How eBPF Empowers Developers to Observe Inside the Linux Kernel in a Safe and Unintrusive Way

How eBPF Empowers Developers to Observe Inside the Linux Kernel in a Safe and Unintrusive Way

June 22, 2026 · 44 min

About this episode

Daniel Finneran discusses the evolution of eBPF and its impact on Linux kernel observability and security.

Daniel Finneran explores how eBPF has evolved far beyond its roots in packet filtering into a robust, safe way to extend the Linux kernel. He explains how the eBPF "verifier", the security guardrail, enables implementation of deep observability and networking without the risks of traditional kernel modules or the slow upstreaming process. He touches on tools like Tetragon that leverage eBPF for "front-foot" security enforcement, proactively intercepting threats such as buffer overflows before they execute, while providing visibility into file systems and drivers without intrusive instrumentation. Read a transcript of this interview: https://bit.ly/4ew9ONB Newsletter: Subscribe to the Software Architects' Newsletter, a monthly roundup of the patterns and technologies senior practitioners are working through, with the news and lessons from people doing the work: https://www.infoq.com/software-architects-newsletter InfoQ Online Certification Programs: 5-week online cohorts for senior engineers and architects, built around QCon talks. Programs now cover software architecture, AI engineering, and organizational architecture. Each week you join a four-hour live session with a…

People in this episode

Guest: Daniel Finneran

Topics covered

Keywords

Mentioned in this episode

Organizations: InfoQ

Products: Tetragon

More episodes of The InfoQ Podcast

Explore listener stats, chart rankings, contacts and more on the The InfoQ Podcast podcast page.