On This Page

Home / Apps/Publish an App to the Cribl Marketplace

Publish an App to the Cribl Marketplace ​

Use this guide to prepare and submit an App for listing in the Cribl Marketplace. Before you submit an App:

  • You have built an App that solves a common problem and provides a clear, focused user experience.
  • Plan to support the App after publication.
  • Create a profile and sign in to the Cribl Marketplace with Google authentication.
  • Review and accept the Developer Terms when prompted.

For guidance on developing and packaging an App, see the Builder Guide.

Prepare the App ​

Before you package the App:

  • Run vulnerability scans, such as npm audit, and resolve high- and critical-severity issues. Cribl rejects Apps with unresolved high- or critical-severity issues.

  • Verify that the name in package.json is unique and does not conflict with the ID of a published App.

  • Use a human-readable display name that identifies the App’s function, such as Datacenter Monitoring.

  • In package.json, add tags for the Cribl products that the App uses. For example:

    "Tags": { "products": ["Stream", "Lake", "Search"] }
  • Provide a safe default configuration for first-time installation.

  • Remove hard-coded secrets and credentials.

  • Test upgrades from supported older versions.

  • Complete the customer-facing README.md.

Use npm run package to create the .tgz archive for submission. For packaging instructions, see Package, Version, and Deploy in the Builder Guide.

Write the README ​

Before you submit an App, provide a customer-facing README.md that explains what the App does, who it is for, how to install and configure it, and how to get support.

App Title and Summary ​

Provide the App name and a one-sentence description of its purpose. Write a summary that can also serve as the Cribl Marketplace overview or App detail description.

What This App Does ​

Describe:

  • The primary problem or workflow that the App addresses.
  • Its key capabilities and benefits.
  • Its intended users, such as administrators, analysts, platform owners, builders, or end users.
  • The supported Cribl products and deployment types, such as Stream, Edge, Search, Lake, Cribl.Cloud, or hybrid environments.

When to Use This App ​

List the main use cases and scenarios where the App provides value. Focus on the problem and the expected outcome.

Before You Install ​

Document:

  • Required Cribl products, versions, or deployment types.
  • Required permissions or user roles.
  • Required external systems, APIs, accounts, or services.
  • Required configuration values, credentials, datasets, or Workspace settings.
  • Known limits, feature flags, quotas, or environment requirements.

Installation ​

Provide clear installation instructions. Tell users to install from the Cribl Marketplace when the App is listed there. If you support manual installation, explain how to install the appropriate release package from the App repository.

For the administrator’s Cribl Marketplace installation flow, see Install from the Cribl Marketplace in the Admin Guide.

Configuration ​

Explain every setting that users must provide after installation. Identify required and optional settings, provide examples and safe defaults, and explain whether each setting applies per user, per App, or across a shared environment.

How to Use ​

Describe the typical workflow from opening the App through completing its primary action. Include a first-run checklist and explain the expected output or results.

Permissions and External Access ​

Document the Cribl API endpoints and external services that the App requires. Use config/policies.yml and config/proxies.yml as sources. Explain what the product permissions and external service calls accomplish. If the App does not make external calls, state that explicitly.

For guidance on these declarations, see Declare In-Product API Permissions Your App Needs and External APIs and proxies.yml in the Builder Guide.

Data and Storage ​

Explain what data the App stores, reads, or changes. Include persistent storage, shared data, KV keys, cleanup behavior, and any usage limits or quotas.

Support Model ​

Identify who owns support and maintenance. Provide a support contact, email address, Slack channel, GitHub issues page, or another support path.

Known Limitations and Troubleshooting ​

Document unsupported scenarios, known limitations, common configuration issues, permission errors, external connectivity problems, and environment-specific considerations.

Handle Data Securely ​

Do not extract, copy, export, or transmit customer data for an unrelated secondary purpose. Do not send customer data to developer-controlled systems, personal storage, test environments, or third-party services.

Document these security details:

  • Authentication and authorization behavior.
  • Required permissions, limited to the minimum the App needs.
  • How the App stores and handles secrets.
  • External hosts, paths, headers, and methods.
  • Network calls that use the approved proxy configuration.
  • Known vulnerabilities and mitigations.
  • A security reporting contact.

For the Apps security model, see Runtime, Architecture, and Security.

Support and Remediation Obligations ​

App builders must provide a contact method and a link to a ticketing system that allow you to:

  • Monitor reported issues.
  • Provide fixes within required security remediation windows.

If the App falls outside the applicable SLA, Cribl may send a warning email. If the issue is not addressed after two additional follow-ups, Cribl may delist the App.

Security Remediation SLAs ​

SeverityRequired Fix SLA
CriticalWithin 10 days
HighWithin 4 weeks

The remediation clock applies to delivering the required fix, not only acknowledging or triaging the issue. Newly discovered vulnerabilities affecting a published App must be remediated within these windows, or the App may be delisted.

Certified Apps have additional support and remediation requirements, including Medium and Low security SLAs. See Certify an App.

Submit the App ​

  1. Sign in to the Cribl Marketplace with Google authentication.
  2. Open the Apps publishing page.
  3. Upload the .tgz package and accept the Developer Terms.
  4. Wait for Cribl to review the submission.

The App remains unavailable in the Cribl Marketplace until Cribl approves it. Cribl contacts you if the submission requires changes.

After publication, continue to monitor the App for security vulnerabilities. If a high- or critical-severity vulnerability occurs, work with Cribl to remediate it. Cribl can remove an App when its publisher does not remediate security vulnerabilities promptly.

To pursue the Cribl Certified badge after publication, see Certify an App.