While the free option with one Engine is great, it would be amazing if we could use that (free one Engine) in an HA format.
In this we would still be sending the same amount/group of parser/blocker/appsec agent data, but, it would allow us to run two CrowdSec binaries in an HA group and I would assume we would need to effectively have the same authentication to CrowdSec on both of them. How you would design the feature/engagement is up to you, but I realize that allowing two when you would normally only allow one would be a sizable difference already.
Big Win:
This would allow for the “cannot reach appsec” to have a native fail over which is highly desirable. No more missed alerts at the WAF layer.
It would be of course a highly sought after feature, and I would practically beg that you allow the engines providing good data that are single engine setups, to pursue using the HA setup, (if not all of engines regardless of how well they are sending data) free with technically “one” HA-pair of two CrowdSec Engines watching the same engaged agents.
Again, thank you for your product!!