Dsnitch
Real-time, zero-config Docker egress inspector via eBPF
Details
- External ID
- 49586159
- Source
- HN
- Company
- —
- Product
- Dsnitch
- Website domain
- github.com
- Launched
- Sept. 6, 2026
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.12998405103668262
- Tags
- —
- Fetched at
- Sept. 10, 2026, 5:31 a.m.
- Updated at
- Sept. 10, 2026, 5:31 a.m.
Description
Hi HN, I built dsnitch because I wanted a zero-config, bandwhich-style live TUI to see what my homelab Docker containers are connecting to—without running sidecar proxies, modifying container configs, or relying on reverse DNS (fails on anycast CDN IPs). Just run the binary and it automatically discovers running containers.Under the hood, it's written in Rust and attaches eBPF probes to the unified cgroup v2 hierarchy and TCP state tracepoints. To map IPs back to domain names accurately, it passively snoops raw UDP/53 DNS responses per cgroup and decodes them in userspace using Hickory DNS. The terminal interface is built with Ratatui.It targets Linux 5.8+ and does not modify or filter network packets in any way. It's strictly read-only.Happy to answer questions or hear your feedback!
Enrichment
- Theme
- proxy, dns, and networking tools
- Vertical
- Horizontal
- Function
- Observability & eval
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- docker network monitoring tool
- Manually corrected
- False
Could you build this?
No Writing an eBPF-based container egress sniffer requires deep Linux kernel programming, bpf bytecode verification expertise, network socket filtering, and C/Rust low-level systems engineering.
What it would actually take: The architecture requires C or Rust (e.g., Aya/libbpf) writing eBPF programs attached to kernel tracepoints/kprobes (like sock:inet_sock_set_state or cgroup skb egress) coupled with a user-space daemon to parse Docker cgroup namespaces and match network flows to container IDs. The hard parts are kernel verifier constraints, zero-overhead packet inspection, and Docker cgroup v1/v2 translation without sidecars. This requires specialized Linux systems/networking kernel engineering expertise.
Discussion
3 comments analyzed.
Concerns raised: DNS name mapping doesn't work with Docker Compose user-defined networks, Containers using /etc/hosts bypass DNS queries, showing only bare IPs, Hardcoded IPs inside containers won't have DNS name resolution
Competitors
Other products that read as similar to this one — 163 launches clear the similarity bar, closest 8 shown.
Attention rank: #148 of 164 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 311 days after the earliest competitor.
- CargoWall · hn · 2026-03-31 · 14 upvotes · similarity 0.55
- Cerberus · hn · 2025-12-20 · 12 upvotes · similarity 0.54
- Netfence · hn · 2026-01-25 · 58 upvotes · similarity 0.50
- D.NIX. · ph · 2026-09-20 · 2 upvotes · similarity 0.48
- Nomina · hn · 2026-06-28 · 6 upvotes · similarity 0.48
- Linnix · hn · 2025-11-11 · 21 upvotes · similarity 0.46
- Nucleus · hn · 2026-06-09 · 40 upvotes · similarity 0.44
- Port Sentinel · ph · 2026-09-14 · 1 upvotes · similarity 0.44
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.