Skip to content

Commit 4e779f2

Browse files
committed
working nginx tracer
1 parent 87ca115 commit 4e779f2

3 files changed

Lines changed: 13 additions & 7 deletions

File tree

‎docker-compose.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,15 @@ services:
44
# trace help only builds the image and runs the help command
55
# to ensure the docker pipeline works without any errors.
66
trace-help:
7-
image: ghcr.io/amirhnajafiz/flap:v0.0.0-beta-8
7+
image: ghcr.io/amirhnajafiz/flap:v0.0.0-beta-9
88
entrypoint: ["/usr/local/app/trace.sh"]
99
command: ["-h"]
1010

1111
# user end-to-end test runs a tracing operation to validate the
1212
# program functionality. If it works successfully, you should be able
1313
# to see the output in tests/logs directory.
1414
e2e:
15-
image: ghcr.io/amirhnajafiz/flap:v0.0.0-beta-8
15+
image: ghcr.io/amirhnajafiz/flap:v0.0.0-beta-9
1616
privileged: true
1717
network_mode: host
1818
pid: host
Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ metadata:
44
name: nginx-service
55
spec:
66
selector:
7-
app: bpftrace
7+
app: nginx-tracer
88
ports:
99
- name: http-web-svc
1010
port: 80
@@ -14,14 +14,15 @@ spec:
1414
apiVersion: v1
1515
kind: Pod
1616
metadata:
17-
name: bpftrace-test
17+
name: nginx-tracer
1818
labels:
19-
app: bpftrace
19+
app: nginx-tracer
2020
spec:
21-
shareProcessNamespace: true # allow containers to see each other's processes
21+
hostPID: true
2222
initContainers:
2323
- name: bpftrace
24-
image: ghcr.io/amirhnajafiz/flap:v0.0.0-beta-8
24+
image: ghcr.io/amirhnajafiz/flap:v0.0.0-beta-9
25+
imagePullPolicy: Never
2526
restartPolicy: Always
2627
securityContext:
2728
privileged: true # or at least add CAP_SYS_PTRACE

‎src/scripts/ntrace.bt‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,11 @@
88
* sudo bpftrace -o tracing.out ntrace.bt <NAME>
99
*/
1010

11+
BEGIN
12+
{
13+
printf("[%s] START tracing file-access events for %s\n", strftime("%Y-%m-%d %H:%M:%S", nsecs), str($1));
14+
}
15+
1116
/* when we see a fork, if parent is tracked then also track child */
1217
tracepoint:sched:sched_process_fork
1318
/ @tracked[args->parent_pid] /

0 commit comments

Comments
 (0)