{"record":{"id":"092bae002ea75442","repo":"vectordotdev/vector","slug":"could-not-build-datadog-domain-regex","errorCode":null,"errorMessage":"Could not build Datadog domain regex","messagePattern":"Could not build Datadog domain regex","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/common/datadog.rs","lineNumber":112,"sourceCode":"\n/// Gets the base API endpoint to use for any calls to Datadog.\n///\n/// If `endpoint` is not specified, we fallback to `site`.\npub(crate) fn get_api_base_endpoint(endpoint: Option<&str>, site: &str) -> String {\n    endpoint.map_or_else(|| format!(\"https://api.{site}\"), compute_api_endpoint)\n}\n\n/// Computes the Datadog API endpoint from a given endpoint string.\n///\n/// This scans the given endpoint for the common Datadog domain names; and, if found, rewrites the\n/// endpoint string using the standard API URI. If not found, the endpoint is used as-is.\nfn compute_api_endpoint(endpoint: &str) -> String {\n    // This mechanism is derived from the forwarder health check in the Datadog Agent:\n    // https://github.com/DataDog/datadog-agent/blob/cdcf0fc809b9ac1cd6e08057b4971c7dbb8dbe30/comp/forwarder/defaultforwarder/forwarder_health.go#L45-L47\n    // https://github.com/DataDog/datadog-agent/blob/cdcf0fc809b9ac1cd6e08057b4971c7dbb8dbe30/comp/forwarder/defaultforwarder/forwarder_health.go#L188-L190\n    static DOMAIN_REGEX: LazyLock<Regex> = LazyLock::new(|| {\n        Regex::new(r\"((?:[a-z]{2}\\d\\.)?(?:datadoghq\\.[a-z]+|ddog-gov\\.com))/*$\")\n            .expect(\"Could not build Datadog domain regex\")\n    });\n\n    if let Some(caps) = DOMAIN_REGEX.captures(endpoint) {\n        format!(\"https://api.{}\", &caps[1])\n    } else {\n        endpoint.into()\n    }\n}\n\n/// Default settings to use for Datadog components.\n#[derive(Clone, Debug, Derivative)]\n#[derivative(Default)]\npub struct Options {\n    /// Default Datadog API key to use for Datadog components.\n    ///\n    /// This can also be specified with the `DD_API_KEY` environment variable.\n    #[derivative(Default(value = \"default_api_key()\"))]\n    pub api_key: Option<SensitiveString>,","sourceCodeStart":94,"sourceCodeEnd":130,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/src/common/datadog.rs#L94-L130","documentation":"`compute_api_endpoint` builds a Datadog API endpoint by matching a static regex against the configured site/domain. The regex is compiled once via LazyLock with `expect`, so if the (hardcoded, constant) pattern were invalid the process panics with 'Could not build Datadog domain regex'. In practice this panic means a static regex literal is broken — an internal invariant, not user input.","triggerScenarios":"First use of the Datadog common endpoint computation (e.g. configuring any Datadog sink) triggers LazyLock regex compilation; panic only occurs if the hardcoded pattern is invalid, e.g. after a bad edit or dependency regression in the `regex` crate.","commonSituations":"Editing the regex constant and introducing a syntax error; a broken `regex` dependency build with compile-time feature changes.","solutions":["If you edited the regex literal, validate it with regex101 or a unit test and fix the syntax","Run `cargo tree -p regex` and check for an unusual dependency version; pin a stable regex version","Update Vector; this panic indicates a source-level bug that should be reported"],"exampleFix":"// before\nRegex::new(r\"((?:[a-z]{2}\\d\\.)?(?:datadoghq\\.[a-z]+|ddog-gov\\.com))/*$\")\n    .expect(\"Could not build Datadog domain regex\")\n// after (during development/testing)\nRegex::new(r\"((?:[a-z]{2}\\d\\.)?(?:datadoghq\\.[a-z]+|ddog-gov\\.com))/*$\")\n    .unwrap_or_else(|e| panic!(\"invalid Datadog domain regex: {e}\"))","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Static regexes should be tested at CI time:\n#[test]\nfn datadog_domain_regex_valid() {\n    regex::Regex::new(r\"((?:[a-z]{2}\\d\\.)?(?:datadoghq\\.[a-z]+|ddog-gov\\.com))/*$\").unwrap();\n}","preventionTips":["Cover static regex compilation with a unit test","Run clippy/tests after editing any regex literal","Validate regex syntax with a linter or regex101 before committing"],"tags":["rust","regex","datadog","panic"],"backgroundTag":"invalid-regex-pattern","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}