Documentation
¶
Overview ¶
Package nettracer accounts for engine, subprocess and executor workload traffic at cgroup socket-buffer hooks.
Index ¶
- func CurrentNetnsCookie() (uint64, error)
- func EngineAccountingAvailable() bool
- func EngineAccountingError() error
- func InitCommandPlacement() (func() error, error)
- func WorkloadParentPath(cgroupParent string) (string, bool)
- type Command
- type EngineSample
- type Sample
- type Tracer
- func (t *Tracer) AddInternalPrefix(prefix netip.Prefix) error
- func (t *Tracer) AddInternalPrefixesForInterface(ifindex int) error
- func (t *Tracer) AddInternalPrefixesForVeth(name string) error
- func (t *Tracer) AttachWorkloads(parent string) (rerr error)
- func (t *Tracer) Close() error
- func (t *Tracer) Workload(path string, netnsCookie uint64) (_ *Workload, rerr error)
- type Workload
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CurrentNetnsCookie ¶
CurrentNetnsCookie returns the cookie of the calling thread's network namespace, as bpf_get_netns_cookie reports it for that namespace's packets.
func EngineAccountingAvailable ¶
func EngineAccountingAvailable() bool
EngineAccountingAvailable reports whether the engine cgroup programs are attached. Missing support is reported explicitly instead of returning zero counters that look authoritative.
func EngineAccountingError ¶
func EngineAccountingError() error
EngineAccountingError explains why engine-wide accounting is unavailable.
func InitCommandPlacement ¶
InitCommandPlacement keeps resource isolation available when eBPF cannot load. The engine owns the returned cleanup; clients never install this.
func WorkloadParentPath ¶
WorkloadParentPath returns the cgroup that contains every executor workload's cgroup for cgroupParent, as the OCI spec generator places them. Systemd slice parents name no path the engine can attach to.
Types ¶
type Command ¶
type Command struct {
// contains filtered or unexported fields
}
func PrepareCommand ¶
PrepareCommand places a command in its own accounting cgroup at clone time. Call before Start, and Close only after Wait (or after a daemon's lifetime). An error leaves cmd unchanged; callers can run it without network metrics.
func PrepareCommandIn ¶
PrepareCommandIn keeps a mount helper beneath its owning exec. Attach to the helper leaf, not the exec parent: container traffic is counted by TCX.
func (*Command) CgroupPath ¶
CgroupPath is the operation's private cgroup, retained until Close.
type EngineSample ¶
type EngineSample struct {
InternalRX uint64
InternalTX uint64
ExternalRX uint64
ExternalTX uint64
}
EngineSample is a cumulative engine-cgroup network-layer snapshot.
func SampleEngine ¶
func SampleEngine() (EngineSample, error)
SampleEngine returns cumulative packet counters for sockets in the engine's exact cgroup, in the engine network namespace. Sibling helper, module, and withExec cgroups remain excluded.
type Tracer ¶
type Tracer struct {
// contains filtered or unexported fields
}
Tracer owns the programs and maps shared by the engine, its subprocesses and executor workloads.
func Active ¶
func Active() *Tracer
Active returns the process-wide tracer used by network providers.
func (*Tracer) AddInternalPrefixesForInterface ¶
AddInternalPrefixesForInterface discovers the bridge containing ifindex and classifies all addresses routed directly by that bridge as internal.
func (*Tracer) AddInternalPrefixesForVeth ¶
AddInternalPrefixesForVeth classifies the addresses of the bridge that the named host-side veth is attached to as internal. It must be called in the network namespace containing the veth.
func (*Tracer) AttachWorkloads ¶
AttachWorkloads attaches the workload programs to parent, creating it if needed. Every workload cgroup created below it inherits them.
func (*Tracer) Workload ¶
Workload reserves counters for the workload cgroup at path, which must be a direct child of the attached workload parent, counting only sockets in the network namespace with netnsCookie. It creates the cgroup if the runtime has not yet, so the counters exist before the workload's first packet; the runtime adopts an existing, empty cgroup.