Resource Management for Private Locations¶
Can Private Locations Be Deployed on Windows, or Are Linux/Kubernetes Required?¶
Choose a CLI or container deployment for your platform. For production environments, we recommend Kubernetes with Escape's Helm chart.
Supported Platforms
CLI builds are available for Windows (amd64), macOS (amd64 and arm64), and Linux (amd64 and arm64). Container images are built for Linux (amd64 and arm64).
Run the Windows binary directly in a terminal. The latest builds for Windows and macOS are available on the release page.
Alternatively, the repository can be cloned and the binary can be built manually for custom deployment scenarios.
Are Additional Resources Needed Based on Traffic Volume?¶
Resource requirements depend on your workload. The Helm defaults are 1 vCPU and 2 GiB RAM for both requests and limits. Configure these values for your workload and monitor CPU and memory usage as you increase traffic:
- Number of concurrent scans: Multiple simultaneous scans require additional resources
- Volume of scan requests: Higher request volumes increase memory and CPU demands
Private Location performance should be monitored through the logging and monitoring capabilities. For assistance with capacity planning and scaling strategies, contact the support team.
How Many Private Locations Are Needed for Your Scan Profiles?¶
Capacity depends on concurrent scans, rather than the total number of scan profiles.
Capacity planning examples:
- Sequential scans: Several profiles can share a Private Location when their scans run at different times. Size it for the workload.
- Concurrent scans: Size and distribute your workload across Private Locations based on:
- The size and complexity of the APIs being scanned
- The resources allocated to each Private Location
- The expected scan duration and throughput requirements
Is It Better to Deploy Multiple Private Locations or Increase Resources on a Single Instance?¶
The optimal scaling strategy depends on the specific use case and workload characteristics:
Each Private Location has a concurrent proxied connection cap that's independent of requests per second and CPU or memory allocation. Excess connections are closed. Distribute scans across multiple Private Locations when concurrency reaches this cap.
Vertical scaling (increasing resources on a single Private Location):
- Advantages: Simpler configuration and management, lower operational overhead, suitable for moderate workloads
- Best for: Organizations with sequential or moderately concurrent scans, predictable workload patterns
- Capacity and availability: Size the instance within its hardware capacity and monitor performance under load. Scans assigned to it depend on that instance's availability.
Horizontal scaling (deploying multiple Private Locations):
- Advantages: Distribute load across instances, add capacity incrementally, and provide multiple locations for selection at scan start
- Best for: Organizations with high-concurrency requirements, distributed teams across multiple networks, mission-critical operations requiring redundancy
- Considerations: Run each agent with a unique location name. Agents using the same name can disrupt each other's connections.
Choose how Escape routes each scan: bind a profile to a location with proxyId, or omit proxyId and set defaultProxyType: PRIVATE through the Public API so Escape selects a healthy Private Location for each scan. Automatic selection provides failover at scan start without a customer load balancer; ensure every eligible location can reach the target.
Recommended approach:
- Start with vertical scaling by increasing resources on a single Private Location to meet initial demand
- Monitor performance metrics through the logging and monitoring capabilities to identify bottlenecks
- Deploy additional Private Locations horizontally when:
- A single instance consistently reaches resource limits (CPU, memory)
- You need alternative healthy locations for new scans when an instance is unavailable
- Scans need to be distributed across different network zones or regions
- Concurrent scan requirements exceed what vertical scaling can reasonably provide