We deployed Orca Security across our entire AWS and Kubernetes footprint 12 months ago. The main selling point was the agentless architecture, but that's also where our biggest operational headache came from.
The sidecar deployments for deeper container scanning have been unstable in production. We've experienced:
* Random sidecar terminations causing orphaned resources
* Resource spikes during scheduled scans affecting app performance
* Several incidents where the sidecar prevented pod eviction, blocking node drains
The cloud security posture management (CSPM) and vulnerability reporting are solid. But the container runtime piece feels like a beta feature they're running in production. Support tickets take weeks for meaningful resolution.
Has anyone else run into these sidecar issues at scale? Specifically on Kubernetes 1.26+ with Cilium CNI. We're considering dropping the runtime component entirely and just using the CSPM, which defeats the purpose of a "unified" platform.