# cilium/hubble

Hubble - Network, Service & Security Observability for Kubernetes using eBPF

Repository: https://github.com/cilium/hubble
Canonical: https://ross.abutalabs.com/products/hubble
Language: Makefile
License: Apache-2.0
License Family: permissive
Topics: ebpf, observability, kubernetes, metrics, networking, security, tracing, cilium
Last push: 2026-08-24T16:05:55+00:00

## Health v2 (maintenance only)
Score: 91/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 75, longevity 100
- inputs: {"age_days": 2479, "days_push": 9, "days_rel": 89, "gap_med": 34.0, "n_releases_24m": 17}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4315, forks 296 (observed 2026-08-28T04:08:41.834486+00:00)

## What it is
Hubble is a fully distributed network, service, and security observability platform for Kubernetes, built on top of Cilium and eBPF. It provides deep visibility into service communication, network flows, and security behavior transparently without requiring application changes.

## Use cases
- visualize service dependency graphs in a Kubernetes cluster
- monitor HTTP and Kafka traffic between microservices
- debug why network communication is failing (DNS, TCP, or layer 7)
- track HTTP 4xx/5xx error rates and request latency percentiles
- observe which connections are blocked by network policies
- detect DNS resolution failures and interrupted TCP connections
- monitor external access to cluster services

## When to choose
- you run Kubernetes with Cilium and need deep network visibility
- you want eBPF-based observability with low overhead and no app instrumentation
- you need security observability for network policy enforcement
- you want metrics and flow logs for service-to-service communication

## When to avoid
- you are not using Cilium or eBPF-capable Linux kernels
- you need application-level APM traces rather than network-level observability
- you run non-Kubernetes workloads exclusively

## Facets
- artifact type: service
- maturity: active
- function: monitoring, tracing, logging, alerting
- domain: monitoring, networking, security, cloud-computing
- platform: self-hosted, cli
- tags: ebpf, cilium, kubernetes-networking, observability, cloud-native, network-security, flow-visibility, service-dependency-graph, containers, devops, kubernetes, linux, docker

## Member repositories
- cilium/hubble (main) score 91

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:41.834486+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:21:46.370726+00:00, confidence not recorded.
  - readme: https://github.com/cilium/hubble (fetched 2026-08-28T04:08:41.834486+00:00, sha b223a221c3f3)
- Data as of 2026-08-30T08:39:29.467469+00:00.
