Traffic

The traffic is used to collecting the network access logs from services through the Service Discovery, and send access logs to the backend server for analyze.

Configuration

NameDefaultEnvironment KeyDescription
access_log.activefalseROVER_ACCESS_LOG_ACTIVEIs active the access log monitoring.
access_log.exclude_namespacesistio-system,cert-manager,kube-systemROVER_ACCESS_LOG_EXCLUDE_NAMESPACESExclude processes in the specified Kubernetes namespace. Multiple namespaces split by “,”
access_log.exclude_clusterROVER_ACCESS_LOG_EXCLUDE_CLUSTERExclude processes in the specified cluster which defined in the process module. Multiple clusters split by “,”
access_log.flush.max_count2000ROVER_ACCESS_LOG_FLUSH_MAX_COUNTThe max count of the access log when flush to the backend.
access_log.flush.period5sROVER_ACCESS_LOG_FLUSH_PERIODThe period of flush access log to the backend.
access_log_protocol_analyze.per_cpu_buffer400KBROVER_ACCESS_LOG_PROTOCOL_ANALYZE_PER_CPU_BUFFERThe size of socket data buffer on each CPU.
access_log.protocol_analyze.parallels2ROVER_ACCESS_LOG_PROTOCOL_ANALYZE_PARALLELSThe count of parallel protocol analyzer.
access_log.protocol_analyze.queue_size5000ROVER_ACCESS_LOG_PROTOCOL_ANALYZE_QUEUE_SIZEThe size of per paralleled analyze queue.

Collectors

Socket Connect/Accept/Close

Monitor all socket connect, accept, and close events from monitored processes by attaching eBPF program to the respective trace points.

Socket traffic

Capture all socket traffic from monitored processes by attaching eBPF program to network syscalls.

Protocol

Data collection is followed by protocol analysis. Currently, the supported protocols include:

  1. HTTP/1.x
  2. HTTP/2

Note: As HTTP2 is a stateful protocol, it only supports monitoring processes that start after monitor. Processes already running at the time of monitoring may fail to provide complete data, leading to unsuccessful analysis.

TLS

When a process uses the TLS protocol for data transfer, Rover monitors libraries such as OpenSSL, BoringSSL, GoTLS, and NodeTLS to access the raw content. This feature is also applicable for protocol analysis.

Note: the parsing of TLS protocols in Java is currently not supported.

L2-L4

During data transmission, Rover records each packet‘s through the network layers L2 to L4 using kprobes. This approach enhances the understanding of each packet’s transmission process, facilitating easier localization and troubleshooting of network issues.