PacketSafari
Ecosystem overview

Cloud-native workload visibility

Keep Kubernetes and eBPF workload context. Capture what still needs proof.

Kubernetes, CNI, service-mesh, eBPF, and container observability tools expose pod, workload, identity, policy, and service context. PacketSafari complements them when a bounded packet capture is needed for deeper protocol or timing analysis.

Kubernetes, containers & eBPFContext → capture → investigation
Scope
Cilium and HubbleRetinaPixieCalico
AcquirePod · node · eBPF captureauthorized incident PCAP
InvestigatePacketSafariCore Engine · Agent · report
Result outExact evidence returns to the team that can act.
Category owns

Connect and secure workloads, expose service dependencies, observe flows, enforce network policy, and correlate traffic with pod and namespace identity.

Acquisition path

Capture from the pod namespace, node, CNI or eBPF sensor, service-mesh proxy, cloud mirror, or approved virtual appliance, and document where encryption terminates.

PacketSafari owns

Investigate the captured traffic while preserving the workload, node, namespace, service, sidecar, and encryption context supplied by the platform.

Representative products

Different jobs. One clean handoff.

These are representative ecosystem products, not partner badges or certification claims. Capabilities and packet access vary by edition, license, deployment, and configuration.

Vendor / productPrimary rolePacket boundaryFitPacketSafari value

eBPF networking, network policy, and workload-aware observability

Flows, service context, and optional packet-oriented diagnostics; PCAP acquisition is workflow-specific.

Complementary

Use Hubble context to select the pod, node, service, and interval for capture.

MicrosoftRetina

Cloud-native container networking observability

Kubernetes network telemetry and capture workflows depending on deployment.

Strong handoff

Bring an authorized capture from the affected cluster into PacketSafari.

New RelicPixie

eBPF-based Kubernetes observability and application telemetry

In-cluster telemetry reconstructed from eBPF data; not automatically a portable PCAP.

Complementary

Investigate a packet capture when protocol detail or independent evidence is still required.

TigeraCalico

Kubernetes networking, security policy, and observability

Flow logs and workload context; raw capture comes from node or workload tooling.

Complementary

Correlate policy and workload identity with the observed packet exchange.

IsovalentTetragon

eBPF runtime enforcement and security observability

Kernel and process events rather than general full-packet retention.

Complementary

Combine runtime evidence with a scoped packet investigation.

Service mesh, traffic policy, telemetry, and proxying

Proxy metrics, logs, traces, and possible capture at sidecar or node boundaries.

Complementary

Separate mesh policy, mTLS, transport, upstream, and application behavior.

LinkerdLinkerd

Service mesh, mTLS, routing, and service metrics

Proxy and service telemetry; packet visibility depends on capture point and encryption.

Complementary

Document the observation boundary and investigate visible protocol behavior.

Grafana LabsBeyla

eBPF application and network observability with OpenTelemetry

Metrics and traces, not a full packet system of record.

Complementary

Use telemetry to scope the remaining question before acquiring a PCAP.

Decision guide

Use each layer for the decision it owns.

PacketSafari adds depth after a capture exists. It does not become the continuous monitor, enforcement point, access broker, packet broker, or recorder.

Do you need workload identity, policy, and continuous cluster visibility?

Use the CNI, service mesh, eBPF, and Kubernetes observability layer.

Do you need exact protocol and transport evidence?

Capture at the pod, node, proxy, or adjacent network boundary where the evidence is visible.

Is service-mesh traffic encrypted?

Choose and document an authorized pre-encryption or post-decryption observation point.