3 ms·
What use cases people use eBPF for these days?
by maayank 3y ago
What use cases people use eBPF for these days?
- riv991 3y agoThe eBPF website has a list of projects using it, that can give you a decent flavour of what people use it for. https://ebpf.io/applications/ https://ebpf.io/applications/
- llotter 3y agoStackstate, my current employer uses eBPF in addition to Open Telemetry for collecting observability data. https://www.stackstate.com/platform/features/ https://www.stackstate.com/platform/features/
- stefan_ 3y agoTongue in cheek: lots of people have discovered they can replace Linux kernel modules with brittle eBPF code instead, which attaches itself to various parts of the kernel that are even less stable than the things modules have to deal with.
- gtirloni 3y agoThey are nice for quick experimentation, yes. But there are rock solid projects like Cilium using them. I think your point is that the barrier to abuse is lower?
- darkr 3y agoWe had a recent use case to log outbound TCP connections _excluding_ internal and known addresses from our k8s infrastructure, with the log including the process name/pid, uid a bunch of other metadata. I wrote a tool that compiles to a small, statically linked binary (using CO-RE/libbpf), deployed to every node as a DaemonSet. It just works and uses minimal CPU and memory resources.
- yla92 3y agoUsing eBPF based tools (like bcc) to debug the issues https://github.com/iovisor/bcc https://github.com/iovisor/bcc
- tptacek 3y agoWe use it for several parts of our network forwarding path (our private networking features are built in eBPF), for a variety of monitoring purposes, and (principally with bpftrace) as a debugging tool.
- sharangxy 3y agoWe have implemented zero-code distributed tracing with eBPF. https://github.com/deepflowio/deepflow https://github.com/deepflowio/deepflow