eBPF with Aya on Fedora
Write eBPF programs in Rust with Aya, deploy them to a Fedora 44 KVM lab, and visualize the output in Grafana via OpenTelemetry.
What this tutorial is
A chapter-based, hands-on path to writing real eBPF programs in Rust with Aya. You build each program on your Fedora 44 laptop, deploy it to a disposable Fedora 44 KVM virtual machine (so a bad program never touches your working kernel), drive load from Python 3.14 clients running in Podman, and watch traces, metrics, and logs land in Grafana through OpenTelemetry. It assumes you have read The Rust Programming Language โ this is not a Rust tutorial. All container images are UBI-based; all kernel tooling (bpftool, bpftrace, bcc) comes from Fedora/Red Hat repositories.
Foundations
Set up the disposable Fedora 44 KVM lab, the Grafana/OTel stack, and the Rust + Aya toolchain โ then write and deploy your first eBPF program.
Tracing the kernel
Observe kernel and syscall activity with kprobes, fentry/fexit, and tracepoints โ from file deletes and opens to process lifecycle and signals.
User-space & language probing
Turn the lens around: uprobes, USDT, and probing inside running applications and language runtimes โ bash, your own Rust binaries, TLS, and more.
Performance & resources
Measure where time and resources go: scheduling latency, hardware IRQs, sampling profiles, memory leaks, block-I/O patterns, and power.
Networking
See and shape packets: TCP connection latency and state, L7 tracing, sockops, TC, and XDP โ including a load balancer and packet capture.
Security & LSM
Enforce and observe security with LSM hooks and signal programs โ connection control, tamper detection, and lab-only offense to understand defense.
Schedulers (sched_ext)
Write real CPU schedulers in BPF with sched_ext / struct_ops, from a minimal policy to a more realistic one.
Application targets
Probe real workloads end to end: an nginx server, a three-signal OpenTelemetry capstone, and a postgres database, tying together kernel and user-space techniques.
Advanced kernel surface
The modern (2024โ2026) BPF feature set: kfuncs, BPF tokens, workqueues, struct_ops, dynptr, BPF arenas, iterators, and user ring buffers.
Operating eBPF
Run eBPF for real: CO-RE portability, L3AF-style zero-downtime upgrades, AI/GPU offloading, power management, and where to go next.
Field guide: the validation tools
Optional. The command-line tools we leaned on for validation all along โ bpftrace, bpftool, and the BCC tools โ and how to drive them from Python to turn one-liners into repeatable tools.
Retrospective
A look back across the whole arc โ from a kprobe counting unlink to operating a fleet โ what held throughout, and where eBPF and Aya go next.
Addenda
Optional extensions that apply the book's machinery to a special case โ starting with observing a homomorphic-encryption workload you deliberately cannot read.