Topical Takes
Short, opinionated posts on eBPF, Linux internals, and the tools we all run in production.
How to Monitor HTTP Traffic on Linux in 2026: Why the Kernel Sees What Your Access Log Doesn't
How to see the HTTP requests crossing a Linux host, including the ones your access log never records because they never reached a handler. Covers eBPF capture at the kernel's TC layer, tcpdump, Coroot, Pixie, Cilium Hubble, a proxy and OpenTelemetry, with the commands to run and the kernel version each one needs.
eBPFobservabilityHTTPnetworkinglinuxtcpdump
Read more →eBPF-Speed L7 Enforcement Without a CNI Migration
Cilium has the fastest datapath in Kubernetes networking, and its best modes are gated behind cluster-wide commitments — here is when that trade is worth making, and when enforcing at XDP without touching your CNI is the smaller move.
eBPFkubernetesnetworkingCilium
Read more →