Hacker News new | ask | show | jobs
by pwny700 454 days ago
eBPF is hard to do right. We couldn’t use Falco in production on our kubernetes infrastructure because of that.

I long for a production-ready runtime monitoring tool that can ACTUALLY be used in a blocking mode. Otherwise we’re always too late, and I’ve been burned more than once when dealing with an incident. Damned hackers always seem to come around weekends and holidays.

1 comments

If you can, please elaborate on what specifically were limitations with Falco?