I set up distribution mode with a single LAPI (server) and multiple Openresty bouncer + Appsec (agents). If the agent was in the same AZ region as server there is no issue. But if the agent was in difference AZ regions e.g. US-SG there was issue as bellow:
-crowsec.log (agent) : time="2025-12-03T08:03:34Z" level=error msg="Error checking auth for API key: Head "http://51.xxx.xxx.xxx/v1/decisions/stream\": context deadline exceeded (Client.Timeout exceeded while awaiting headers)" name=CDN-WAF type=appsec time="2025-12-03T08:03:34Z" level=error msg="Unauthorized request from '127.0.0.1:38654' (real IP = xx.xxx.xxx) invalid API key" name=CDN-WAF type=appsec