Skip to content

[spycloud] Add Agentless Deployment Support #19350

Description

@mohitjha-elastic

Description

Add agentless support to the spycloud.

Requirements

Following the established Phase I pattern, for each integration see the Onboarding Integration Guide.

1. Technical implementation

  • Update integration manifest.yml to enable agentless deployment mode ()
  • Update integration documentation with agentless deployment instructions
  • Update changelog.md

Example reference: #13367

2. Performance documentation

  • Test and document throughput in agentless (requires access to vendor environment and/or sample data)
  • Document specific metrics for each integration. For example/where possible:
    • API response time: Average time for vendor API calls to complete
    • Events processed per minute: How many log entries/events the integration can handle
    • Error rates: Percentage of failed API calls or data processing errors
    • Container resource usage: CPU and memory consumption under typical load
    • Vendor-specific limits: Rate limiting thresholds and API quotas

Example documentation format: "Crowdstrike Falcon Intelligence: 200ms avg API response, 5,000 events/min, 0.1% error rate, 512MB RAM/0.5CPU, 1000 API calls/hour limit"

Dependencies

  • Agentless infrastructure GA readiness (still in beta)
  • Input compatibility: Currently agentless is optimized for httpjson and cel inputs
  • UX enhancement: Add agentless deployment filter/toggle to integrations catalog page for better discoverability

Activity

  1. added
    Integration:spycloudSpyCloud Enterprise Protection (Partner supported)
    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]
    on Jun 3, 2026
  2. infra-vault-gh-plugin-prod commented on Jun 3, 2026

    @infra-vault-gh-plugin-prod

    Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

  3. github-actions commented on Jun 3, 2026

    @github-actions
    Contributor

    tl;dr: SpyCloud already uses CEL streams that are agentless-capable; the missing piece is declaring deployment_modes.agentless in packages/spycloud/manifest.yml and updating docs/changelog accordingly.

    1. Recommendation

    Implement agentless support as a manifest/docs/changelog change (no stream template redesign):

    1. Add policy_templates[].deployment_modes (default + agentless) in packages/spycloud/manifest.yml.
    2. Bump package version and add changelog entry in packages/spycloud/changelog.yml (enhancement: “Enable Agentless deployment.”).
    3. Update source docs in packages/spycloud/_dev/build/docs/README.md (and generated packages/spycloud/docs/README.md) to include agentless deployment guidance instead of agent-only wording.

    2. Findings

    Key evidence from codebase
    • packages/spycloud/manifest.yml:32-37 has CEL input but no deployment modes:
      • policy_templates → inputs → - type: cel
    • packages/spycloud/data_stream/breach_catalog/manifest.yml:4-8, .../breach_record/manifest.yml:4-8, .../compass/manifest.yml:4-8 all already use CEL stream templates.
    • CEL integrations that support agentless declare it in the package manifest, e.g.:
      • packages/ti_abusech/manifest.yml:43-51
      • packages/ti_greynoise/manifest.yml:35-43
    • SpyCloud docs are currently agent-only:
      • packages/spycloud/_dev/build/docs/README.md:25 (“Elastic Agent must be installed...”).
    • Changelog precedent for this exact change exists:
      • packages/ti_abusech/changelog.yml:102-106 (“Enable Agentless deployment.”)
      • packages/forgerock/changelog.yml:8-11 (agentless enablement entry)

    I also ran 3 parallel repo investigations (manifest-focused, datastream-focused, history-focused); all converged on the same root gap: missing deployment_modes declaration for SpyCloud.

    3. Verification

    Command output
    $ grep -n "deployment_modes" packages/spycloud/manifest.yml || true
    # (no output)
    
    $ grep -n "deployment_modes" packages/ti_abusech/manifest.yml
    43:    deployment_modes:
    
    $ grep -n "Elastic Agent must be installed" packages/spycloud/_dev/build/docs/README.md
    25:Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions...

    4. Detailed Action Plan

    Step-by-step implementation plan
    1. Manifest update (packages/spycloud/manifest.yml)
      • Under policy_templates[0], add:
        • deployment_modes.default.enabled: true
        • deployment_modes.agentless.enabled: true
        • deployment_modes.agentless.release: beta
        • deployment_modes.agentless.organization/division/team using current team convention.
    2. Versioning + changelog
      • Bump version in packages/spycloud/manifest.yml (minor bump).
      • Prepend changelog entry in packages/spycloud/changelog.yml with type enhancement and PR link.
    3. Docs source + generated docs
      • Update packages/spycloud/_dev/build/docs/README.md requirements/setup sections to include agentless deployment path.
      • Regenerate/align packages/spycloud/docs/README.md from source template workflow.
    4. Validation
      • Run package validation/docs build flow used by this repo to confirm manifest and docs are accepted.

    5. Related Items

    Issues, PRs, and files
    Type Link / File Relevance
    Issue #19350 Current request: add SpyCloud agentless support
    Issue #17973 Related by search query (spycloud + agentless), but content was integrity-filtered in this run
    PR #13173 Precedent changelog link for “Enable Agentless deployment.” in ti_abusech
    PR #19205 Precedent changelog link for agentless enablement in forgerock
    File packages/spycloud/manifest.yml Missing deployment_modes block
    File packages/spycloud/_dev/build/docs/README.md Agent-only requirement wording
    File packages/ti_abusech/manifest.yml Concrete manifest pattern for agentless CEL integration
    File packages/ti_greynoise/manifest.yml Same team, same CEL + agentless pattern

    Note

    🔒 Integrity filter blocked 16 items

    The following items were blocked because they don't meet the GitHub integrity level.

    • #19350 issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #19350 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #17973 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #18881 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #15988 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #17560 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #17973 issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • [spycloud] Add Agentless Deployment Support #19350 issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #14725 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #10608 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #10532 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #10537 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #11210 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #13320 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #12632 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
    • #11833 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".

    To allow these resources, lower min-integrity in your GitHub frontmatter:

    tools:
      github:
        min-integrity: approved  # merged | approved | unapproved | none

    What is this? | From workflow: Issue Triage

    Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Integration:spycloudSpyCloud Enterprise Protection (Partner supported)Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions