Full-Stack Observability on GKE Autopilot: What Google Locks Down, and How to See Through It Anyway

GKE Autopilot's security model blocks privileged containers, host namespaces, and direct node access by default - which is precisely what most observability and security agents depend on to enrich application telemetry with infrastructure context. For platform teams moving from GKE Standard to Autopilot, this creates a quiet but serious gap: the monitoring stack that worked yesterday may silently lose depth today, and closing that gap usually means building and maintaining a custom privileged-workload allowlist by hand.

In this session, groundcover — a newly approved official partner on Google's GKE Autopilot program — walks through exactly what Autopilot restricts and why, what breaks in your logs, traces, and infra metrics once you're on Autopilot, and how to get full-stack, kernel-level visibility back without reopening the security boundaries Autopilot was built to enforce. We'll deploy groundcover's eBPF sensor live on a real Autopilot cluster to show what "native" partner-level access actually looks like in practice, including how a bring-your-own-cloud architecture keeps that data inside your own environment for teams operating under strict compliance requirements.

What you'll learn:

  • What GKE Autopilot's security model restricts, and the reasoning behind each guardrail
  • The specific observability and security gaps teams hit after migrating from Standard to Autopilot
  • How official Autopilot partner status differs from a self-managed allowlist workaround — and why that distinction matters for maintenance overhead and audit posture
  • A live install and walkthrough of full-stack, zero-instrumentation observability running natively on Autopilot

Who should attend: Platform, infrastructure, and SRE leaders operating or evaluating GKE Autopilot — particularly teams in regulated industries where data residency and compliance shape tooling decisions.

Featured Guests

Adam Hicks,

Adam Hicks,

gc, Sales Engineer

Bo Fu,

Bo Fu,

Google, Product Management

Featured Guests

Adam Hicks,

Adam Hicks,

gc, Sales Engineer

Bo Fu,

Bo Fu,

Google, Product Management

Trusted by teams who demand more

Real teams, real workloads, real results with groundcover.

“We cut our costs in half and now have full coverage in prod, dev, and testing environments where we previously had to limit it due to cost concerns.”

Sushant Gulati

Sr Engineering Mgr, BigBasket

“Observability used to be scattered and unreliable. With groundcover, we finally have one consolidated, no-touch solution we can rely on.“

ShemTov Fisher

DevOps team lead
Solidus Labs

“We went from limited visibility to a full-cluster view in no time. groundcover’s eBPF tracing gave us deep Kubernetes insights with zero months spent on instrumentation.”

Kristian Lee

Global DevOps Lead, Tracr

“The POC took only a day and suddenly we had trace-level insight. groundcover was the snappiest, easiest observability platform we’ve touched.”

Adam Ceresia

Software Engineering Mgr, Posh

“All vendors charge on data ingest, some even on users, which doesn’t fit a growing company. One of the first things that we liked about groundcover is the fact that pricing is based on nodes, not data volumes, not number of users. That seemed like a perfect fit for our rapid growth”

Elihai Blomberg,

DevOps Team Lead, Riskified

“We got a bill from Datadog that was more then double the cost of the entire EC2 instance”

Said Sinai Rijcov,

DevOps Engineer at EX.CO.

“We ditched Datadog’s integration overhead and embraced groundcover’s eBPF approach. Now we get full-stack Kubernetes visibility, auto-enriched logs, and reliable alerts across clusters with zero code changes.”

Eli Yaacov

Prod Eng Team Lead, Similarweb

Observability
for what comes next.

Start in minutes. No migrations. No data leaving your infrastructure. No surprises on the bill.