Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

AIOStack

Using eBPF to Secure AI Services in Kubernetes

Details

External ID
46618481
Source
HN
Company
—
Product
AIOStack
Website domain
aurva.io
Launched
Jan. 14, 2026
Cohort
—
Upvotes
9
Upvotes percentile
0.461133069828722
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Hey HN! We built a tool that uses eBPF to discover AI services and their data flows in Kubernetes clusters.Modern AI apps often follow this pattern: 1. Service receives request 2. Queries database (PostgreSQL/Redis/MongoDB) 3. Sends data to LLM API (OpenAI/Anthropic/Bedrock) 4. Consumes or returns the AI generated responseSecurity teams often don't know: - Which services are making AI calls - What databases they're accessing first - Whether PII is being sent to third-party APIs - What libraries and packages are being used for AIOur eBPF based tool attaches to network and fs syscalls to observe: - Outbound connections to AI API endpoints (pattern matching on domains/IPs) - Database protocol detection (PostgreSQL, MySQL, MongoDB wire protocols) - Service-to-service communication within the cluster - Libraries invoked by processes (PyTorch, HF, OpenCV etc)Architecture: - eBPF with C in kernel space - Go userspace agent processes events - Results sent to in-cluster exporter - Next.js for visualizationGitHub: https://github.com/aurva-io/AIOstack Demo: https://aurva.aiQuestions for you guys: 1. What classifications/buckets would you like to see for apps? 2. Other protocols/services we should detect? 3. Performance overhead-what's acceptable in prod?

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Security
Function
Observability & eval
Audience
B2B
AI stance
Not AI
Project type
Commercial product
Normalized one-liner
ebpf-based security for ai services in kubernetes
Manually corrected
False

Could you build this?

No Writing and deploying eBPF programs to safely hook Linux kernel network and socket events inside Kubernetes clusters to inspect TLS/HTTP traffic requires deep kernel systems engineering.

What it would actually take: The stack involves C/Rust (using Aya or libbpf) compiling eBPF bytecode for kernel-space kprobes, uprobes, and tracepoints (specifically hooking SSL/TLS read/write functions and socket operations) paired with a Go/Rust userspace daemon and Kubernetes operator. The hard part is managing verifier constraints across kernel versions, non-invasive TLS plaintext extraction, high-throughput packet processing, and low-overhead metadata tagging, requiring deep Linux kernel and network security expertise.

Discussion

1 comment analyzed.

Competitors

Other products that read as similar to this one — 98 launches clear the similarity bar, closest 8 shown.

Attention rank: #55 of 99 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 76 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a observability & eval tool for Media & entertainment yet.