Skip to content

feat: recognise the netflow source type - #301

Open
amegz wants to merge 1 commit into
kaasops:mainfrom
amegz:feat/netflow-source-type
Open

amegz wants to merge 1 commit into
kaasops:mainfrom
amegz:feat/netflow-source-type

Conversation

@amegz

@amegz amegz commented Oct 8, 2026

Copy link
Copy Markdown

Summary

Adds netflow to the source types the operator knows, and publishes its Service port as UDP.

Two things are wrong today for a pipeline that uses a netflow source:

  1. netflow is on neither aggregatorTypes nor agentTypes, so the pipeline is marked invalid with
    unsupported source type: netflow.
  2. The protocol of a source's Service port comes from its mode option (extractProtocol). netflow is UDP-only and
    has no mode, so even with the role pinned the port would be published as TCP.

The change:

  • NetflowType is added to aggregatorTypes (a network listener, it belongs on an aggregator).
  • A small udpOnlyTypes set lists the sources that are UDP regardless of their options, and extractProtocol now takes the
    source type as well as its options. Behaviour for every other type is unchanged (mode: udp still selects UDP).

Note on the source itself

The netflow source is not in a released Vector yet: it is the open PR vectordotdev/vector#24628 (NetFlow v5 over UDP,
the first of a planned series). This change only registers the type, so that the operator does not reject the config once
a Vector that has the source is used. I understand if you would rather wait until the source is released; I have been
running this together with a Vector build that includes that PR.

It is complementary to #283: spec.role lets a pipeline with an unlisted source type through, but the Service port of a
UDP-only source still needs to be UDP, which is what udpOnlyTypes is for.

How did you test this PR?

  • Unit tests in internal/config/netflow_source_test.go: extractProtocol for netflow, syslog with mode: udp / tcp
    and vector; VectorRole() of a netflow pipeline is aggregator. go test ./internal/config/... passes.
  • On a dev AKS cluster: a VectorAggregator with a netflow pipeline (two sources on UDP 2055 and 2056) became valid, the
    operator created a Service with 2055/UDP,2056/UDP, and flow records sent to those ports reached the sink.

🤖 Generated with Claude Code

Register `netflow` as an aggregator source type and create its Service port as UDP.

- aggregatorTypes: a pipeline whose source is `netflow` gets the aggregator role instead of failing with
  "unsupported source type: netflow".
- extractProtocol: the protocol of the Service port was taken from the `mode` option of the source, which only some
  sources have. `netflow` listens on UDP and has no such option, so its port was published as TCP. Sources listed in
  udpOnlyTypes are UDP regardless of their options.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant