eBPF: Preventing Garbage HTTP Payloads When Reading Kernel Scatter-Gather Buffers
How our nettap eBPF agent produced garbage HTTP bodies from kernel iov_iter scatter-gather buffers, and the CO-RE plus task-local storage fix that made it correct.
Browse 29 posts in this category
How our nettap eBPF agent produced garbage HTTP bodies from kernel iov_iter scatter-gather buffers, and the CO-RE plus task-local storage fix that made it correct.
AI pushed throughput up 59%, yet median delivery got worse. The bottleneck moved to validation. How replaying production traffic in CI closes the gap.
The trace was sampled out. I found the bug anyway — by filtering recorded traffic on the customer's email instead of a trace ID. Here's how to follow one request across four services with no trace IDs and no OpenTelemetry.
Capture production traffic and store it in your own Elasticsearch with Speedscale BYOC. Pull it locally with es-gather.py and reproduce bugs with proxymock.
A Kubeshark alternative that goes beyond observability. Stream live cluster traffic into proxymock, then replay or mock it locally from your laptop.
Export recorded proxymock traffic to Datadog Synthetics in one command. Auth headers redacted, global variables created. No scripting, no flaky journeys.
Observability tells you what failed—but not how to recreate it. Why reproducibility is the missing fourth pillar, and what that means for incident response.
Learn the 4 golden signals — latency, traffic, errors, and saturation — and how to use them for monitoring, alerting, and pre-release testing.
Learn how to capture, inspect, archive encrypted microservice traffic with Speedscale's eBPF collector, no certificate management or code changes required.
Choose the desktop proxymock or the hosted cloud trial to get started.