Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Dsnitch

Real-time, zero-config Docker egress inspector via eBPF

Details

External ID
49586159
Source
HN
Company
—
Product
Dsnitch
Website domain
github.com
Launched
Sept. 6, 2026
Cohort
—
Upvotes
5
Upvotes percentile
0.12998405103668262
Tags
—
Fetched at
Sept. 10, 2026, 5:31 a.m.
Updated at
Sept. 10, 2026, 5:31 a.m.

Description

Hi HN, I built dsnitch because I wanted a zero-config, bandwhich-style live TUI to see what my homelab Docker containers are connecting to—without running sidecar proxies, modifying container configs, or relying on reverse DNS (fails on anycast CDN IPs). Just run the binary and it automatically discovers running containers.Under the hood, it's written in Rust and attaches eBPF probes to the unified cgroup v2 hierarchy and TCP state tracepoints. To map IPs back to domain names accurately, it passively snoops raw UDP/53 DNS responses per cgroup and decodes them in userspace using Hickory DNS. The terminal interface is built with Ratatui.It targets Linux 5.8+ and does not modify or filter network packets in any way. It's strictly read-only.Happy to answer questions or hear your feedback!

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Horizontal
Function
Observability & eval
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
docker network monitoring tool
Manually corrected
False

Could you build this?

No Writing an eBPF-based container egress sniffer requires deep Linux kernel programming, bpf bytecode verification expertise, network socket filtering, and C/Rust low-level systems engineering.

What it would actually take: The architecture requires C or Rust (e.g., Aya/libbpf) writing eBPF programs attached to kernel tracepoints/kprobes (like sock:inet_sock_set_state or cgroup skb egress) coupled with a user-space daemon to parse Docker cgroup namespaces and match network flows to container IDs. The hard parts are kernel verifier constraints, zero-overhead packet inspection, and Docker cgroup v1/v2 translation without sidecars. This requires specialized Linux systems/networking kernel engineering expertise.

Discussion

3 comments analyzed.

Concerns raised: DNS name mapping doesn't work with Docker Compose user-defined networks, Containers using /etc/hosts bypass DNS queries, showing only bare IPs, Hardcoded IPs inside containers won't have DNS name resolution

Competitors

Other products that read as similar to this one — 163 launches clear the similarity bar, closest 8 shown.

Attention rank: #148 of 164 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 311 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a observability & eval tool for Media & entertainment yet.