Programming the Linux Kernel for Enhanced Observability, Networking, and Security
Liz Rice

#eBPF
#Linux
#Linux_Kernel
#Observability
#Networking
#Security
#BTF
🐝 ورود به دنیای eBPF و برنامهنویسی Kernel
🚀 eBPF فناوری تحولآفرینیه که اجازه میده کدهای سفارشی بنویسی و رفتار Kernel را بهصورت Dynamic تغییر بدی. این فناوری به بستری قدرتمند برای ساخت نسل تازهای از ابزارهای Security، Observability و Networking تبدیل شده است.
✨ ویژگیهای کلیدی
🧠 توضیح میده چرا eBPF طی چند سال اخیر به چنین فناوری مهمی تبدیل شده است.
💻 نحوه نوشتن کدهای مقدماتی eBPF، مدیریت Programها و متصلکردن آنها به Eventها را آموزش میده.
⚙️ ارتباط Componentهای eBPF با Linux و تأثیر آنها بر رفتار Operating System را بررسی میکنه.
🔍 نشان میده ابزارهای مبتنی بر eBPF چطور بدون تغییر اپلیکیشن یا Configuration آن، فرایند Instrumentation را انجام میدن.
🌐 نقش eBPF در ساخت ابزارهای جدید Observability، Security و Networking را توضیح میده.
📘 توضیح کتاب
📚 این کتاب کاربردی برای Developerها، System Administratorها، Operatorها و دانشجویانی نوشته شده که درباره eBPF کنجکاون و میخوان نحوه عملکرد آن را بهتر درک کنن. نویسنده، لیز رایس، همچنین پایه لازم را برای افرادی فراهم میکنه که قصد دارن نوشتن Programهای eBPF را شخصاً تجربه کنن.
🧩 کتاب ابتدا اهمیت eBPF و جایگاه آن در سیستمهای مدرن را توضیح میده. سپس با یک Hello World ساده، ساختار داخلی Programهای eBPF، System Callها، Verifier و انواع Program و Attachment را بررسی میکنه.
⚙️ در ادامه یاد میگیری Componentهای eBPF چطور با Linux تعامل میکنن و بدون ایجاد تغییر مستقیم در اپلیکیشنها، اطلاعات مربوط به Performance، Security و رفتار سیستم را جمعآوری میکنن.
🌐 فصلهای تخصصی کتاب کاربرد eBPF را در Networking و Security توضیح میدن. همچنین با فناوریها و مفاهیمی مثل CO-RE، BTF و Libbpf آشنا میشی و مسیر لازم برای ورود به eBPF Programming را دنبال میکنی.
📊 ابزارهای eBPF میتونن اپلیکیشنها را بدون تغییر کد یا Configuration آنها Instrument کنن. این قابلیت زمینه ساخت ابزارهایی را فراهم کرده که دید دقیقتری از رفتار Software Infrastructure ارائه میدن و مشکلات Performance یا Security را در سطح عمیقتری آشکار میکنن.
🔧 برای نمونه، اگر بدونی Eventها چطور Programهای eBPF را فعال میکنن، Mental Model دقیقتری از اطلاعاتی خواهی داشت که یک ابزار مبتنی بر eBPF هنگام نمایش Performance Metricها واقعاً اندازهگیری میکنه.
🔥 یک Application Developer ممکنه هنگام Performance Tuning از ابزاری مثل Parca برای تولید Flame Graph استفاده کنه تا Functionهایی را پیدا کنه که بیشترین زمان اجرا را مصرف میکنن. در بررسی ابزارهای Security نیز شناخت eBPF کمک میکنه نقاط قوت آن را بشناسی و از استفاده سادهانگارانهای که در برابر Attackها اثربخشی کمتری داره دوری کنی.
🐧 حتی اگر امروز از ابزارهای eBPF استفاده نمیکنی، این کتاب میتونه بینشهای جالبی درباره بخشهایی از Linux ارائه بده که شاید قبلاً به آنها توجه نکرده باشی. بیشتر Developerها Kernel را بدیهی در نظر میگیرن؛ چون زبانهای برنامهنویسی با
Abstractionهای سطح بالا اجازه میدن روی Application Development تمرکز کنن که خودش بهاندازه کافی دشواره.
🛠️ Developerها معمولاً برای انجام بهتر کار از Debuggerها و Performance Analyzerها استفاده میکنن. شناخت جزئیات داخلی یک Debugger یا ابزار Performance میتونه جالب باشه، اما ضروری نیست؛ همانطور که بیشتر افراد بدون نگرانی درباره نحوه ساخت ابزارهای eBPF از آنها استفاده خواهند کرد.
🪄 آرتور سی. کلارک نوشته بود: «هر فناوری بهاندازه کافی پیشرفته، از جادو قابلتشخیص نیست.» بااینحال، لیز رایس ترجیح میده وارد جزئیات بشه و بفهمه این ترفند جادویی چطور کار میکنه. اگر همین کنجکاوی را داشته باشی، eBPF Programming کمک میکنه درک دقیقتری از قابلیتهای این فناوری به دست بیاری.
🎯 بعد از مطالعه کتاب، ساختار eBPF و ارتباط آن با Linux Kernel را بهتر درک میکنی، Programهای مقدماتی eBPF مینویسی، آنها را به Eventها متصل میکنی و میتونی ابزارهای مبتنی بر eBPF را در حوزههای Performance، Observability، Security و Networking آگاهانهتر ارزیابی و استفاده کنی.
🎯 چیزهایی که یاد میگیری
📌 یاد میگیری چرا eBPF در چند سال اخیر به یکی از فناوریهای مهم زیرساخت Software تبدیل شده است.
💻 میتونی Programهای مقدماتی eBPF بنویسی، آنها را مدیریت کنی و به Eventها متصل کنی.
⚙️ درک میکنی Componentهای eBPF چطور با Linux ارتباط برقرار میکنن و رفتار Operating System را بهصورت Dynamic تغییر میدن.
🔍 یاد میگیری ابزارهای eBPF چطور بدون تغییر اپلیکیشنها یا Configuration آنها، فرایند Instrumentation را انجام میدن.
🌐 با کاربرد eBPF در Networking و ساخت ابزارهای زیرساختی جدید آشنا میشی.
🔐 میتونی نقاط قوت eBPF در Security را بشناسی و از روشهای سادهانگارانه و کماثر در برابر Attackها دوری کنی.
📊 یاد میگیری Performance Metricها و Flame Graphهای تولیدشده با ابزارهایی مثل Parca را بهتر تحلیل کنی.
🧩 با CO-RE، BTF، Libbpf، eBPF Verifier و انواع Program و Attachment آشنا میشی.
👤 این کتاب برای چه کسانیه؟
💻 این کتاب برای Developerها، System Administratorها، Operatorها و دانشجویانی مناسبه که درباره eBPF کنجکاون و میخوان اطلاعات بیشتری درباره نحوه عملکرد آن به دست بیارن. مطالب همچنین پایه مناسبی برای افرادی فراهم میکنن که قصد دارن Programهای eBPF بنویسن.
💼 eBPF بستری قدرتمند برای نسل جدید ابزارهای Instrumentation و Tooling فراهم کرده؛ بنابراین احتمالاً طی سالهای آینده فرصتهای شغلی مناسبی برای eBPF Developerها وجود خواهد داشت.
🛠️ برای استفاده از کتاب، حتماً لازم نیست قصد نوشتن کد eBPF داشته باشی. اگر در Operations، Security یا هر حوزه مرتبط با Software Infrastructure فعالیت میکنی، احتمال زیادی وجود داره که امروز یا طی چند سال آینده با ابزارهای مبتنی بر eBPF روبهرو بشی. شناخت ساختار داخلی این ابزارها کمک میکنه مؤثرتر از آنها استفاده کنی.
🐧 کتاب فرض میکنه با Commandهای پایه Shell در Linux راحت هستی و با مفهوم استفاده از Compiler برای تبدیل Source Code به Executable Program آشنایی داری. چند نمونه ساده از Makefileها نیز ارائه میشن و حداقل آشنایی با نحوه استفاده make از این Fileها در نظر گرفته شده است.
🧑💻 مثالهای کدنویسی فراوانی با Python، C و Go در کتاب وجود دارن. برای استفاده از این مثالها به دانش عمیق این زبانها نیاز نیست، اما اگر بهطور کلی با خواندن Code راحت باشی، بیشترین بهره را از کتاب میبری. آشنایی با مفهوم Pointer که یک محل در Memory را مشخص میکنه هم لازم است.
📖 فهرست مطالب
فصل ۱. eBPF چیست و چرا اهمیت دارد؟
فصل ۲. Hello World در eBPF
فصل ۳. کالبدشناسی یک Program در eBPF
فصل ۴. System Call مربوط به bpfQ
فصل ۵. CO-RE، BTF و Libbpf
فصل ۶. eBPF Verifier
فصل ۷. انواع eBPF Program و Attachment
فصل ۸. کاربرد eBPF در Networking
فصل ۹. کاربرد eBPF در Security
فصل ۱۰. eBPF Programming
فصل ۱۱. آینده تکامل eBPF
👤 درباره نویسنده
🐝 لیز رایس Chief Open Source Officer در Isovalent است؛ شرکتی متخصص در eBPF و سازنده پروژه Cilium برای Cloud Native Networking، Security و Observability.
🏢 او عضو CNCF Governing Board و هیئتمدیره OpenUK است.
📋 لیز رایس از سال ۲۰۱۹ تا ۲۰۲۲ ریاست Technical Oversight Committee در CNCF را بر عهده داشت و در سال ۲۰۱۸ نیز یکی از رؤسای مشترک KubeCon + CloudNativeCon بود.
📚 او نویسنده کتاب Container Security منتشرشده توسط O’Reilly است.
⚙️ لیز تجربه گستردهای در Software Development، مدیریت تیم و Product Management داره که از فعالیت روی Network Protocolها و Distributed Systemها و حضور در حوزههای فناوری دیجیتال مثل VOD، Music و VoIP به دست اومده است.
🚴 وقتی مشغول نوشتن Code یا صحبت درباره آن نیست، از دوچرخهسواری در مکانهایی با آبوهوای بهتر از زادگاهش London، شرکت در مسابقههای مجازی Zwift و ساخت موسیقی با نام هنری Insider Nine لذت میبره.
What is eBPF? With this revolutionary technology, you can write custom code that dynamically changes the way the kernel behaves. It's an extraordinary platform for building a whole new generation of security, observability, and networking tools.
This practical book is ideal for developers, system administrators, operators, and students who are curious about eBPF and want to know how it works. Author Liz Rice, chief open source officer with cloud native networking and security specialists Isovalent, also provides a foundation for those who want to explore writing eBPF programs themselves.
With this book, you will:
Table of Contents
Chapter 1. What Is eBPF, and Why Is It Important?
Chapter 2. eBPf's "Hello World"
Chapter 3. Anatomy of an eBPF Program
Chapter 4. The bpfQ System Call
Chapter 5. CO-RE, BTF, and Libbpf
Chapter 6. The eBPF Verifier
Chapter 7. eBPF Program and Attachment Types
Chapter 8. eBPF for Networking
Chapter 9. eBPF for Security
Chapter 10. eBPF Programming
Chapter 11. The Future Evolution of eBPF
Who This Book Is For
This book is for developers, system administrators, operators, and students who are curious about eBPF and want to know more about how it works. It will provide a foundation for those who want to explore writing eBPF programs themselves. Since eBPF provides a great platform for a whole new generation of instrumentation and tooling, there will likely be gainful employment for eBPF developers for some years to come.
But you don’t necessarily need to be planning to write eBPF code yourself for this book to be useful to you. If you work in operations, security, or any other role that involves software infrastructure, you’re likely to come across eBPF-based tooling, now or over the next few years. If you understand something about the internals of these tools, you’ll be in a better position to use them effectively. For example, if you know how events can trigger eBPF programs, you’ll have a better mental model for exactly what an eBPF-based tool is really measuring when it shows you performance metrics. If you’re an application developer, you might also come into contact with some of these eBPF-based tools—for example, if you are performance tuning an application, you might use a tool like Parca to generate flame graphs showing which functions are taking the most time. If you are evaluating security tools, this book will help you understand where eBPF shines, and how to avoid using it in a naïve way that is less effective against attacks.
Even if you’re not using eBPF tools today, I hope this book will give you interesting insights into areas of Linux that you might not have considered before. Most developers take the kernel for granted, as they use programming languages with convenient higher-level abstractions that allow them to focus on the work of application development—which is plenty hard enough! They use tools like debuggers and performance analyzers to help them do their job effectively. Knowing the internals of how a debugger or performance tool works might be interesting, but it’s not essential. Yet, for many of us, it’s fun and fulfilling to go down the rabbit hole to find out more. In the same way, most people will use eBPF tools without having to worry about how they are built. Arthur C. Clarke wrote that “any sufficiently advanced technology is indistinguishable from magic,” but personally, I like to dig in and find out how the magic trick works. You might be like me and feel compelled to explore eBPF programming to get a better feel for what is possible with this technology. If so, I think you’ll enjoy this book.
Prerequisite Knowledge
This book assumes you are comfortable with basic shell commands on Linux and with the idea of using a compiler to turn source code into an executable program. There are some simple example extracts from Makefiles, on the assumption that you have at least a minimal understanding of how make uses these files.
There are lots of code examples in Python, C, and Go. You won’t need in-depth knowledge of those languages to get something out of these examples, but you’ll get the most out of the book if you are generally happy to read some code. I’m also assuming you are familiar with the idea of pointers, which identify a memory location.
Liz Rice is the chief open source officer with eBPF specialists at Isovalent, creators of the Cilium cloud native networking, security and observability project. She sits on the CNCF Governing Board and on the Board of OpenUK. She was chair of the CNCF's Technical Oversight Committee in 2019-2022, and co-chair of KubeCon + CloudNativeCon in 2018. She is also the author of Container Security published by O'Reilly.
She has a wealth of software development, team, and product management experience from working on network protocols and distributed systems and in digital technology sectors such as VOD, music, and VoIP. When not writing code, or talking about it, Liz loves riding bikes in places with better weather than her native London, competing in virtual races on Zwift, and making music under the pseudonym Insider Nine.









