Topical Takes
Short, opinionated posts on eBPF, Linux internals, and the tools we all run in production.
How to Capture Packets on wg0 and Other Tunnel Interfaces on Linux: The Ethernet Header Is Not Missing, It Was Never There
Capturing on wg0, gre1 or tun0 hands you a bare IP packet, because a raw-IP tunnel device has no MAC header to give you; pktscope is a terminal packet analyzer whose TCX eBPF tap starts the snap at the MAC header on Ethernet-framed devices and at the network header on tunnels, so the decode and the hex offsets match the device you picked.
How to Monitor HTTP Traffic on Linux in 2026: What the Kernel Sees That Your Proxy Doesn't
A sidecar proxy sees the traffic you routed through it. The kernel's TC layer sees what actually crossed the wire, including loopback, without anything being rerouted. Compares OpenTelemetry, Envoy, tcpdump, Pixie, Cilium Hubble and httpwatch, and how to pick the one that answers your question.
How to Monitor HTTP Traffic on Linux in 2026: Why the Kernel Sees What Your Access Log Doesn't
How to see the HTTP requests crossing a Linux host, including the ones your access log never records because they never reached a handler. Covers eBPF capture at the kernel's TC layer, tcpdump, Coroot, Pixie, Cilium Hubble, a proxy and OpenTelemetry, with the commands to run and the kernel version each one needs.