eBPF for Linux Observability, Networking & Security
Parent: DevOps, Infrastructure & Observability · researched 2026-06-01T01:39:27.535Z· 26 sources · 13 concepts · skill devops-infra
DevOps / infrastructure / observability family ROUTER. Split into focused sub-hubs — route to: devops-linux-internals (kernel, boot, memory/NUMA, storage/filesystems, virtualization, io_uring, cgroups
devops-infra
- DevOps / infrastructure / observability family ROUTER. Split into focused sub-hubs - route to: devops-linux-internals (kernel, boot, memory/NUMA, storage/filesystems, virtualization, io_uring, cgroups/namespaces, sandboxing, immutable Linux, privilege); devops-linux-admin (sysadmin, systemd, package management, shell scripting, host networking diagnostics); devops-containers-cicd (Docker, Kubernetes, CI/CD pipelines, Terraform/Kafka IaC, git workflows, library packaging); devops-observability (Node/OTel observability, Pino logging, Sentry, eBPF, Linux perf tracing). Pick the sub-hub matching the task. [source]
- This hub routes to on-demand reference files under references/. See each spoke for depth. [source]
Children
- eBPF VM, verifier, JIT & maps (frontier)
- Helpers and kfuncs (frontier)
- Program & attach types (kprobe/uprobe/tracepoint/fentry/XDP/tc/LSM) (frontier)
- CO-RE, BTF, vmlinux.h & libbpf portability (frontier)
- bpftrace tracing language (frontier)
- bcc (BPF Compiler Collection) tools (frontier)
- Development frameworks (libbpf, cilium/ebpf Go, aya Rust, eunomia-bpf) (frontier)
- Cilium eBPF CNI & kube-proxy replacement (XDP/tc/socket hooks, DSR, Maglev) (frontier)
- Hubble flow visibility (frontier)
- eBPF runtime security (BPF LSM, Tetragon, Falco, KubeArmor) (frontier)
- Continuous profiling (Parca, Pixie) (frontier)
- Ring buffer vs per-CPU perf buffer event streaming (frontier)
- eBPF verifier limits & troubleshooting (frontier)
Frontier under this node: CO-RE, BTF, vmlinux.h & libbpf portability, Cilium eBPF CNI & kube-proxy replacement (XDP/tc/socket hooks, DSR, Maglev), Continuous profiling (Parca, Pixie), Development frameworks (libbpf, cilium/ebpf Go, aya Rust, eunomia-bpf), Helpers and kfuncs, Hubble flow visibility, Program & attach types (kprobe/uprobe/tracepoint/fentry/XDP/tc/LSM), Ring buffer vs per-CPU perf buffer event streaming, bcc (BPF Compiler Collection) tools, bpftrace tracing language, eBPF VM, verifier, JIT & maps, eBPF runtime security (BPF LSM, Tetragon, Falco, KubeArmor), eBPF verifier limits & troubleshooting