USER GUIDE
netevd — User Documentation
netevd is a Netlink-first Linux network event daemon (Rust). It watches carrier, address, route, and manager state — then runs your scripts with rich context. Opt-in observe-only eBPF adds packet drops, TCP retransmits, and TCP resets into the same hook directories. It also maintains per-interface policy routing on multi-homed hosts and exposes REST and Prometheus on :9090 (/metrics is on that same server).
| You want to… | Open |
|---|---|
| Install and fire the first hook | Getting Started |
| Orient around hooks / CLI / API | Using the operator surfaces |
| Observe-only eBPF (drops / TCP) | eBPF guide · ringbuf drain |
| Screen-by-screen / command guides | Page-by-page guides |
| Look up hooks and CLI | Complete page index |
| YAML, systemd, ports, security | Admin basics |
| Multi-home, resume, observe | Common workflows |
→ Docs one-pager · GitHub · netctl
Printable PDFs¶
node scripts/user-docs/build-user-pdfs.mjs
Output lands in pdf/:
netevd-User-README.pdfnetevd-Getting-Started.pdfnetevd-Page-by-Page.pdfnetevd-Admin-Basics.pdf
Product at a glance¶
Hooks → /etc/netevd/{carrier,routable,routes,drops,…}.d/
Config → /etc/netevd/netevd.yaml
eBPF → cargo build --features ebpf (see ebpf.md)
REST/API → :9090 (default bind 127.0.0.1), including /metrics
Unit → netevd.service (+ optional netevd-ebpf.conf drop-in)
Images → ghcr.io/zyvorai/netevd:latest-ubuntu (Ubuntu 26.04), :latest-alpine
Remote → ./scripts/deploy-remote.sh <host> [user]
CLI → netevd status | list | show | events | validate | reload
Operate from CLI¶
- Install and enable:
sudo ./install.sh && sudo systemctl enable --now netevd - Validate config:
netevd validate - Inspect live state:
netevd status && netevd list interfaces - Watch events during a link test:
netevd events -f -i eth0 - Fleet scrape: point Prometheus at
http://<host>:9090/metrics
Never publish lab IPs in runbooks — use <host> for remote targets.
Zyvor · zyvor.dev · netevd · Apache-2.0