sample rate will be lower if
    // fewer than 5 events are processed by Substation.
    sub.tf.aggregate.to.array({ object: { target_key: 'meta sample' }, batch: { count: 5 } }),
    // A strict sample rate can be enforced by dropping any events that
    // contain the `sample` key, but do not have a length of 5.
    sub.tf.meta.switch(settings={ cases: [
      {
        condition: sub.cnd.num.len.eq({ object: { source_key: 'meta sample' }, value: 5 }),
        transforms: [
          sub.tf.object.copy({ object: { source_key: 'meta sample.0' } }),
        ],
      },
      {
        condition: sub.cnd.num.len.gt({ object: { source_key: 'meta sample' }, value: 0 }),
        transforms: [
          sub.tf.util.drop(),
        ],
      },
    ] }),
    sub.tf.obj.cp({ object: { source_key: 'meta sample.0' } }),
    sub.tf.send.stdout(),
  ],
}

Write formatted changes to the file.

> substation fmt -w examples/transform/aggregate/sample/config.jsonnet
examples/transform/aggregate/sample/config.jsonnet

Types of changes

Checklist: