Tag: eBPF
All the articles with the tag "eBPF".

Cilium Tetragon: eBPF runtime security that blocks, not just logs
Falco and most eBPF security tools can only alert after the fact. Tetragon, Cilium's runtime security engine, can do more — kill a process synchronously in the kernel before the syscall even returns. We break down the TracingPolicy anatomy, enforcement risks, and the safe rollout pattern: audit first, Sigkill later.

Sidecar-free service mesh: Cilium Service Mesh next to Istio Ambient
Cilium Service Mesh handles mTLS and L7 routing on the eBPF datapath with no separate proxy components at all — unlike Istio Ambient, which drops the sidecar but keeps ztunnel and waypoint. We compare the architectures, the honest limitations, and turn on mTLS in a cluster that already runs Hubble.

OBI: zero-code application tracing via eBPF, the Grafana Beyla successor
OpenTelemetry eBPF Instrumentation (OBI) traces HTTP/gRPC/SQL straight from the kernel — no in-container agent, no line of application code touched. We look at how OBI differs from Hubble, Tetragon and Pyroscope, how it plugs into an OTel Collector you already run, and where zero-code instrumentation hits its ceiling.

eBPF without the pain: Cilium and network observability in Kubernetes
What eBPF is in plain terms, why Cilium beats kube-proxy and sidecars, how Hubble shows flows and drop reasons, and what you need to stand it all up in a kind cluster in an evening.