eBPF looks cheap but isn't free: Bitbison's deep dive on hooks, CO-RE reads and rings

tianyin_xu · x · 2026-09-03

eBPF underlies most modern infrastructure—containers, Kubernetes networking, and most security products—and everyone assumes it's cheap. Bitbison notes it can be, but there are plenty of performance foot-guns. The company hooks massive numbers of syscalls to build a causal model of every event on a system (powering its verifiable Linux security platform), so slowdowns matter. Their full writeup covers hooking, CO-RE reads, maps, rings, and dynamic data structures.

Original post →

More from Infra

Infra channel →