Beyond Power and Magic: Forging Stable eBPF Tools for the Post-Demon King Era - K. Tada & C. Gaggini
Ebpf Bpff Linux kernel Kprobe Tracepoint Btf Co Re Fentry Kfuncs Cloud Native Kubernetes Observability Runtime security Kubecon
This KubeCon talk explores how to build durable eBPF tools that survive kernel upgrades and production environments. It compares traditional hooks (kprobes, tracepoints) with newer stable interfaces (fentry/fexit, kfuncs) and explains how BTF and CO-RE enable cross-kernel portability without constant rewrites. Designed for platform engineers and developers building production eBPF observability or security tools.