How AWS Lambda logs every flow across thousands of microVMs per host with eBPF and Rust
A great eBPF case study from AWS Lambda. Their iptables-based flow logging needed 100,000+ rules for about 2,000 microVMs and got slower with every packet. The replacement uses eBPF at the TC hook, ring buffers, and unprivileged Rust taggers using ~300KB RAM each. It drops zero packets and its output is byte-for-byte identical to the old records. The lesson: observe from outside the hot path.