Skip to content

Daemonset mode for appsec deployment #348

Description

@especially-relative

Problem Statement

Many ingress/gateway installations use daemonsets to run an instance of the ingress/gateway controller per node. Many appsec configurations require a round-trip between the ingress/gateway container and the appsec container. In cases where the cluster spans many regions this may cause issues.

Feature suggestion

Provide an option to run the appsec container as a daemonset in addition to running as a deployment (left as default for backwards compatibility). The appsec service should also support both internalTrafficPolicy and trafficDistribution to provide options to avoid cross-region or even cross-node traffic

Additional background

The crowdsec agent container already supports both deployment and daemonset modes for a somewhat similar reason: it may be the case that it needs to collect logs from every node

Alternatives

  1. Guess the count of nodes, set the deployment replicas high and use affinity to spread pods? Then patch in the service internalTrafficPolicy/trafficDistribution via kustomize to provide traffic support
  2. deal with latency from cross-node/cross-zone traffic for blocking WAF rules

Assumption

Appsec container does not need to make frequent round-trips to LAPI for each request

disclaimer

No AI was used

Activity

  1. github-actions commented on Apr 20, 2026

    @github-actions

    @especially-relative: Thanks for opening an issue, it is currently awaiting triage.

    If you haven't already, please provide the following information:

    • kind : bug, enhancementor documentation
    • area : agent, appsec, configuration, cscli, local-api

    In the meantime, you can:

    1. Check Crowdsec Documentation to see if your issue can be self resolved.
    2. You can also join our Discord.
    3. Check Releases to make sure your agent is on the latest version.
    Details

    I am a bot created to help the crowdsecurity developers manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the forked project rr404/oss-governance-bot repository.

  2. github-actions commented on Apr 20, 2026

    @github-actions

    @especially-relative: There are no 'kind' label on this issue. You need a 'kind' label to start the triage process.

    • /kind bug
    • /kind documentation
    • /kind enhancement
    Details

    I am a bot created to help the crowdsecurity developers manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the forked project rr404/oss-governance-bot repository.

  3. especially-relative commented on Apr 28, 2026

    @especially-relative
    Author

    /kind enchancement

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions