Akto eBPF Traffic Collector Platform Specific
This document is for clients who install the dockerless eBPF bundle (Go binary + module.cc(bcc) + shell wrappers), distributed as a versioned .tar.gz.
Tarball naming convention:
akto-mirroring-module-<version>-<os>-<kernel>-<arch>.tar.gz
Platform Downloads
Amazon Linux 2 — kernel 5.10, x86_64
https://akto.blob.core.windows.net/traffic-collector-binaries/akto-mirroring-module-1.0.0-amzn2-5.10-x86_64.tar.gz
Amazon Linux 2023 — kernel 6.1, x86_64
https://akto.blob.core.windows.net/traffic-collector-binaries/akto-mirroring-module-1.0.0-amzn2023-6.1-x86_64.tar.gz
Amazon Linux 2023 — kernel 6.1, aarch64
https://akto.blob.core.windows.net/traffic-collector-binaries/akto-mirroring-module-1.0.0-amzn2023-6.1-aarch64.tar.gz
Contact Akto for a download URL if your platform is not listed.
Install
1. Download the archive
Use the platform-specific URL from the table above.
wget -O akto-mirroring-module-<version>-<os>-<kernel>-<arch>.tar.gz "<ARTIFACT_URL>"(curl -fL "<ARTIFACT_URL>" -o akto-mirroring-module-<version>-<os>-<kernel>-<arch>.tar.gz works the same way.)
2. Unpack (default layout: /ebpf)
/ebpf)As root (paths in the archive are rooted at ebpf/):
This creates /ebpf/ including:
ebpf/ebpf-logging
Main Go binary
ebpf/<os>-<kernel>-<arch>-setup.sh
Platform-specific prerequisite script (e.g. amzn2-5.10-x86_64-setup.sh)
ebpf/kernel/module.cc
C kernel code
ebpf/ebpf-bcc-run.sh
Supervisor loop
ebpf/run-ebpf-bcc-host.sh
Host entrypoint (sudo wrapper; detached by default)
ebpf/uninstall-ebpf-bcc-host.sh
Stops processes; leaves ${EBPF_ROOT} on disk
ebpf/.env
Default environment (edit before production)
If you install under a different directory, set EBPF_ROOT consistently (see below) and keep ebpf-bcc-run.sh and .env together under that directory.
3. Run platform prerequisites
The tarball includes a platform-specific setup script that installs required kernel headers and BCC libraries. This must be run before akto ebpf module is started everytime. Run it once after unpacking:
Amazon Linux 2 (kernel 5.10, x86_64)
sudo bash /ebpf/amzn2-5.10-x86_64-setup.sh
Amazon Linux 2023 (kernel 6.1, x86_64)
sudo bash /ebpf/amzn2023-6.1-x86_64-setup.sh
Amazon Linux 2023 (kernel 6.1, aarch64)
sudo bash /ebpf/amzn2023-6.1-aarch64-setup.sh
For reference, upstream BCC installation docs: https://github.com/iovisor/bcc/blob/master/INSTALL.md
4. Configure
Edit /ebpf/.env (or ${EBPF_ROOT}/.env). At minimum set AKTO_KAFKA_BROKER_MAL to your broker (replace the <kafka-ip> placeholder in the shipped template).
Typical bare-metal defaults in that file:
EBPF_ROOT=/ebpf— bundle root.HOST_MAPPING=/— host path prefix (use/hostwhen running inside Docker with-v /:/host).ENABLE_LOGS=false/LOG_FILE=/ebpf/dump.log— shipped defaults; if you changeEBPF_ROOT, setLOG_FILEunder that directory (for example/opt/akto/ebpf/dump.log).
5. Run (detached by default)
run-ebpf-bcc-host.sh starts the supervisor under nohup and returns immediately. It writes ${EBPF_ROOT}/ebpf-bcc-run.pid. nohup.out is not used. With ENABLE_LOGS=false, ebpf-bcc-run.sh attaches non-TTY stdout/stderr to LOG_FILE (see .env / MAX_LOG_SIZE for rotation).
Follow logs:
ebpf-bcc-run.shshell output (memory lines, restarts) and collector whenENABLE_LOGS=false(bundle default):tail -f /ebpf/dump.logor overrideLOG_FILEin.env
Attach to the supervisor in the foreground (blocks this shell), for debugging:
Or with a non-default install root:
Ensure EBPF_ROOT in the environment matches EBPF_ROOT in .env when you use a custom path.
6. Uninstall
Stops ebpf-bcc-run.sh / ebpf-logging for this install (using the pidfile when present, then matching processes). It does not remove EBPF_ROOT.
Custom root:
Omit -y for an interactive confirmation (requires a TTY).
What’s Happening Behind the Scenes?
eBPF hooks into your Linux kernel to capture real-time traffic—even if it’s encrypted (TLS).
No code changes, no traffic proxying, no SSL termination.
The collector forwards API traces to Akto for real-time inventory and security analysis.
Get Support for your Akto setup
There are multiple ways to request support from Akto. We are 24X7 available on the following:
In-app
intercomsupport. Message us with your query on intercom in Akto dashboard and someone will reply.Join our discord channel for community support.
Contact
help@akto.iofor email support.Contact us here.
Last updated