Tracing SSL/TLS connections using eBPF
blog.px.dev
blog.px.dev
It's also a trivial bpftrace program, which we've been recommending for beginners over bcc for years (including in my eBPF summit keynote two years running).
This article would make sense if it was written in 2015.
Also, sometimes I think it’s a bummer when stuff like this comes up when tons of work has already been done. It’s pretty reliable that unless you have a very specific use-case, there’s probably a BPF tool written to do something.
One solution is to spend several years developing expertise and finding the edge of the known world, beyond which is yet to be explored. In this space it means knowing all the tools that are out there. It's no coincidence that I find it easy to draw these diagrams:
https://www.brendangregg.com/Perf/linux_observability_tools....
... and to find new areas where there are missing tools. These skills are connected!
But I'm lucky to have had roles where I have spent over a decade specializing in performance analysis and tooling. For a lot of people with limited time, your best bet is to not learn the entire world, but to learn some narrow specific use case and see what tools exist just for that, and how it can be improved. Just like you say: a very specific use case.
Plus check the open issues on bcc/bpftrace github, since there's stuff there (not just bugs, but tool/feature ideas) that haven't been done yet.
It's only that way if you see the main purpose of this blog post to explain someone how to trace a TLS connection. That could indeed be shortened to 10 lines of "use this existing tool". However to me it doesn't seem like this is the main goal of the post. It mostly uses TLS tracing as an example to describe how eBPF based tracing works, and what components are necessary for it. It can be seen as a tutorial on how to add tracing support for any other userspace function, instead of just being an explanation on how to use a predefined tool to use a single problem. I don't think its a bad thing if more of those tutorials show up.
(However, of course kprobes and uprobes could be combined to at least become aware of all traffic that did not trigger any uprobe)