We Put an L7 Firewall in the Kernel
Application-layer firewall decisions at XDP, before a socket buffer exists. We built a firewall that decides on HTTP/2 headers in the kernel with eBPF and lets you write the policy as a JavaScript app. Matching a header costs under 200ns, the request around it costs microseconds, and it runs on cleartext HTTP/2 behind TLS termination. Here's how it works and what we measured.