Repository navigation
[spycloud] Add Agentless Deployment Support #19350
Description
Activity
- addedenhancementNew feature or requestNew feature or requestTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
on Jun 3, 2026 - addedIntegration:spycloudSpyCloud Enterprise Protection (Partner supported)SpyCloud Enterprise Protection (Partner supported)Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]
on Jun 3, 2026 infra-vault-gh-plugin-prod commented
on Jun 3, 2026 More actionsPinging @elastic/security-service-integrations (Team:Security-Service Integrations)
tl;dr: SpyCloud already uses CEL streams that are agentless-capable; the missing piece is declaring
deployment_modes.agentlessinpackages/spycloud/manifest.ymland updating docs/changelog accordingly.1. Recommendation
Implement agentless support as a manifest/docs/changelog change (no stream template redesign):
- Add
policy_templates[].deployment_modes(default+agentless) inpackages/spycloud/manifest.yml. - Bump package version and add changelog entry in
packages/spycloud/changelog.yml(enhancement: “Enable Agentless deployment.”). - Update source docs in
packages/spycloud/_dev/build/docs/README.md(and generatedpackages/spycloud/docs/README.md) to include agentless deployment guidance instead of agent-only wording.
2. Findings
Key evidence from codebase
packages/spycloud/manifest.yml:32-37has CEL input but no deployment modes:policy_templates→inputs→- type: cel
packages/spycloud/data_stream/breach_catalog/manifest.yml:4-8,.../breach_record/manifest.yml:4-8,.../compass/manifest.yml:4-8all already use CEL stream templates.- CEL integrations that support agentless declare it in the package manifest, e.g.:
packages/ti_abusech/manifest.yml:43-51packages/ti_greynoise/manifest.yml:35-43
- SpyCloud docs are currently agent-only:
packages/spycloud/_dev/build/docs/README.md:25(“Elastic Agent must be installed...”).
- Changelog precedent for this exact change exists:
packages/ti_abusech/changelog.yml:102-106(“Enable Agentless deployment.”)packages/forgerock/changelog.yml:8-11(agentless enablement entry)
I also ran 3 parallel repo investigations (manifest-focused, datastream-focused, history-focused); all converged on the same root gap: missing
deployment_modesdeclaration for SpyCloud.3. Verification
Command output
$ grep -n "deployment_modes" packages/spycloud/manifest.yml || true # (no output) $ grep -n "deployment_modes" packages/ti_abusech/manifest.yml 43: deployment_modes: $ grep -n "Elastic Agent must be installed" packages/spycloud/_dev/build/docs/README.md 25:Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions...
4. Detailed Action Plan
Step-by-step implementation plan
- Manifest update (
packages/spycloud/manifest.yml)- Under
policy_templates[0], add:deployment_modes.default.enabled: truedeployment_modes.agentless.enabled: truedeployment_modes.agentless.release: betadeployment_modes.agentless.organization/division/teamusing current team convention.
- Under
- Versioning + changelog
- Bump
versioninpackages/spycloud/manifest.yml(minor bump). - Prepend changelog entry in
packages/spycloud/changelog.ymlwith typeenhancementand PR link.
- Bump
- Docs source + generated docs
- Update
packages/spycloud/_dev/build/docs/README.mdrequirements/setup sections to include agentless deployment path. - Regenerate/align
packages/spycloud/docs/README.mdfrom source template workflow.
- Update
- Validation
- Run package validation/docs build flow used by this repo to confirm manifest and docs are accepted.
5. Related Items
Issues, PRs, and files
Type Link / File Relevance Issue #19350 Current request: add SpyCloud agentless support Issue #17973 Related by search query ( spycloud+agentless), but content was integrity-filtered in this runPR #13173 Precedent changelog link for “Enable Agentless deployment.” in ti_abusechPR #19205 Precedent changelog link for agentless enablement in forgerockFile packages/spycloud/manifest.ymlMissing deployment_modesblockFile packages/spycloud/_dev/build/docs/README.mdAgent-only requirement wording File packages/ti_abusech/manifest.ymlConcrete manifest pattern for agentless CEL integration File packages/ti_greynoise/manifest.ymlSame team, same CEL + agentless pattern Note
🔒 Integrity filter blocked 16 items
The following items were blocked because they don't meet the GitHub integrity level.
- #19350
issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #19350
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #17973
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #18881
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #15988
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #17560
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #17973
issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - [spycloud] Add Agentless Deployment Support #19350
issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #14725
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #10608
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #10532
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #10537
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #11210
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #13320
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #12632
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - #11833
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
To allow these resources, lower
min-integrityin your GitHub frontmatter:tools: github: min-integrity: approved # merged | approved | unapproved | none
What is this? | From workflow: Issue Triage
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
- Add
Description
Add agentless support to the spycloud.
Requirements
Following the established Phase I pattern, for each integration see the Onboarding Integration Guide.
1. Technical implementation
Example reference: #13367
2. Performance documentation
Example documentation format: "Crowdstrike Falcon Intelligence: 200ms avg API response, 5,000 events/min, 0.1% error rate, 512MB RAM/0.5CPU, 1000 API calls/hour limit"
Dependencies