Home / Companies / Speedscale / Blog / Post Details
Content Deep Dive

Debugging Encrypted Microservice Traffic with Speedscale's eBPF Collector

Blog post from Speedscale

Post Details
Company
Date Published
Author
Matt LeRay
Word Count
1,686
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Speedscale’s eBPF collector is presented as a Kubernetes-based approach for capturing full request and response traffic from production Java applications without code changes, TLS certificate management, per-pod sidecars, or application restarts. By using Linux kernel eBPF instrumentation and OpenSSL uprobes at the SSL_read and SSL_write functions, it can observe plaintext payloads before encryption and after decryption, including outbound HTTPS traffic. The workflow involves installing the Speedscale operator through Helm with eBPF enabled, optionally deploying a Spring Boot demo application, enabling monitoring for a selected workload in the Infrastructure UI, and inspecting live traffic in the Traffic Viewer. Captured data includes request and response headers, bodies, status codes, durations, URLs, and timestamps, with filters for time ranges, direction, status, headers, URLs, and full-text payload searches, alongside a service dependency map. Selected traffic can be archived as reusable snapshots containing raw exchanges, transformation rules, and discovered dynamic tokens, then replayed against new service versions, used for assertions, or used to mock dependencies. The post notes configurable CPU and memory limits for high-volume nodes and advises against debug logging under production load because it can increase CPU use and cause dropped traffic.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 2 2,478 412 128 +56%
Observability 2 4,660 984 209 +14%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.