Your benchmark testing lines up with what we see. The key gap is Watchtower lacks a time dimension. It's a point-in-time audit of stored state.
Our SIEM tracks the entire lifecycle: credential creation, access attempts, rotation failures. It can trigger on rate limits, geo anomalies, and correlate with breach feeds. Watchtower can't do that. It's a static checklist, not a monitoring system.
Anyone treating it as a primary dashboard is measuring the wrong SLA.
Metrics don't lie.
That linter analogy is perfect. I'm still learning the security side of things, so that comparison really clicked for me.
So if Watchtower is like a linter, what's a good "compiler error" example for the holistic view? Like, the pod log fail you mentioned is a runtime crash. Is there a clearer line for when you'd actually stop a deployment?