PRODUCT
netevd
netevd runs your scripts the moment something changes on a Linux network interface — link up/down, a new IP, a route change — instead of a NetworkManager dispatcher script, a systemd-networkd ExecStartPost hack, or a cron job polling ip addr.
-
FAQ
Licensing, support, production readiness, and platform questions.
-
Community Edition vs Enterprise
Feature and support comparison.
-
User documentation
Installation, CLI, hooks, and the operator surfaces.
-
Observe-only eBPF
Packet drops, TCP retransmit, and TCP reset hooks.
-
Using the operator surfaces
CLI, REST API, Prometheus, and journal-based operation.
-
Getting started
Install netevd and fire your first hook.
netevd runs your scripts the moment something changes on a Linux network interface — link up/down, a new IP, a route change — instead of you writing a NetworkManager dispatcher script, a systemd-networkd ExecStartPost hack, or a cron job that polls ip addr every few seconds. It bridges systemd-networkd, NetworkManager, and dhclient into one event system, with sub-100ms netlink-driven latency, opt-in eBPF observation for silent packet drops and TCP health, automatic policy routing for multi-homed hosts, a REST API, Prometheus metrics, and a defense-in-depth security model.
See the full README on GitHub for the complete feature tour, quick start, configuration reference, and security/performance details.
- 🔌 Netlink-driven events — sub-100ms latency, zero polling
- 📡 Observe-only eBPF — drops, TCP retransmit, TCP reset
- 🛣️ Automatic policy routing for multi-homed hosts
- 📊 Prometheus metrics
- 🌐 REST API for status, interfaces, routes, and events
- 🔒 Defense-in-depth security model
Start here¶
- FAQ — licensing, support, production readiness, and platform questions
- Community Edition vs Enterprise — feature and support comparison
- User documentation — installation, CLI, hooks, and the operator surfaces
- Using the operator surfaces — CLI, REST API, Prometheus, and journal-based operation
- Getting started — install netevd and fire your first hook
- Changelog — 0.4.1 notes (Ubuntu 26.04 image, Alpine 3.23, remote deploy)
- Admin basics — config, hooks, ports, privilege, and validation at a glance
- 17 hook directories span carrier/link, address, route, MTU, manager state, and observe-only eBPF (drops / tcp-retransmit / tcp-reset). See the Hook Contract. ↩
- 1000+ events/sec sustained throughput, per the README's Performance table. See Performance in the README. ↩
- 9 REST endpoints for status, interfaces, routes, events, and metrics. See REST API in the README. ↩