Skip to content

Best practices for real-time streaming of eBPF SSL/TLS capture data in Kubernetes? #187

@aman1105-sa

Description

@aman1105-sa

I'm working on a Kubernetes-native SSL/TLS monitoring system using eBPF (similar to your lesson 30-sslsniff).

Current Setup:

  • Using eCapture (eBPF-based SSL capture tool) as a DaemonSet
  • Need to stream captured HTTP data in real-time to create Kubernetes CRDs
  • Facing issues with buffered stdout - data doesn't appear until process exits

Questions:

  1. What's the recommended approach for real-time streaming of eBPF capture data (perf buffers, ring buffers, or something else)?
  2. Have you seen any examples of integrating eBPF capture tools with Kubernetes for observability?
  3. Are there alternatives to stdout for getting immediate output from eBPF programs in daemon mode?

Any guidance or pointers to relevant lessons would be appreciated!

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions