GitHub uses eBPF to improve deployment safety
GitHub uses eBPF technology to detect and prevent circular dependencies in its deployment processes, ensuring system reliability during outages. By isolating deployment scripts in cGroups and controlling their network access, GitHub can block unintended dependencies on its own services. This approach allows safer, more resilient deployments without disrupting production traffic.
- ▪GitHub hosts its own source code, creating potential circular dependencies during outages.
- ▪eBPF is used to monitor and restrict network calls from deployment scripts at the kernel level.
- ▪The solution leverages cGroups and the BPF_PROG_TYPE_CGROUP_SKB program type to isolate and control script behavior.
- ▪A Go-based proof of concept using the cilium/ebpf library enables conditional network filtering for specific processes.
Hacker News (Newest) files mainly under programming. We currently carry 5,306 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | The GitHub Blog |
| Canonical URL | https://github.blog/engineering/infrastructure/how-github-uses-ebpf-to-improve-deployment-safety/ |
| Publication time | Wed, 29 Apr 2026 04:08:51 +0000 |
| Retrieval time | 2026-04-29T05:01:00.886Z |
| Last seen | 2026-04-29T05:01:00.886Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | HFVb-LPAzyiG |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Home / Engineering / Infrastructure How GitHub uses eBPF to improve deployment safety Learn how Github uses eBPF to detect and prevent circular dependencies in its deployment tooling. Lawrence Gripper & Aleksey Levenstein April 16, 2026 | 7 minutes Share: Did you know that, at GitHub, we host all of our own source code on github.com? We do this because we’re our own biggest customer—testing out changes internally before they go to users. However, there’s one downside: If github.com were ever to go down, we wouldn’t be able to access our own source code. This is what you’d call a very simple circular dependency: to deploy GitHub, we needed GitHub. If GitHub is down, then we wouldn’t be able to deploy something to fix it.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at The GitHub Blog.