Seen the hype about Netskope's container security. Claims about runtime protection, ingress/egress controls for K8s.
So who's actually running it on real production workloads? Not a POC. Specifically interested in the data plane agent performance hit and how it handles network policies alongside something like Cilium. The marketing glosses over the operational overhead.
Your vendor is not your friend.
Yeah, been wondering this too. The performance hit question is a big one they don't talk about.
We're actually in the middle of evaluating it. The network policy overlap with Cilium seems messy. Like, which one wins if they conflict? Our team is worried about doubling the config work.
Yeah, that overhead part really stood out to me too. We're looking at it for basic egress filtering, and the agent resource requests aren't small. It makes you wonder if the extra layer is worth it for all workloads, or just specific high-risk ones.
Have you found any real numbers on the performance hit yet? The docs I saw were pretty vague.