A comprehensive, no-fluff guide to writing kernel networking software with eBPF in Rust from first principles: the Linux packet path and the TCP/IP stack, the eBPF virtual machine, verifier and maps, the XDP and tc data planes, sockmap and cgroup hooks, Kubernetes networking with Cilium - all wrapped around a complete service-mesh data path capstone, tuned for software engineers working at the networking level.
https://arpanpathak.github.io/ebpf-rust-networking-book/
- Part I - Foundations (Chapters 1-3): the Linux packet path from the NIC to your socket, the eBPF virtual machine - verifier, JIT, BTF - and the Aya toolchain that brings eBPF to Rust.
- Part II - eBPF Programs, Maps & the Data Path (Chapters 4-6): the map contract between kernel and userspace, XDP at line rate, and the traffic control hooks on the other side of the stack.
- Part III - Protocols, Sockets & the Kernel Data Plane (Chapters 7-9): TCP/IP and the receive path with GRO/GSO and RSS, sockmap and SK_MSG socket redirect, and cgroup hooks for filtering and resource control.
- Part IV - Kubernetes Networking & Cilium (Chapters 10-12): the Kubernetes networking model, CNI and kube-proxy; Cilium's eBPF data plane that replaces iptables and iptables-based proxies; and the service mesh, network policies, mTLS and Hubble observability on top.
- Part V - Production Systems Engineering (Chapters 13-15): performance engineering for packet-rate software, testing and debugging against the verifier, and the security model - and attack surface - of eBPF itself.
- Part VI - The Capstone (Chapter 16): a complete service-mesh data
path in Rust - XDP load balancing, sockmap socket redirect, and a
Hubble-style observability ring buffer - run against a real
kindcluster with Cilium.
Plus a foreword, an epilogue, and three appendices (Aya & eBPF API reference, networking & kernel notation, recommended reading & tools).
- Every concept explained from first principles; every eBPF hook, helper, map type and Aya API defined before use.
- Every code block fully commented, verifier-conscious, and built in the shape the kernel accepts - the same discipline expected in a kernel or cloud-networking code review.
- A complete capstone: an XDP load balancer, sockmap socket redirection and a ring-buffer observability pipeline in one Rust workspace, deployed to a real cluster.
- 2D SVG diagrams for every chapter in the Night Owl palette: the packet path, the verifier pipeline, map layouts, XDP and tc hook positions, sockmap redirects, Kubernetes service routing, the Cilium data plane, and the capstone architecture.
- A Night Owl inspired dark theme (bluish-black, easy on the eyes) with full support for printing.
ebpf-rust-networking-book/
βββ LICENSE # MIT license
βββ CODE_OF_CONDUCT.md # Contributor Covenant 2.1
βββ CONTRIBUTING.md # How to contribute (read this first)
βββ SECURITY.md # How to report vulnerabilities
βββ CODING_STANDARDS.md # The book's constitution
βββ .github/workflows/
β βββ deploy-pages.yml # GitHub Actions -> GitHub Pages
βββ book/
β βββ book.toml # mdBook configuration
β βββ custom.css # Night Owl dark theme
β βββ src/ # Markdown source of the book
βββ code/ # Buildable companions, one per chapter
Requires mdBook v0.5.x:
mdbook build book # compile to book/book/
mdbook serve book # live preview at http://localhost:3000The Rust companions need the Aya toolchain: bpf-linker for the kernel-side
programs and a plain Rust toolchain for the userspace side. Loading and
running the eBPF programs requires Linux 5.15+ with CONFIG_BPF,
CONFIG_BPF_SYSCALL and CONFIG_DEBUG_INFO_BTF=y; the capstone needs a
kind cluster or any small Kubernetes distribution.
Corrections, clarifications and missing concepts are all welcome. Please read CONTRIBUTING.md and CODE_OF_CONDUCT.md first. If you find a bug in a program, a packet-path claim, or a number, open an issue - the book is a living document.
MIT. See LICENSE for details.