This company provides real-time visibility into API traffic within application clusters, enabling developers to debug and troubleshoot issues more effectively. Their security software offers identity-aware, protocol-level insights to help users understand what's happening across their entire cluster environment.
Funding
Funding not disclosed
Founders
Product
Problem
Troubleshooting and debugging in Kubernetes environments can be challenging due to the complexity of distributed systems and the difficulty in observing network traffic between pods and services. Existing tools often lack real-time visibility into API traffic and require significant configuration or instrumentation. This makes it difficult for DevOps, SREs, and security teams to quickly identify and resolve issues, leading to increased downtime and potential security vulnerabilities.
Solution
Kubeshark provides deep network observability for Kubernetes, enabling users to inspect all internal and external cluster connections, API calls, and data in transit. By leveraging technologies like eBPF and AF_PACKET, Kubeshark captures Layer 4 traffic and reconstructs it into application-layer protocols, offering protocol-level visibility into K8s' internal API traffic, including encrypted traffic. The platform features real-time, identity-aware, protocol-level visibility into API traffic, allowing users to monitor traffic as it enters, exits, and flows through containers, pods, namespaces, nodes, and clusters. Kubeshark also supports traffic recording and offline analysis, enabling users to capture traffic based on specific events or schedules and analyze it later for forensic purposes or compliance.
Target Audience
Kubeshark is designed for DevOps engineers, SREs, and security teams who need real-time visibility into Kubernetes network traffic for troubleshooting, debugging, security monitoring, and compliance.
Features
- Real-time, protocol-level visibility into Kubernetes API traffic
- Support for protocols including HTTP/1.0, HTTP/1.1, HTTP/2, WebSocket, gRPC, GraphQL, Kafka, Redis, LDAP, Radius, Diameter, TLS, TCP, UDP, SCTP, ICMP and DNS
- TLS decryption using OpenSSL, Go's crypto/tls, and BoringSSL
- Integration with service mesh solutions like Istio and Linkerd for displaying mTLS traffic in clear text
- Traffic recording and offline analysis with PCAP and JSON formats
- Automated distributed tracing with network, Kubernetes, and Linux OS context
- Network Agents for anomaly detection, policy enforcement, and custom metric generation
- Integration with Prometheus, Grafana, Kibana, Splunk, Elastic, InfluxDB, Datadog, AWS S3, Kinesis, and Google Cloud Storage
- Sensitive data redaction
- OIDC/SAML Single Sign-On (SSO)