nettracer

package
v1.0.0-beta.16 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 23 Imported by: 0

Documentation

Overview

Package nettracer accounts for engine, subprocess and executor workload traffic at cgroup socket-buffer hooks.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CurrentNetnsCookie

func CurrentNetnsCookie() (uint64, error)

CurrentNetnsCookie returns the cookie of the calling thread's network namespace, as bpf_get_netns_cookie reports it for that namespace's packets.

func EngineAccountingAvailable

func EngineAccountingAvailable() bool

EngineAccountingAvailable reports whether the engine cgroup programs are attached. Missing support is reported explicitly instead of returning zero counters that look authoritative.

func EngineAccountingError

func EngineAccountingError() error

EngineAccountingError explains why engine-wide accounting is unavailable.

func InitCommandPlacement

func InitCommandPlacement() (func() error, error)

InitCommandPlacement keeps resource isolation available when eBPF cannot load. The engine owns the returned cleanup; clients never install this.

func WorkloadParentPath

func WorkloadParentPath(cgroupParent string) (string, bool)

WorkloadParentPath returns the cgroup that contains every executor workload's cgroup for cgroupParent, as the OCI spec generator places them. Systemd slice parents name no path the engine can attach to.

Types

type Command

type Command struct {
	// contains filtered or unexported fields
}

func PrepareCommand

func PrepareCommand(cmd *exec.Cmd) (_ *Command, rerr error)

PrepareCommand places a command in its own accounting cgroup at clone time. Call before Start, and Close only after Wait (or after a daemon's lifetime). An error leaves cmd unchanged; callers can run it without network metrics.

func PrepareCommandIn

func PrepareCommandIn(cmd *exec.Cmd, parent string) (*Command, error)

PrepareCommandIn keeps a mount helper beneath its owning exec. Attach to the helper leaf, not the exec parent: container traffic is counted by TCX.

func (*Command) CgroupPath

func (c *Command) CgroupPath() string

CgroupPath is the operation's private cgroup, retained until Close.

func (*Command) Close

func (c *Command) Close() error

func (*Command) Sample

func (c *Command) Sample() (Sample, error)

func (*Command) WaitEmpty

func (c *Command) WaitEmpty(ctx context.Context) error

WaitEmpty waits for the daemon and all descendants, not just its launcher. Keep sampling until this returns, before releasing the counters.

type EngineSample

type EngineSample struct {
	InternalRX uint64
	InternalTX uint64
	ExternalRX uint64
	ExternalTX uint64
}

EngineSample is a cumulative engine-cgroup network-layer snapshot.

func SampleEngine

func SampleEngine() (EngineSample, error)

SampleEngine returns cumulative packet counters for sockets in the engine's exact cgroup, in the engine network namespace. Sibling helper, module, and withExec cgroups remain excluded.

type Sample

type Sample struct {
	InternalRX uint64
	InternalTX uint64
	ExternalRX uint64
	ExternalTX uint64
}

Sample is a cumulative snapshot for one workload or subprocess.

type Tracer

type Tracer struct {
	// contains filtered or unexported fields
}

Tracer owns the programs and maps shared by the engine, its subprocesses and executor workloads.

func Active

func Active() *Tracer

Active returns the process-wide tracer used by network providers.

func New

func New() (*Tracer, error)

func (*Tracer) AddInternalPrefix

func (t *Tracer) AddInternalPrefix(prefix netip.Prefix) error

func (*Tracer) AddInternalPrefixesForInterface

func (t *Tracer) AddInternalPrefixesForInterface(ifindex int) error

AddInternalPrefixesForInterface discovers the bridge containing ifindex and classifies all addresses routed directly by that bridge as internal.

func (*Tracer) AddInternalPrefixesForVeth

func (t *Tracer) AddInternalPrefixesForVeth(name string) error

AddInternalPrefixesForVeth classifies the addresses of the bridge that the named host-side veth is attached to as internal. It must be called in the network namespace containing the veth.

func (*Tracer) AttachWorkloads

func (t *Tracer) AttachWorkloads(parent string) (rerr error)

AttachWorkloads attaches the workload programs to parent, creating it if needed. Every workload cgroup created below it inherits them.

func (*Tracer) Close

func (t *Tracer) Close() error

func (*Tracer) Workload

func (t *Tracer) Workload(path string, netnsCookie uint64) (_ *Workload, rerr error)

Workload reserves counters for the workload cgroup at path, which must be a direct child of the attached workload parent, counting only sockets in the network namespace with netnsCookie. It creates the cgroup if the runtime has not yet, so the counters exist before the workload's first packet; the runtime adopts an existing, empty cgroup.

type Workload

type Workload struct {
	// contains filtered or unexported fields
}

Workload holds the counters of one executor workload's cgroup.

func (*Workload) Close

func (w *Workload) Close() error

Close releases the workload's counters. Sample the workload for the last time first.

func (*Workload) Sample

func (w *Workload) Sample() (Sample, error)

Sample returns the workload's cumulative counters.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL