Topical Takes
Short, opinionated posts on eBPF, Linux internals, and the tools we all run in production.
How to Sandbox an AI Coding Agent on Linux in 2026: What the Kernel Can Refuse That Permissions Only Ask About
Claude Code, Codex, Aider and self-hosted agents run with your full filesystem access and choose what to read on their own — here are the six real ways to confine one, what each actually covers, and why the built-in sandboxes govern shell commands rather than the agent's own file reads.
How to Test and Debug WebSocket Traffic on Linux in 2026: Your Integration Test Asserts on the Client, Not the Wire
A WebSocket integration test asserts on what your client library returned, which is not what crossed the connection. How to see the real frames inside wss:// on Linux with wssnoop, Wireshark and a TLS keylog, mitmproxy and Chrome DevTools, and how to turn a captured session into a fixture your test suite can replay.
Traversal vs yeet: An AI SRE Reasons Over Your Telemetry, It Doesn't Collect It
Traversal's AI SRE runs causal search over the observability stack you already have, so its ceiling is what your instrumentation recorded; yeet is a JavaScript runtime for Linux ops that loads an eBPF probe for one missing fact while the incident is open. Which order to use them in, and how to test it against your own postmortems.
How to Monitor HTTP Traffic on Linux in 2026: What the Kernel Sees That Your Proxy Doesn't
A sidecar proxy sees the traffic you routed through it. The kernel's TC layer sees what actually crossed the wire, including loopback, without anything being rerouted. Compares OpenTelemetry, Envoy, tcpdump, Pixie, Cilium Hubble and httpwatch, and how to pick the one that answers your question.
How to Capture 802.11 Frames on a Connected Interface on Linux: Your Radio Already Hears Them
Monitor mode drops the association you are trying to diagnose, so airodump-ng and Kismet cannot watch the link you are standing on; airtop attaches eBPF fentry programs to mac80211 and cfg80211 to read 802.11 frames, RSSI in dBm and deauth counts on a normal connected Linux interface.
How to Monitor HTTP Traffic on Linux in 2026: Why the Kernel Sees What Your Access Log Doesn't
How to see the HTTP requests crossing a Linux host, including the ones your access log never records because they never reached a handler. Covers eBPF capture at the kernel's TC layer, tcpdump, Coroot, Pixie, Cilium Hubble, a proxy and OpenTelemetry, with the commands to run and the kernel version each one needs.