eBPF in Practice: Building High-Performance Linux Systems with Advanced Tracing, Observability, and Security (en Inglés)
Reseña del libro "eBPF in Practice: Building High-Performance Linux Systems with Advanced Tracing, Observability, and Security (en Inglés)"
Every second, your Linux servers make thousands of decisions you never see: files opening, processes forking, packets arriving, connections dropping. Most engineers only find out something went wrong after it already has. eBPF changes that. It lets you run small, safe programs directly inside the kernel - watching, measuring, and even acting on system behavior in real time, without rebuilding the kernel or slowing anything down.Picture this: a production server is running hot. CPU usage is climbing, but nobody can say why. The usual tools - top, vmstat - just point at a vague number. You need to know which function, in which process, is actually burning the cycles, and you need the answer now, without rebooting anything.This is the exact problem eBPF was built to solve - and it's the exact problem this book teaches you to solve yourself. You will start by understanding why older tools like printk and SystemTap fell short. Then you will build your own tracing tools, one working program at a time, until tracing a live, unexplained slowdown feels less like guesswork and more like a conversation with your own kernel.What's InsideFoundations: eBPF's architecture - the verifier, JIT compiler, and maps - explained clearly, with real codeKernel & application tracing: kprobes, tracepoints, uprobes, and USDT probes, including correlating kernel events with application-level contextPerformance observability: CPU and off-CPU flame graphs, memory/disk/network tracing, and a custom Prometheus metrics pipelineNetworking: XDP-based load balancing, DDoS mitigation, egress filtering, and how platforms like Cilium apply these ideas at cluster scaleSecurity: LSM-based access control, a working intrusion detection system, and seccomp-BPF sandboxingProduction readiness: CO-RE portability, benchmarking overhead, testing, CI/CD, and fleet-wide deploymentEvery chapter includes complete, explained code - no unfinished snippets, no unexplained magic.Who It's Meant ForThis book is for: Backend and platform engineers who want to stop guessing and start measuring what their systems actually doSite reliability and DevOps engineers who need to diagnose production issues fast, without downtimeSecurity engineers building runtime detection and enforcement instead of relying on logs aloneAnyone comfortable with C who wants a genuine, practical understanding of modern Linux internalsNo prior eBPF experience is needed. If you can read C and you're comfortable in a Linux terminal, you're ready.Somewhere on your infrastructure, right now, something is happening that no dashboard is showing you. A slow query. A silent retry storm. A process reading a file it shouldn't. The tools to see it - and stop it - already exist inside your own kernel.This book teaches you to use them.Open Chapter 1. Your kernel has been talking this whole time. It's time you learned to listen.