[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"project-4987":3},{"id":4,"name":5,"fullName":6,"owner":5,"repo":5,"description":7,"homepage":8,"htmlUrl":9,"language":10,"languages":9,"totalLinesOfCode":9,"stars":11,"forks":12,"watchers":13,"openIssues":14,"contributorsCount":15,"subscribersCount":15,"size":15,"stars1d":16,"stars7d":17,"stars30d":18,"stars90d":15,"forks30d":15,"starsTrendScore":19,"compositeScore":20,"rankGlobal":9,"rankLanguage":9,"license":21,"archived":22,"fork":22,"defaultBranch":23,"hasWiki":24,"hasPages":22,"topics":25,"createdAt":9,"pushedAt":9,"updatedAt":46,"readmeContent":47,"aiSummary":48,"trendingCount":15,"starSnapshotCount":15,"syncStatus":49,"lastSyncTime":50,"discoverSource":51},4987,"kubeshark","kubeshark\u002Fkubeshark","eBPF-powered network observability for Kubernetes. Indexes L4\u002FL7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.","https:\u002F\u002Fkubeshark.com",null,"Go",11949,539,71,138,0,3,27,59,16,43.2,"Apache License 2.0",false,"master",true,[26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45],"cloud-native","devops","docker","ebpf","golang","grpc","incident-response","kubernetes","mcp","network-analysis","network-engineering","network-observability","network-security","observability","pcap","rest","root-cause-analysis","sniffer","sre","wireshark","2026-06-12 02:01:06","\u003Cp align=\"center\">\n  \u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002Fkubeshark\u002Fassets\u002Fmaster\u002Fsvg\u002Fkubeshark-logo.svg\" alt=\"Kubeshark\" height=\"120px\"\u002F>\n\u003C\u002Fp>\n\n\u003Cp align=\"center\">\n    \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fkubeshark\u002Fkubeshark\u002Freleases\u002Flatest\">\u003Cimg alt=\"Release\" src=\"https:\u002F\u002Fimg.shields.io\u002Fgithub\u002Fv\u002Frelease\u002Fkubeshark\u002Fkubeshark?logo=GitHub&style=flat-square\">\u003C\u002Fa>\n    \u003Ca href=\"https:\u002F\u002Fhub.docker.com\u002Fr\u002Fkubeshark\u002Fworker\">\u003Cimg alt=\"Docker pulls\" src=\"https:\u002F\u002Fimg.shields.io\u002Fdocker\u002Fpulls\u002Fkubeshark\u002Fworker?color=%23099cec&logo=Docker&style=flat-square\">\u003C\u002Fa>\n    \u003Ca href=\"https:\u002F\u002Fdiscord.gg\u002FWkvRGMUcx7\">\u003Cimg alt=\"Discord\" src=\"https:\u002F\u002Fimg.shields.io\u002Fdiscord\u002F1042559155224973352?logo=Discord&style=flat-square&label=discord\">\u003C\u002Fa>\n    \u003Ca href=\"https:\u002F\u002Fjoin.slack.com\u002Ft\u002Fkubeshark\u002Fshared_invite\u002Fzt-3jdcdgxdv-1qNkhBh9c6CFoE7bSPkpBQ\">\u003Cimg alt=\"Slack\" src=\"https:\u002F\u002Fimg.shields.io\u002Fbadge\u002Fslack-join_chat-green?logo=Slack&style=flat-square\">\u003C\u002Fa>\n\u003C\u002Fp>\n\n\u003Cp align=\"center\">\u003Cb>Network Observability for SREs & AI Agents\u003C\u002Fb>\u003C\u002Fp>\n\n\u003Cp align=\"center\">\n  \u003Ca href=\"https:\u002F\u002Fdemo.kubeshark.com\u002F\">Live Demo\u003C\u002Fa> · \u003Ca href=\"https:\u002F\u002Fdocs.kubeshark.com\">Docs\u003C\u002Fa>\n\u003C\u002Fp>\n\n---\n\nKubeshark indexes cluster-wide network traffic at the kernel level using eBPF — delivering instant answers to any query using network, API, and Kubernetes semantics.\n\n**What you can do:**\n\n- **Download Retrospective PCAPs** — cluster-wide packet captures filtered by nodes, time, workloads, and IPs. Store PCAPs for long-term retention and later investigation.\n- **Visualize Network Data** — explore traffic matching queries with API, Kubernetes, or network semantics through a real-time dashboard.\n- **See Encrypted Traffic in Plain Text** — automatically decrypt TLS\u002FmTLS traffic using eBPF, with no key management or sidecars required.\n- **Integrate with AI** — connect your favorite AI assistant (e.g. Claude, Copilot) to include network data in AI-driven workflows like incident response and root cause analysis.\n\n![Kubeshark](https:\u002F\u002Fgithub.com\u002Fkubeshark\u002Fassets\u002Fraw\u002Fmaster\u002Fpng\u002Fstream.png)\n\n---\n\n## Get Started\n\n```bash\nhelm repo add kubeshark https:\u002F\u002Fhelm.kubeshark.com\nhelm install kubeshark kubeshark\u002Fkubeshark\nkubectl port-forward svc\u002Fkubeshark-front 8899:80\n```\n\nOpen `http:\u002F\u002Flocalhost:8899` in your browser. You're capturing traffic.\n\n> For production use, we recommend using an [ingress controller](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fingress) instead of port-forward.\n\n**Connect an AI agent** via MCP:\n\n```bash\nbrew install kubeshark\nclaude mcp add kubeshark -- kubeshark mcp\n```\n\n[MCP setup guide →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fmcp)\n\n---\n\n### Network Data for AI Agents\n\nKubeshark exposes cluster-wide network data via [MCP](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fmcp) — enabling AI agents to query traffic, investigate API calls, and perform root cause analysis through natural language.\n\n> *\"Why did checkout fail at 2:15 PM?\"*\n> *\"Which services have error rates above 1%?\"*\n> *\"Show TCP retransmission rates across all node-to-node paths\"*\n> *\"Trace request abc123 through all services\"*\n\nWorks with Claude Code, Cursor, and any MCP-compatible AI.\n\n![MCP Demo](https:\u002F\u002Fgithub.com\u002Fkubeshark\u002Fassets\u002Fraw\u002Fmaster\u002Fgif\u002Fmcp-demo.gif)\n\n[MCP setup guide →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fmcp)\n\n### AI Skills\n\nOpen-source, reusable skills that teach AI agents domain-specific workflows on top of Kubeshark's MCP tools:\n\n| Skill | Description |\n|-------|-------------|\n| **[Network RCA](skills\u002Fnetwork-rca\u002F)** | Retrospective root cause analysis — snapshots, dissection, PCAP extraction, trend comparison |\n| **[KFL](skills\u002Fkfl\u002F)** | KFL (Kubeshark Filter Language) expert — writes, debugs, and optimizes traffic filters |\n\nInstall as a Claude Code plugin:\n\n```\n\u002Fplugin marketplace add kubeshark\u002Fkubeshark\n\u002Fplugin install kubeshark\n```\n\nOr clone and use directly — skills trigger automatically based on conversation context.\n\n[AI Skills docs →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fmcp\u002Fskills)\n\n---\n\n### Query with API, Kubernetes, and Network Semantics\n\nKubeshark indexes cluster-wide network traffic by parsing it according to protocol specifications, with support for HTTP, gRPC, Redis, Kafka, DNS, and more. A single [KFL query](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Fkfl2) can combine all three semantic layers — Kubernetes identity, API context, and network attributes — to pinpoint exactly the traffic you need. No code instrumentation required.\n\n![KFL query combining API, Kubernetes, and network semantics](https:\u002F\u002Fgithub.com\u002Fkubeshark\u002Fassets\u002Fraw\u002Fmaster\u002Fpng\u002Fkfl-semantics.png)\n\n[KFL reference →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Fkfl2) · [Traffic indexing →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Fl7_api_dissection)\n\n### Workload Dependency Map\n\nA visual map of how workloads communicate, showing dependencies, traffic volume, and protocol usage across the cluster.\n\n![Service Map](https:\u002F\u002Fgithub.com\u002Fkubeshark\u002Fassets\u002Fraw\u002Fmaster\u002Fpng\u002Fservicemap.png)\n\n[Learn more →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Fservice_map)\n\n### Traffic Retention & PCAP Export\n\nCapture and retain raw network traffic cluster-wide, including decrypted TLS. Download PCAPs scoped by time range, nodes, workloads, and IPs — ready for Wireshark or any PCAP-compatible tool. Store snapshots in cloud storage (S3, Azure Blob, GCS) for long-term retention and cross-cluster sharing.\n\n![Traffic Retention](https:\u002F\u002Fgithub.com\u002Fkubeshark\u002Fassets\u002Fraw\u002Fmaster\u002Fpng\u002Fsnapshots-list.png)\n\n[Snapshots guide →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Ftraffic_snapshots) · [Cloud storage →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fsnapshots_cloud_storage)\n\n---\n\n## Features\n\n| Feature | Description |\n|---------|-------------|\n| [**Traffic Snapshots**](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Ftraffic_snapshots) | Point-in-time snapshots with cloud storage (S3, Azure Blob, GCS), PCAP export for Wireshark |\n| [**Traffic Indexing**](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Fl7_api_dissection) | Real-time and delayed L7 indexing with request\u002Fresponse matching and full payloads |\n| [**Protocol Support**](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fprotocols) | HTTP, gRPC, GraphQL, Redis, Kafka, DNS, and more |\n| [**TLS Decryption**](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fencrypted_traffic) | eBPF-based decryption without key management, included in snapshots |\n| [**AI Integration**](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fmcp) | MCP server + open-source AI skills for network RCA and traffic filtering |\n| [**KFL Query Language**](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fv2\u002Fkfl2) | CEL-based query language with Kubernetes, API, and network semantics |\n| [**100% On-Premises**](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Fair_gapped) | Air-gapped support, no external dependencies |\n\n---\n\n## Install\n\n| Method | Command |\n|--------|---------|\n| Helm | `helm repo add kubeshark https:\u002F\u002Fhelm.kubeshark.com && helm install kubeshark kubeshark\u002Fkubeshark` |\n| Homebrew | `brew install kubeshark && kubeshark tap` |\n| Binary | [Download](https:\u002F\u002Fgithub.com\u002Fkubeshark\u002Fkubeshark\u002Freleases\u002Flatest) |\n\n[Installation guide →](https:\u002F\u002Fdocs.kubeshark.com\u002Fen\u002Finstall)\n\n---\n\n## Contributing\n\nWe welcome contributions. See [CONTRIBUTING.md](CONTRIBUTING.md).\n\n## License\n\n[Apache-2.0](LICENSE)\n","Kubeshark 是一个基于 eBPF 的 Kubernetes 网络可观测性工具，能够索引 L4\u002FL7 流量并提供完整的 K8s 上下文信息，同时无需密钥即可解密 TLS 通信。其核心功能包括通过实时仪表盘可视化网络数据、下载集群范围内的 PCAP 文件以供长期存储和调查，以及支持 AI 代理通过 MCP 接口查询网络数据。该项目特别适用于需要深入分析容器化应用网络行为的 SRE 团队及 DevOps 工程师，在故障排查、性能优化和安全审计等场景中发挥重要作用。",2,"2026-06-11 03:01:55","top_language"]