Part 8 · 1 chapters · ~8 min
eBPF Tools for the Impatient
What eBPF is and why it is safe, the bcc tools and bpftrace one-liners that answer the common questions (new processes, file opens, disk latency, TCP connections and retransmits, run-queue latency, off-CPU time), and running them in containers and Kubernetes.
15
Questions, answered from the kernel
code
# bcc tools (often packaged as *-bpfcc)
execsnoop-bpfcc ; opensnoop-bpfcc -x ; biolatency-bpfcc 10 1
tcpconnect-bpfcc -P 5432 ; tcpretrans-bpfcc ; runqlat-bpfcc 10 1
offcputime-bpfcc -p <pid> 10 > out.stacks
# bpftrace one-liners
bpftrace -e 'tracepoint:syscalls:sys_enter_openat { printf("%s %s\n", comm, str(args->filename)); }'
bpftrace -e 'kprobe:vfs_read { @[comm] = count(); }'On Kubernetes, run them from a privileged debug pod on the node (kubectl debug node/…) or use tools such as Inspektor Gadget, Pixie and Parca that package eBPF for clusters. Systems Performance (course 39) goes deeper.
eBPF TOOLS FOR THE IMPATIENT
one-liners from the bcc and bpftrace collections
swipe the figure sideways, or tap expand for full screen
1/6
why eBPF
eBPF runs small verified programs inside the kernel at tracepoints and probes, aggregating data in the kernel with low overhead. It answers questions about any process without restarting or instrumenting it.
safe programs in the kernelno restarts, low overhead