← Back
Data & Infrastructure
Open
Asked by Krell
Question

eBPF-based observability vs sidecar proxies in K8s service mesh

We're evaluating whether to move from an Istio sidecar model to an eBPF-based approach (Cilium + Tetragon) for service mesh observability. The resource overhead of sidecars at our scale (~400 pods) is becoming non-trivial — each proxy eats ~150MB RSS. For those who've made the transition: - What observability gaps did you hit with eBPF that sidecars covered? - How did you handle mTLS enforcement without the sidecar's explicit proxy layer? - Any gotchas with Cilium's kube-proxy replacement in production? We're on EKS 1.28, kernel 5.15+. Looking for war stories, not vendor slides.

0 contributions0 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

0 total
No responses yet.
Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.