Terminus Expanse
CurriculumBlogPricingSign in
Back to catalog
Expert (optional)

eBPF

Run safe, sandboxed programs inside the kernel itself, without writing a kernel module.

Prerequisite: Kernel Modules

What you'll actually learn

Before eBPF, watching what a running kernel was actually doing meant either trusting whatever a tool like strace chose to show you, or writing a kernel module and risking a full system crash from one bad pointer. This track has you write small eBPF programs and attach them to real kernel events — a syscall, a network packet arriving, a function being called — so you see, directly, what the kernel is doing at the moment it does it.

What you'll be able to do

You'll build a working tracer that answers a real question a running system can't easily answer on its own — which process is actually opening this file, where exactly a packet gets dropped — using the same class of technique tools like Cilium and Falco are built on, verified safe by the kernel before it ever runs.

Syllabus

1Why eBPF Existsexpert~9 min
2The eBPF Verifier: Safety Without Trustexpert~10 min
3Hooking Into the Kernel: Probes and Program Typesexpert~10 min
4eBPF Maps: Sharing State Between Kernel and Userlandexpert~9 min
5Real Tools Built on eBPFexpert~9 min
6Synthesis: Tracing a Real Problem With bpftraceexpert~11 min

Frequently asked

How long does eBPF take to complete?

Roughly 1 hour across 6 hands-on quests — you can go at your own pace and pick up exactly where you left off.

What do I need to know before starting eBPF?

You should be comfortable with Kernel Modules first — the skill tree unlocks eBPF once you've cleared those.

Is eBPF free to learn?

Yes — eBPF is fully available on the free tier, starting with a free first quest and no payment method required to sign up. Plus and Elite remove pacing limits but don't gate any of the eBPF curriculum behind a paywall.

Start this skill for free

Create a free account and begin your first quest — no card required.

Start free