# yeet docs, raw Markdown index

Every documentation page as a raw Markdown file. Fetch any URL below to
read its source. The rendered HTML pages at /docs/ carry no information
these files lack.

39 pages.

## Guides

- [Capabilities](/docs/raw/capabilities.md): Yeet is a JavaScript runtime that observes your system from the kernel boundary using a single daemon per machine.
- [FAQ](/docs/raw/faq.md): Yeet is a JavaScript runtime for building custom infrastructure tools that observe and act on your system from the kernel boundary.
- [Intro](/docs/raw/intro.mdx): yeet is a runtime for developing tools that observe and control your programs.
- [Set Alerts](/docs/raw/set-alerts.md): A yeet tool runs locally and renders to your terminal, but the same callback that updates your dashboard can also page you.

## Installation

- [Docker (Linux)](/docs/raw/install/docker-linux.md): You can run the yeet daemon inside a Docker container on a Linux host.
- [Docker (macOS/Windows)](/docs/raw/install/docker.md): Yeet requires a Linux kernel, so it can't run natively on macOS or Windows.
- [Installation](/docs/raw/install/index.md): yeet currently supports Linux natively.
- [Manual Installation](/docs/raw/install/manual-installation.md): If you prefer not to use the one-line installer, you can set up yeet manually using the instructions below for your package manager.
- [Terraform](/docs/raw/install/terraform.md): A complete working example of everything in this guide is available at github.com/yeet-src/terraform-aws-yeet-ec2-termination-handler.

## Writing scripts

- [eBPF](/docs/raw/scripts/ebpf.md): Yeet scripts load a compiled eBPF object (`.bpf.o`), attach its programs, and talk to its maps from JavaScript — ring buffers, hash maps, arrays, LPM tries, bloom filters, per-CPU maps, and `.data`/`.rodata`/`.bss` gl...
- [GraphQL modules](/docs/raw/scripts/graphql-modules.md): Importing a `.gql` or `.graphql` file produces a module with a single default export.
- [Overview](/docs/raw/scripts/index.md): Yeet scripts run inside a V8 isolate with a curated set of globals: the `yeet` object, the terminal, timers and `console` from the runtime reference, and `Worker` and `SharedWorker` for talking to other isolates.
- [Runtime reference](/docs/raw/scripts/runtime-reference.md): Global timer functions, behaving like their browser counterparts.
- [Terminal (tty & style)](/docs/raw/scripts/terminal.md): Low-level terminal control.
- [TUI](/docs/raw/scripts/tui.md): `yeet:tui` is a declarative terminal UI framework built into the runtime.
- [Workers](/docs/raw/scripts/workers.md): `Worker` and `SharedWorker` are globals in every script.
- [AI (yeet:ai)](/docs/raw/scripts/yeet-ai.md): `yeet:ai` is provider-agnostic AI chat.
- [Auth (yeet:auth)](/docs/raw/scripts/yeet-auth.md): `yeet:auth` signs the daemon in from a script.
- [BTF types (yeet:btf)](/docs/raw/scripts/yeet-btf.md): `yeet:btf` queries the kernel's BTF — the type information the running kernel carries about its own structs, unions, enums, and functions.
- [yeet global](/docs/raw/scripts/yeet-global.md): The `yeet` object is the primary host-provided API surface, installed as a global before script evaluation begins.
- [Symbols (yeet:sym)](/docs/raw/scripts/yeet-sym.md): `yeet:sym` inspects the symbols and debug information of a binary, the running kernel, or a live process.
- [Telemetry (yeet:telemetry)](/docs/raw/scripts/yeet-telemetry.md): `yeet:telemetry` turns metrics into the wire format the tools people already run expect — today, the Prometheus text exposition format (version 0.0.4).

## Example tools

- [airtop](/docs/raw/examples/airtop.md): htop for the airwaves. A live 802.11 (Wi-Fi) RF dashboard in your terminal.
- [claudefeed](/docs/raw/examples/claudefeed.md): `tail -f` for Claude Code. Every command a session runs, every file it opens, every TCP port it reaches or binds — decoded and streamed live to your terminal. Scoped to that session's process subtree. No other PIDs, n...
- [dialout](/docs/raw/examples/dialout.md): tcpdump for intent. What is this box dialing, and why?
- [docker-net](/docs/raw/examples/docker-net.md): A spatial, live-updating map of every container on the host.
- [grpcsnoop](/docs/raw/examples/grpcsnoop.md): `tcpdump` for gRPC. Watch the protobuf messages flowing between services, decoded to readable fields.
- [heatsink](/docs/raw/examples/heatsink.md): htop for your thermals. Six columns, four colors, the number that actually predicts a throttle.
- [httpinspect](/docs/raw/examples/httpinspect.md): `top` for the HTTP endpoints on your host.
- [Tools library](/docs/raw/examples/index.mdx): Ready-to-run tools built with yeet.
- [knicks-scoreboard](/docs/raw/examples/knicks-scoreboard.md): htop, but it's a Knicks game. Your CPU called from the Garden floor — user time versus the system, top processes as the starting five.
- [md-sentry](/docs/raw/examples/md-sentry.md): A tripwire for the files that tell your agent who it is. Watch every create, modify, delete, and rename of an agent's markdown brain in real time, tagged by whether the agent itself made the change.
- [metropolis](/docs/raw/examples/metropolis.md): An art-deco city that breathes your system.
- [proctop](/docs/raw/examples/proctop.md): A `top(1)`-like process viewer.
- [runfrom](/docs/raw/examples/runfrom.md): Every exec on your box, live. Catch the ones that shouldn't be running.
- [usbsnoop](/docs/raw/examples/usbsnoop.md): Live USB transfer sniffer from two fentry hooks. No usbmon, no hardware sniffer.

## cli

- [Overview](/docs/raw/cli/index.md): yeet is a daemon (`yeetd`) and a CLI that talks to it.
- [Running scripts](/docs/raw/cli/run.md): `yeet run` starts a script in a fresh isolate under the daemon, with your terminal attached.
- [Services](/docs/raw/cli/services.md): A service is a set of scripts the daemon keeps running for you.
