Skip to content

PRODUCT

netevd

netevd runs your scripts the moment something changes on a Linux network interface — link up/down, a new IP, a route change — instead of a NetworkManager dispatcher script, a systemd-networkd ExecStartPost hack, or a cron job polling ip addr.

Get the highlights.

  • 3
    backends, one event system
  • 171
    hook directories
  • <100ms
    netlink event latency
  • eBPF
    observe-only drops / TCP
  • 1000+2
    events / sec

netevd runs your scripts the moment something changes on a Linux network interface — link up/down, a new IP, a route change — instead of you writing a NetworkManager dispatcher script, a systemd-networkd ExecStartPost hack, or a cron job that polls ip addr every few seconds. It bridges systemd-networkd, NetworkManager, and dhclient into one event system, with sub-100ms netlink-driven latency, opt-in eBPF observation for silent packet drops and TCP health, automatic policy routing for multi-homed hosts, a REST API, Prometheus metrics, and a defense-in-depth security model.

See the full README on GitHub for the complete feature tour, quick start, configuration reference, and security/performance details.

  • 🔌 Netlink-driven events — sub-100ms latency, zero polling
  • 📡 Observe-only eBPF — drops, TCP retransmit, TCP reset
  • 🛣️ Automatic policy routing for multi-homed hosts
  • 📊 Prometheus metrics
  • 🌐 REST API for status, interfaces, routes, and events
  • 🔒 Defense-in-depth security model

Start here

  1. 17 hook directories span carrier/link, address, route, MTU, manager state, and observe-only eBPF (drops / tcp-retransmit / tcp-reset). See the Hook Contract. ↩
  2. 1000+ events/sec sustained throughput, per the README's Performance table. See Performance in the README. ↩
  3. 9 REST endpoints for status, interfaces, routes, events, and metrics. See REST API in the README. ↩