Skip to content

ssi_all: use triple-brace templating in complex templates - Part 2 - #17623

Merged
kcreddy merged 1 commit into
elastic:mainfrom
kcreddy:triple-braces
Mar 5, 2026
Merged

kcreddy merged 1 commit into
elastic:mainfrom
kcreddy:triple-braces

Conversation

@kcreddy

@kcreddy kcreddy commented Mar 2, 2026 •

Copy link
Copy Markdown
Contributor

Proposed commit message

ssi_all: use triple-brace Mustache templating in ingest pipelines

Fix remaining double-brace Mustache template variables in ingest
pipelines for packages owned by elastic/security-service-integrations.

This is a follow-up to #11314 which addressed most packages but missed
some. Affected packages: admin_by_request_epm,
aws_securityhub, beyondinsight_password_safe, bitsight, cloudflare,
cloudflare_logpush, google_workspace, m365_defender,
microsoft_exchange_online_message_trace, rapid7_insightvm,
sentinel_one, tenable_ot_security, ti_cif3.

Relates: #7641

[git-generate]
for f in $(
	(
		for p in $(
			for f in packages/*/manifest.yml; do
				if yq -e 'select(.owner.github == "elastic/security-service-integrations")' "$f" >/dev/null 2>&1; then
					dirname "$f"
				fi
			done
		); do
			rg -l '(^|[^{])\{\{[^{][ .a-zA-Z0-9_]*[^}]\}\}($|[^}])' -g '*.yml' "$p" || true
		done
	)|grep "elasticsearch/ingest_pipeline"|sort|uniq
); do
	perl -pi -e 's/(?<!\{)(\{\{[^{][ .a-zA-Z0-9_]*[^}]}})(?!\})/{$1}/g' $f
done
for p in $(git diff --name-only HEAD~1|cut -d/ -f1,2|sort|uniq); do
	(
		cd $p
		elastic-package test pipeline -g
		elastic-package changelog add \
			--description "Use triple-brace Mustache templating when referencing variables in ingest pipelines." \
			--type bugfix \
			--next patch \
			--link https://github.com/elastic/integrations/pull/17623
	)>/dev/null 2>&1
done

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

@kcreddy kcreddy self-assigned this Mar 2, 2026
@kcreddy
kcreddy marked this pull request as ready for review March 2, 2026 16:40
@kcreddy
kcreddy requested a review from a team as a code owner March 2, 2026 16:40
@kcreddy kcreddy added Integration:google_workspace Google Workspace Integration:cloudflare Cloudflare Integration:sentinel_one SentinelOne Integration:m365_defender Microsoft Defender XDR Integration:microsoft_exchange_online_message_trac Microsoft Exchange Online Message Trace Integration:cloudflare_logpush Cloudflare Logpush Integration:ti_cif3 Collective Intelligence Framework v3 (Community supported) Integration:rapid7_insightvm Rapid7 InsightVM Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Integration:beyondinsight_password_safe BeyondInsight and Password Safe Integration:admin_by_request_epm Admin By Request EPM Integration:tenable_ot_security Tenable OT Security Integration:aws_securityhub AWS Security Hub Integration:bitsight Bitsight (Partner supported) labels Mar 2, 2026
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@kcreddy kcreddy added bugfix Pull request that fixes a bug issue Category: Integration quality Category: Quality used for SI planning labels Mar 2, 2026
@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Mar 2, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When I squash the four commits into one and give it the commit message that's proposed (with the PR number added), we don't get exactly what is here. There are some inconsequential YAML and whitespace changes, but there is also a reversion of the ti_cif3 changes. Can you check that?

In cases where git-generate is used, I'd recommend keeping the PR as a single commit so that the state in the PR is essentially as it will be once it's merged.

@kcreddy
kcreddy force-pushed the triple-braces branch 2 times, most recently from f71a073 to 6d59d01 Compare March 3, 2026 12:14
@kcreddy

kcreddy commented Mar 3, 2026 •

Copy link
Copy Markdown
Contributor Author

When I squash the four commits into one and give it the commit message that's proposed (with the PR number added), we don't get exactly what is here. There are some inconsequential YAML and whitespace changes, but there is also a reversion of the ti_cif3 changes. Can you check that?

In cases where git-generate is used, I'd recommend keeping the PR as a single commit so that the state in the PR is essentially as it will be once it's merged.

@efd6, the problem was rg wasn't identifying ti_cif3 file because the original pattern uses [^}] after }} which requires a character to exist, missing cases where }} is at the end of a line. I updated the rg regex to match with perl regex to support lookarounds. Now ti_cif3 is included.
I also retained the whitespace and yaml formatting changes that are being done by elastic-package test pipeline and elastic-package changelog add and squashed into single commit.

@kcreddy
kcreddy requested a review from efd6 March 3, 2026 12:20

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please use

ssi_all: use triple-brace Mustache templating in ingest pipelines

Fix remaining double-brace Mustache template variables in ingest
pipelines for packages owned by elastic/security-service-integrations.

This is a follow-up to #11314 which addressed most packages but missed
some. Affected packages: admin_by_request_epm,
aws_securityhub, beyondinsight_password_safe, bitsight, cloudflare,
cloudflare_logpush, google_workspace, m365_defender,
microsoft_exchange_online_message_trace, rapid7_insightvm,
sentinel_one, tenable_ot_security, ti_cif3.

Relates: #7641

[git-generate]
for f in $(
	(
		for p in $(
			for f in packages/*/manifest.yml; do
				if yq -e 'select(.owner.github == "elastic/security-service-integrations")' "$f" >/dev/null 2>&1; then
					dirname "$f"
				fi
			done
		); do
			rg -l '(^|[^{])\{\{[^{][ .a-zA-Z0-9_]*[^}]\}\}($|[^}])' -g '*.yml' "$p" || true
		done
	)|grep "elasticsearch/ingest_pipeline"|sort|uniq
); do
	perl -pi -e 's/(?<!\{)(\{\{[^{][ .a-zA-Z0-9_]*[^}]}})(?!\})/{$1}/g' $f
done
for p in $(git diff --name-only HEAD~1|cut -d/ -f1,2|sort|uniq); do
	(
		cd $p
		elastic-package test pipeline -g
		elastic-package changelog add \
			--description "Use triple-brace Mustache templating when referencing variables in ingest pipelines." \
			--type bugfix \
			--next patch \
			--link https://github.com/elastic/integrations/pull/17623
	)>/dev/null 2>&1
done

This does not depend on PCRE and fixes the missing issue number. You can rebase this onto main and use the -conflict flag in git generate when you get to conflicts during the rebase.

Fix remaining double-brace Mustache template variables in ingest
pipelines for packages owned by elastic/security-service-integrations.

This is a follow-up to elastic#11314 which addressed most packages but missed
some. Affected packages: admin_by_request_epm,
aws_securityhub, beyondinsight_password_safe, bitsight, cloudflare,
cloudflare_logpush, google_workspace, m365_defender,
microsoft_exchange_online_message_trace, rapid7_insightvm,
sentinel_one, tenable_ot_security, ti_cif3.

Relates: elastic#7641

[git-generate]
for f in $(
	(
		for p in $(
			for f in packages/*/manifest.yml; do
				if yq -e 'select(.owner.github == "elastic/security-service-integrations")' "$f" >/dev/null 2>&1; then
					dirname "$f"
				fi
			done
		); do
			rg -l '(^|[^{])\{\{[^{][ .a-zA-Z0-9_]*[^}]\}\}($|[^}])' -g '*.yml' "$p" || true
		done
	)|grep "elasticsearch/ingest_pipeline"|sort|uniq
); do
	perl -pi -e 's/(?<!\{)(\{\{[^{][ .a-zA-Z0-9_]*[^}]}})(?!\})/{$1}/g' $f
done
for p in $(git diff --name-only HEAD~1|cut -d/ -f1,2|sort|uniq); do
	(
		cd $p
		elastic-package test pipeline -g
		elastic-package changelog add \
			--description "Use triple-brace Mustache templating when referencing variables in ingest pipelines." \
			--type bugfix \
			--next patch \
			--link elastic#17623
	)>/dev/null 2>&1
done
@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @kcreddy

@kcreddy
kcreddy requested a review from efd6 March 4, 2026 09:14
@kcreddy
kcreddy merged commit 6b441ed into elastic:main Mar 5, 2026
9 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package admin_by_request_epm - 1.1.2 containing this change is available at https://epr.elastic.co/package/admin_by_request_epm/1.1.2/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package aws_securityhub - 0.2.1 containing this change is available at https://epr.elastic.co/package/aws_securityhub/0.2.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package beyondinsight_password_safe - 0.12.3 containing this change is available at https://epr.elastic.co/package/beyondinsight_password_safe/0.12.3/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package bitsight - 0.1.1 containing this change is available at https://epr.elastic.co/package/bitsight/0.1.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package cloudflare - 2.32.1 containing this change is available at https://epr.elastic.co/package/cloudflare/2.32.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package cloudflare_logpush - 1.43.3 containing this change is available at https://epr.elastic.co/package/cloudflare_logpush/1.43.3/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package google_workspace - 3.3.1 containing this change is available at https://epr.elastic.co/package/google_workspace/3.3.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package m365_defender - 5.10.1 containing this change is available at https://epr.elastic.co/package/m365_defender/5.10.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package microsoft_exchange_online_message_trace - 2.0.1 containing this change is available at https://epr.elastic.co/package/microsoft_exchange_online_message_trace/2.0.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package rapid7_insightvm - 2.6.1 containing this change is available at https://epr.elastic.co/package/rapid7_insightvm/2.6.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package sentinel_one - 2.4.1 containing this change is available at https://epr.elastic.co/package/sentinel_one/2.4.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package tenable_ot_security - 1.0.1 containing this change is available at https://epr.elastic.co/package/tenable_ot_security/1.0.1/

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package ti_cif3 - 1.18.2 containing this change is available at https://epr.elastic.co/package/ti_cif3/1.18.2/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Pull request that fixes a bug issue Category: Integration quality Category: Quality used for SI planning Integration:admin_by_request_epm Admin By Request EPM Integration:aws_securityhub AWS Security Hub Integration:beyondinsight_password_safe BeyondInsight and Password Safe Integration:bitsight Bitsight (Partner supported) Integration:cloudflare_logpush Cloudflare Logpush Integration:cloudflare Cloudflare Integration:google_workspace Google Workspace Integration:m365_defender Microsoft Defender XDR Integration:microsoft_exchange_online_message_trac Microsoft Exchange Online Message Trace Integration:rapid7_insightvm Rapid7 InsightVM Integration:sentinel_one SentinelOne Integration:tenable_ot_security Tenable OT Security Integration:ti_cif3 Collective Intelligence Framework v3 (Community supported) Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

{cloudflare_logpush,m365_defender,sentinel_one}: incorrect mustache snippet escaping

3 participants