Issues with Endpoint Protection client blocking container startup on Swarm/Kubernetes

Newbie574394 Lv1Posted Sep-23-2025 02:34

We are experiencing abnormal behavior with the Endpoint Protection client installed on linux servers running containerized workloads orchestrated by Docker Swarm or Kubernetes.

Specifically, we noticed that when the client is present, some containers fail to start properly. The issue does not occur when the client is removed. We attempted to configure path exclusions within the solution, but the problem persists.

Currently, the client is configured in monitoring mode only (read/analysis), without taking any enforcement actions, only generating alerts. However, despite this passive configuration, the client still seems to interfere with container operations.

As soon as we uninstall the Endpoint Protection client from the host machine, container startup returns to normal.
In addition, please note that we are attaching a screenshot of the typical error we encounter: it indicates that a file already exists, even though the directory shows that no such file is present. This behavior prevents new containers from starting, and it appears that the EDR may be holding a lock on the file, which blocks the process until it releases it.


We really don’t know what else to do to deal with this issue, so I’m posting here in the community to understand if anyone has faced the same problems in their environment and found how to fix it or a way to workaround.

By solving this question, you may help 340 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

I Can Help:

Change

Moderator on This Board

2
1
0

Started Topics

Followers

Follow

1
1
0

Started Topics

Followers

Follow

910
182
94

Started Topics

Followers

Follow

Trending Topics

Board Leaders