Welcome to Advanced Traffic Shaping with tc and eBPF in Linux. Preventing a single noisy neighbor or runaway microservice from saturating your network interface requires robust Quality of Service (QoS). Historically, Linux handled this with tc (Traffic Control). Today, eBPF supercharges it.

1. The Linux Traffic Control (tc) Hierarchy

The Linux kernel manages outbound traffic through queuing disciplines (qdiscs). The default is usually pfifo_fast or fq_codel (Fair Queuing Controlled Delay). When you need to enforce strict bandwidth limits (policing) or guarantee minimum bandwidth (shaping), you must build a hierarchy of classes and filters using a classful qdisc like HTB (Hierarchical Token Bucket).

HTB allows you to define a root bandwidth limit (e.g., 10 Gbps) and subdivide it among child classes (e.g., 8 Gbps for web traffic, 2 Gbps for backups), allowing classes to borrow unused bandwidth from each other.

2. Traditional Packet Classification with u32

To assign packets to specific HTB classes, tc uses filters. The u32 filter is the most common, allowing you to match arbitrary bytes in the IP or TCP header. While powerful, u32 syntax is notoriously complex and difficult to scale dynamically in a modern orchestration environment where IP addresses constantly change.

3. Enter eBPF (Extended Berkeley Packet Filter)

eBPF revolutionized Linux networking. Instead of writing static u32 rules, you can write C code, compile it to eBPF bytecode, and attach it directly to the tc ingress or egress hooks.

Because eBPF programs can access kernel maps (high-speed key-value stores shared between kernel and user space), a Go or Python daemon running in user space can dynamically update the IP addresses or port numbers that the eBPF program is shaping, without reloading the entire tc rule tree.

4. eBPF and XDP (eXpress Data Path)

For inbound traffic (ingress policing), eBPF provides the XDP hook. XDP executes before the Linux networking stack even allocates an sk_buff structure. This allows you to drop or redirect packets at wire speed (millions of packets per second per core), making XDP the de facto standard for building high-performance software DDoS mitigators and load balancers.

Conclusion

The combination of tc for hierarchical shaping and eBPF for dynamic, programmatic classification represents the cutting edge of software-defined networking on Linux bare metal.