DaemonSets carry every cluster's node-level plumbing:
| Job on each node | Open-source examples | License | Reads from the node |
|---|---|---|---|
| Pod networking | kindnet, Calico 3.32 111,267 , Cilium 1.20 96,364 | Apache-2.0 | Network interfaces, eBPF |
| Log collection | Fluent Bit 5.1 83,977 , Grafana Alloy 1.20 2,264 | Apache-2.0 | /var/log/pods via hostPath |
| Node metrics | Prometheus 16,091 node_exporter 1.12 | Apache-2.0 | /proc, /sys |
| Runtime security | Falco 0.45 296,676 | Apache-2.0 | Kernel syscalls (eBPF) |
kube-proxy and CSI node plugins (CSI) are DaemonSets too, as are commercial agents such as Datadog 381 's. Needing host paths or privileges, they are the Pod Security exceptions (Pod Security and Policies) to audit first. BookNest itself needs none until node_exporter arrives with Prometheus in Observability and Debugging.