← All repos

kubeshark

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.

cloud-nativedevopsdockerebpfgolanggrpcincident-responsekubernetesmcpnetwork-analysisnetwork-engineeringnetwork-observabilitynetwork-securityobservabilitypcaprestroot-cause-analysissniffersrewireshark
Browse cluster: Distributed Databases & Data Systems
2,243commits
56contributors
4languages

Tech stack & purpose

Kubeshark is an eBPF-powered network observability platform for Kubernetes that indexes layer 4 and layer 7 traffic while maintaining full Kubernetes context, and can decrypt TLS traffic without requiring keys. Built in Go, it provides network observability through multiple interfaces: a dashboard for human users, AI agent queries via MCP (Model Context Protocol), and integration with Claude via a plugin that exposes network root cause analysis and KFL filtering skills. The project is deployable via Helm chart and supports various configuration options including cloud storage for snapshots, custom image registries, and flexible traffic capture settings.

Community & reference links

Languages

Go
92.4%
Makefile
5.2%
Shell
1.3%
Go Template
1.2%

Contributors (top 30 of 56)