vectordotdev/vector · error

Could not build Datadog domain regex

Error message

Could not build Datadog domain regex

What it means

`compute_api_endpoint` builds a Datadog API endpoint by matching a static regex against the configured site/domain. The regex is compiled once via LazyLock with `expect`, so if the (hardcoded, constant) pattern were invalid the process panics with 'Could not build Datadog domain regex'. In practice this panic means a static regex literal is broken — an internal invariant, not user input.

Solutions

  1. If you edited the regex literal, validate it with regex101 or a unit test and fix the syntax
  2. Run `cargo tree -p regex` and check for an unusual dependency version; pin a stable regex version
  3. Update Vector; this panic indicates a source-level bug that should be reported

Example fix

// before
Regex::new(r"((?:[a-z]{2}\d\.)?(?:datadoghq\.[a-z]+|ddog-gov\.com))/*$")
    .expect("Could not build Datadog domain regex")
// after (during development/testing)
Regex::new(r"((?:[a-z]{2}\d\.)?(?:datadoghq\.[a-z]+|ddog-gov\.com))/*$")
    .unwrap_or_else(|e| panic!("invalid Datadog domain regex: {e}"))
Defensive patterns

Strategy: try-catch

Try / catch

// Static regexes should be tested at CI time:
#[test]
fn datadog_domain_regex_valid() {
    regex::Regex::new(r"((?:[a-z]{2}\d\.)?(?:datadoghq\.[a-z]+|ddog-gov\.com))/*$").unwrap();
}

Prevention

When it happens

Trigger: First use of the Datadog common endpoint computation (e.g. configuring any Datadog sink) triggers LazyLock regex compilation; panic only occurs if the hardcoded pattern is invalid, e.g. after a bad edit or dependency regression in the `regex` crate.

Common situations: Editing the regex constant and introducing a syntax error; a broken `regex` dependency build with compile-time feature changes.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/092bae002ea75442. Report an issue: GitHub.

Appendix: source

Thrown at src/common/datadog.rs:112

/// Gets the base API endpoint to use for any calls to Datadog.
///
/// If `endpoint` is not specified, we fallback to `site`.
pub(crate) fn get_api_base_endpoint(endpoint: Option<&str>, site: &str) -> String {
    endpoint.map_or_else(|| format!("https://api.{site}"), compute_api_endpoint)
}

/// Computes the Datadog API endpoint from a given endpoint string.
///
/// This scans the given endpoint for the common Datadog domain names; and, if found, rewrites the
/// endpoint string using the standard API URI. If not found, the endpoint is used as-is.
fn compute_api_endpoint(endpoint: &str) -> String {
    // This mechanism is derived from the forwarder health check in the Datadog Agent:
    // https://github.com/DataDog/datadog-agent/blob/cdcf0fc809b9ac1cd6e08057b4971c7dbb8dbe30/comp/forwarder/defaultforwarder/forwarder_health.go#L45-L47
    // https://github.com/DataDog/datadog-agent/blob/cdcf0fc809b9ac1cd6e08057b4971c7dbb8dbe30/comp/forwarder/defaultforwarder/forwarder_health.go#L188-L190
    static DOMAIN_REGEX: LazyLock<Regex> = LazyLock::new(|| {
        Regex::new(r"((?:[a-z]{2}\d\.)?(?:datadoghq\.[a-z]+|ddog-gov\.com))/*$")
            .expect("Could not build Datadog domain regex")
    });

    if let Some(caps) = DOMAIN_REGEX.captures(endpoint) {
        format!("https://api.{}", &caps[1])
    } else {
        endpoint.into()
    }
}

/// Default settings to use for Datadog components.
#[derive(Clone, Debug, Derivative)]
#[derivative(Default)]
pub struct Options {
    /// Default Datadog API key to use for Datadog components.
    ///
    /// This can also be specified with the `DD_API_KEY` environment variable.
    #[derivative(Default(value = "default_api_key()"))]
    pub api_key: Option<SensitiveString>,

View on GitHub (pinned to bdb87aeaa4)