Skip to content

feat(llm): put LLM capture behind --enable-llm-capture - #350

Merged
blue4209211 merged 1 commit into
mainfrom
feat/llm-capture-flag
Oct 2, 2026
Merged

blue4209211 merged 1 commit into
mainfrom
feat/llm-capture-flag

Conversation

@mayankpande88

Copy link
Copy Markdown
Contributor

Follow-up to #348, which was merged before this commit reached it.

LLM capture adds work to every socket read and write in the kernel (a capture-map lookup, and a destination check on each new connection's first write) and parses captured traffic in userspace. Clusters with no LLM traffic, or no interest in it, should not pay for that. This makes it opt-in, as Node.js and .NET tracing already are: --enable-llm-capture / ENABLE_LLM_CAPTURE=true, default off.

  • Kernel: a one-entry config map, set at load time, gates the destination check and the capture-map lookup. While it is zero, the only cost is one array lookup per read or write.
  • Userspace: SNI tagging, API-path detection and LLM metric registration are skipped while the flag is off.
  • Unconditional: the TLS ciphertext skip and the HTTP/2 fixes from feat(llm): accurate LLM usage capture; fix TLS and HTTP/2 parsing #348 stay on; they are correctness fixes that reduce L7 work for everyone.

Behaviour change: LLM metrics now require the flag. The Helm chart needs a value for it in deployments that want them.

Validated on a test cluster (18 nodes, Linux 6.8), one build both ways:

  • Off: no LLM series, no load errors, every scrape healthy; ciphertext skipping still active.
  • On: captures resume, every scrape healthy.

Capturing LLM traffic adds work to every socket read and write in the kernel
(a capture-map lookup, and a destination check on each new connection's
first write) and parses captured traffic in userspace. Clusters with no LLM
traffic, or no interest in it, should not pay for that, so it is now opt-in,
as Node.js and .NET tracing already are.

A one-entry config map, set at load time, gates the kernel side: while it is
zero, the only cost is one array lookup per read or write. Userspace skips
SNI tagging, API-path detection and the LLM metric families.

The TLS ciphertext skip and the HTTP/2 fixes stay unconditional: they are
correctness fixes that reduce L7 work for everyone.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request makes the LLM capture feature optional and disabled by default, introducing the --enable-llm-capture flag. It optimizes the eBPF probe paths to bypass LLM capture logic when disabled, minimizing performance overhead, and conditionally registers LLM metrics in userspace. Feedback on the changes suggests adding a defensive nil check when accessing the llm_capture_config eBPF map in tracer.go to prevent a potential runtime panic if the map is missing from the loaded collection.

Comment thread ebpftracer/tracer.go
@blue4209211
blue4209211 merged commit d449628 into main Oct 2, 2026
@blue4209211
blue4209211 deleted the feat/llm-capture-flag branch October 2, 2026 09:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants