eBPF Essentials: Security and Observability (LFWS304)

This one-day course introduces eBPF and shows how to use it to secure, monitor and optimize Kubernetes environments.

Suggested prerequisites: basic Linux sysadmin and command line skills, basic knowledge of decoupled, transient microservices, and a basic understanding of Kubernetes cluster architecture.

Audience: DevOps engineers, security professionals and cloud admins.

If you want to move beyond monitoring into proactive security and observability, eBPF is a technology worth knowing. This course is designed for DevOps engineers, security professionals and cloud admins who want practical eBPF expertise, with real-time insights and policy-driven control over their Kubernetes environments.

The day starts with why eBPF matters and how it works internally. You will learn to program the Linux kernel with eBPF, integrate with tools like Cilium and Tetragon, detect and respond to runtime threats, and visualize system performance through real-time observability pipelines. The later part of the course covers advanced uses such as anomaly detection, policy enforcement and forensics.

The course prepares you for cloud and security engineering roles that call for both depth and adaptability. By mastering eBPF for real-time observability and protection, you will be ready to lead initiatives that make modern infrastructure more secure, resilient and efficient.

← All Linux Foundation courses