
How Linux BPF Iterators Transform Kernel Data Access
In episode 127 of The Linux Podcast, Lucas and Luna explore BPF iterators — a relatively recent addition to the eBPF ecosystem that lets you traverse kernel data structures efficiently without writing manual loops in C. They walk through a concrete example: using a BPF iterator to list all open TCP sockets with minimal overhead, comparing it to older methods like /proc and netlink. The hosts discuss how iterators reduce boilerplate, improve safety, and enable new observability use cases. They also cover the runtime cost difference and why projects like Cilium and Falco are adopting iterators. A focused, code-level conversation for anyone building or debugging Linux systems.
#Linux #eBPF #BPFIterators #Kernel #Observability #SystemsProgramming #Networking #TCP #Cilium #Falco #OpenSource #Technology #Performance #KernelDevelopment #LinuxKernel #FexingoBusiness #BusinessPodcast #Podcast
Keep every episode free: buymeacoffee.com/fexingo
Information
- Show
- FrequencyUpdated Daily
- PublishedJuly 23, 2026 at 1:05 PM UTC
- Length9 min
- Season3
- Episode127
- RatingClean