awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
aya-rs avatar

aya-rs/aya

0
View on GitHub↗
4,321 Stars·397 Forks·Rust·apache-2.0·7 Aufrufeaya-rs.dev/book↗

Aya

Aya is a Rust-native framework for writing, compiling, and loading eBPF programs into the Linux kernel. It provides a complete development environment that eliminates the need for a C toolchain or libbpf, allowing developers to work entirely within the Rust ecosystem. The framework manages the full lifecycle of eBPF programs, including async runtime integration, CO-RE BTF resolution for kernel version portability, ELF-based program loading, and safe kernel memory access.

The framework distinguishes itself through its pure Rust compilation pipeline, which compiles Rust source code directly into eBPF bytecode without requiring external compilers. It supports kernel hook attachment across multiple attachment points including tracepoints, kprobes, cgroups, and network interfaces. Aya also provides safe packet parsing with bound checks for Ethernet, IPv4, TCP, and UDP headers, along with userspace-kernel map communication for synchronizing data between kernel-space eBPF programs and userspace applications.

The project covers the full eBPF development lifecycle, including program writing with support for function calls and global variables, program loading and attachment, kernel observability through structured log emission and consumption, and network packet processing with XDP and socket filters. It includes project scaffolding for generating new Rust eBPF project skeletons with the correct toolchain and program type, as well as toolchain installation commands to prepare the development environment.

Features

  • eBPF Frameworks for Rust - Provides a complete Rust-native framework for writing, compiling, and loading eBPF programs into the Linux kernel.
  • eBPF Function Call Relocations - Support function call relocation and global data maps so eBPF programs can call functions and use initialized globals.
  • eBPF Log Consumers - Provides a userspace API to read and process structured log messages emitted by eBPF programs.
  • Kernel Event Hooks - Loads compiled eBPF objects into the kernel and attaches them to hook points like system calls or network events.
  • Kernel-Space Packet Processing - Filters, redirects, and inspects network packets at the kernel level using XDP and socket filters.
  • Kernel Bytecode Execution - Loads compiled eBPF bytecode into the Linux kernel for execution.
  • CO-RE Relocation - Resolves kernel data structure offsets at load time using BTF for portable eBPF binaries across kernel versions.
  • eBPF Lifecycle Management - Manages the full lifecycle of eBPF programs including loading, attachment, logging, and event handling from userspace.
  • eBPF Object Loading - Loads compiled eBPF programs from ELF object files, resolving program references and maps for kernel execution.
  • Network Interface Attachments - Loads compiled eBPF objects and attaches them to network interfaces for packet processing.
  • Kernel Map Management - Creates and interacts with kernel-side data structures that share state between user-space and eBPF programs.
  • eBPF Program Deployment - Loads compiled eBPF programs into the kernel and manipulates them from user-space.
  • CO-RE Portable eBPF Deployments - Builds single compiled eBPF binaries that run across different Linux kernel versions using CO-RE and BTF.
  • Event-Triggered Programs - Writes kernel-space programs in Rust that run inside the Linux kernel in response to events.
  • XDP Program Writers - Provides a Rust-native API for writing XDP programs that process incoming network packets.
  • eBPF Kprobe Attachments - Attaches eBPF programs to kernel function entry points via kprobes for custom logic execution.
  • Kernel-Userspace Shared Maps - Synchronizes data between kernel-space eBPF programs and userspace applications using shared memory maps.
  • Userspace Map Populators - Insert entries into an eBPF map from a userspace program to dynamically update the packet filtering policy at runtime.
  • BTF and CO-RE Resolvers - Resolves kernel data structure offsets at load time using BTF for portable eBPF binaries.
  • eBPF Async Lifecycle Managers - Provides async runtime integration for managing non-blocking eBPF program lifecycle and event handling.
  • eBPF Bytecode Compilers - Compiles Rust source code directly into eBPF bytecode without requiring a C toolchain or external compiler.
  • Pure Rust Compilation Pipelines - Compiles Rust source code directly into eBPF bytecode without requiring a C toolchain or external compiler.
  • Kernel Execution Hooks - Binds eBPF programs to kernel attachment points such as tracepoints, kprobes, cgroups, and network interfaces.
  • Kernel Event Observability - Monitors system events by attaching eBPF programs to tracepoints and kprobes for debugging and performance analysis.
  • Protocol Header Parsers - Provides safe parsing of Ethernet, IPv4, TCP, and UDP headers with bound checks.
  • Safe Packet Header Parsers - Ships safe packet parsing with bound checks for Ethernet, IPv4, TCP, and UDP headers.
  • IP Blocklist Droppers - Drops packets by looking up destination IP addresses in a blocklist map.
  • Source IP Blocklist Droppers - Filters packets by looking up source IP addresses in a hash map and dropping matches.
  • eBPF Socket Filters - Attaches eBPF programs to network sockets for per-packet inspection and modification.
  • Bidirectional Traffic Inspectors - Attaches classifier programs to qdiscs for bidirectional packet inspection and decision-making.
  • Async Runtime Integrations - Integrates eBPF program lifecycle and event handling with async runtimes for non-blocking operation.
  • eBPF Context Memory Copiers - Provides safe kernel memory access by copying data structures into eBPF context without page faults.
  • eBPF Context Readers - Copies kernel data structures into eBPF context safely to prevent page faults.
  • Userspace Memory Readers - Read a string from userspace memory inside an eBPF program using a per-CPU buffer to work around stack limits.
  • eBPF Cgroup Hooks - Attaches eBPF programs to cgroup hooks to execute custom logic on process operations.
  • eBPF Log Emissions - Emits structured log messages from kernel-space eBPF code that are received and printed by the userspace loader.
  • Tracepoint Monitoring - Attaches eBPF programs to static kernel tracepoints to monitor events like system calls or scheduler activity.
  • Packet Arrival Logging - Logs a message from inside an eBPF program each time a packet arrives, visible in user-space output.
  • Packet Metadata Extraction Logging - Outputs extracted packet information such as source IP and port to the kernel log for debugging or monitoring.
  • Packet Field Extractors - Ships safe packet parsing with bound checks to extract IP addresses and ports from headers.
  • Structured Logging - Emits structured log messages from kernel-space eBPF programs using the info macro for debugging or monitoring.
  • Development Frameworks - Rust library for writing and managing eBPF objects.

Star-Verlauf

Star-Verlauf für aya-rs/ayaStar-Verlauf für aya-rs/aya

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Open-Source-Alternativen zu Aya

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Aya.
  • eunomia-bpf/bpf-developer-tutorialAvatar von eunomia-bpf

    eunomia-bpf/bpf-developer-tutorial

    4,145Auf GitHub ansehen↗

    This project is an educational resource providing a comprehensive development tutorial for writing and loading eBPF programs using C, Go, and Rust within the Linux kernel. It serves as a technical guide for developing custom logic to execute directly in the kernel. The materials cover specialized domains including kernel observability and tracing, security implementation for intrusion detection, and high-performance network engineering for packet filtering and load balancing. It also includes dedicated manuals for Linux kernel tracing and the use of kprobes, uprobes, and tracepoints. The pro

    Cbpfebpfexamples
    Auf GitHub ansehen↗4,145
  • cilium/ebpfAvatar von cilium

    cilium/ebpf

    7,529Auf GitHub ansehen↗

    This project is a Go library and runtime for loading and managing eBPF programs and maps. It provides a bytecode loader and kernel interface to inject instructions into kernel hooks for system-level execution and observability across both Linux and Windows operating systems. The library features a relocation engine and tooling to ensure program compatibility across different kernel versions and distributions. It supports portable deployment by embedding compiled objects for multiple CPU architectures into a single binary and provides the ability to load signed system drivers on Windows. The

    Gobtfebpfgo
    Auf GitHub ansehen↗7,529
  • inspektor-gadget/inspektor-gadgetAvatar von inspektor-gadget

    inspektor-gadget/inspektor-gadget

    2,720Auf GitHub ansehen↗

    Inspektor Gadget is an eBPF observability toolset and program framework designed for tracing Linux systems and debugging Kubernetes nodes. It provides a suite of tools to collect kernel-level telemetry and export system metrics via the OpenTelemetry standard. The project distinguishes itself by packaging inspection tools as OCI-compliant container images, allowing for standardized distribution and deployment across clusters and hosts. It employs a modular data processing pipeline that utilizes WebAssembly modules to transform and filter telemetry, and leverages Compile Once Run Everywhere for

    Cbpfbpf-programscncf-project
    Auf GitHub ansehen↗2,720
  • aquasecurity/traceeAvatar von aquasecurity

    aquasecurity/tracee

    4,377Auf GitHub ansehen↗

    Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho

    Gobpfdockerebpf
    Auf GitHub ansehen↗4,377
Alle 30 Alternativen zu Aya anzeigen→

Häufig gestellte Fragen

Was macht aya-rs/aya?

Aya is a Rust-native framework for writing, compiling, and loading eBPF programs into the Linux kernel. It provides a complete development environment that eliminates the need for a C toolchain or libbpf, allowing developers to work entirely within the Rust ecosystem. The framework manages the full lifecycle of eBPF programs, including async runtime integration, CO-RE BTF resolution for kernel version portability, ELF-based program loading, and safe kernel memory access.

Was sind die Hauptfunktionen von aya-rs/aya?

Die Hauptfunktionen von aya-rs/aya sind: eBPF Frameworks for Rust, eBPF Function Call Relocations, eBPF Log Consumers, Kernel Event Hooks, Kernel-Space Packet Processing, Kernel Bytecode Execution, CO-RE Relocation, eBPF Lifecycle Management.

Welche Open-Source-Alternativen gibt es zu aya-rs/aya?

Open-Source-Alternativen zu aya-rs/aya sind unter anderem: eunomia-bpf/bpf-developer-tutorial — This project is an educational resource providing a comprehensive development tutorial for writing and loading eBPF… cilium/ebpf — This project is a Go library and runtime for loading and managing eBPF programs and maps. It provides a bytecode… inspektor-gadget/inspektor-gadget — Inspektor Gadget is an eBPF observability toolset and program framework designed for tracing Linux systems and… facebookincubator/katran — Katran is an eBPF-based Layer 4 load balancer designed for high-performance network packet forwarding directly within… aquasecurity/tracee — Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events… bpftrace/bpftrace — bpftrace is a high-level eBPF tracing tool and kernel instrumentation framework for Linux. It provides a tracing…