Part 8 · 1 chapters · ~8 min

eBPF Tools for the Impatient

What eBPF is and why it is safe, the bcc tools and bpftrace one-liners that answer the common questions (new processes, file opens, disk latency, TCP connections and retransmits, run-queue latency, off-CPU time), and running them in containers and Kubernetes.

15

Questions, answered from the kernel

code
# bcc tools (often packaged as *-bpfcc)
execsnoop-bpfcc            ; opensnoop-bpfcc -x      ; biolatency-bpfcc 10 1
tcpconnect-bpfcc -P 5432   ; tcpretrans-bpfcc        ; runqlat-bpfcc 10 1
offcputime-bpfcc -p <pid> 10 > out.stacks

# bpftrace one-liners
bpftrace -e 'tracepoint:syscalls:sys_enter_openat { printf("%s %s\n", comm, str(args->filename)); }'
bpftrace -e 'kprobe:vfs_read { @[comm] = count(); }'

On Kubernetes, run them from a privileged debug pod on the node (kubectl debug node/…) or use tools such as Inspektor Gadget, Pixie and Parca that package eBPF for clusters. Systems Performance (course 39) goes deeper.

eBPF TOOLS FOR THE IMPATIENT
one-liners from the bcc and bpftrace collections
execsnoopEvery new process: catchshort-lived processes that topnever shows.opensnoopEvery file open, with errors:config not found, permissiondenied.biolatencyBlock IO latency histogram: is thedisk slow?tcpconnect / tcpretransOutbound connections andretransmits, per process.runqlatScheduler run-queue latency: CPUsaturation that averages hide.offcputimeWhere threads block, with stacks:the off-CPU view.
swipe the figure sideways, or tap expand for full screen
1/6
why eBPF
eBPF runs small verified programs inside the kernel at tracepoints and probes, aggregating data in the kernel with low overhead. It answers questions about any process without restarting or instrumenting it.
safe programs in the kernelno restarts, low overhead