beyla
Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart. Covers requirements (Linux 5.8+ with BTF, CAP_SYS_ADMIN, host PID), language matrix (Go / Java / Python / Ruby / Node / .NET / Rust / C++ / PHP), Docker + Helm + DaemonSet install
- 0
- Installs
- —
- Rating
- —
- Success rate
- 3
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 abd2f3675343bd71… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Grafana Beyla
Zero-code HTTP / gRPC / DB instrumentation via eBPF. Emits OTLP traces + Prometheus metrics.
Prerequisites
- Linux kernel 5.8+ with BTF enabled (
ls /sys/kernel/btf/vmlinuxmust exist) - Root or
CAP_SYS_ADMIN(orprivileged: truein Kubernetes +hostPID: true) - x86_64 or ARM64
- An OTLP receiver (Tempo, Alloy, OTel Collector) reachable from Beyla
Common Workflows
1. Instrument a single binary with Docker
# 1. Run Beyla against the app's port (the app must already be running, listening on 8080)
docker run --privileged --pid=host \
-v /sys/kernel/debug:/sys/kernel/debug:ro \
-e BEYLA_OPEN_PORT=8080 \
-e BEYLA_PROMETHEUS_PORT=8999 \
-e OTEL_EXPORTER_OTLP_ENDPOINT=http://otel-collector:4318 \
-p 8999:8999 \
grafana/beyla
# 2. Generate some traffic
curl http://localhost:8080/ ; curl http://localhost:8080/api/users/42
# 3. Verify Beyla emitted metrics — should list http_server_request_duration_seconds + counters
curl -s http://localhost:8999/metrics | grep -E '^http_(server|client)_request_duration'
# 4. Verify traces — in Grafana Explore on Tempo, search by service.name (default = process name)
# Or: query Tempo's search API for spans with service.name="<app>"
2. Deploy as a cluster-wide DaemonSet
Full DaemonSet + RBAC YAML lives in references/kubernetes.md. After applying:
# 1. Verify DaemonSet rollout
kubectl -n monitoring rollout status ds/beyla
# 2. Verify pods are Running, one per node
kubectl -n monitoring get pods -l app=beyla -o wide
# 3. Verify eBPF probes attached (no errors mentioning BTF or "permission denied")
kubectl -n monitoring logs ds/beyla --tail=50 | grep -Ei 'error|fail|btf' || echo "clean"
# 4. Verify telemetry is flowing — check the Tempo/Alloy receiver for spans from the cluster
# Or scrape one pod directly:
kubectl -n monitoring port-forward ds/beyla 8999:8999 &
curl -s localhost:8999/metrics | head
3. Send to Grafana Cloud via Alloy
# beyla-config.yml
otel_traces_export: { endpoint: http://alloy:4318 }
otel_metrics_export: { endpoint: http://alloy:4318 }
# Verify Alloy is forwarding — check Alloy UI (localhost:12345) for the
# otelcol.receiver.otlp.beyla component showing received spans/metrics > 0.
Full Alloy + Beyla YAML: references/config.md.
Troubleshooting
failed to load BPF object→ kernel < 5.8 or BTF missing; check/sys/kernel/btf/vmlinux- No spans in Tempo, but Prometheus metrics show → check
OTEL_EXPORTER_OTLP_ENDPOINT, protocol (http vs grpc), and ports (4318 http / 4317 grpc) - HTTP route cardinality explosion → set
routes.unmatched: heuristicand add patterns (seereferences/config.md) - Pod restarts with
CrashLoopBackOff→ likely missinghostPID: trueorprivileged: true/ required capabilities
Resources
- Beyla docs
- Beyla GitHub
references/config.md— full config, env vars, samplers, routes decorator, generated metrics table, runtime matrixreferences/kubernetes.md— DaemonSet + RBAC + discovery filters + Helm
Files
3- SKILL.md
7a8803e5fc4.2 KB - references/config.md
4c84a977453.3 KB - references/kubernetes.md
efb792b09e1.9 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from grafana/skills8
Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config, unused-metric detection, and Alloy remote_write fallback. Use when investigating a high Mimir/Grafana Cloud
Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role assignments, configures
Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate re
Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook), notification policies with hierarchical matchers, silences, mute timings, on-call schedules and escala
Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo / Pyroscope. Covers the Alloy config language (blocks, `sys.env`, component refs), `prometheus.scrape`
Get RED metrics + service maps + frontend RUM + AI/LLM monitoring out of Grafana Cloud — Application Observability (`traces_spanmetrics_*` from OTel traces, p50/p95/p99 latency, exemplar-to-trace, traces-to-logs / profiles), Frontend Observability with the Faro Web SDK (Core Web Vitals, session repl
Use when starting any grafana-app-sdk work — scaffolding a Grafana app, initializing a Grafana App Platform app, picking a deployment mode (standalone operator / grafana/apps / frontend-only), wiring app-specific config, or onboarding to the SDK. Covers `grafana-app-sdk` CLI install, `project init`
Connect AI coding agents (Claude Code, Cursor, VS Code, OpenAI Codex) to Grafana Cloud via the `mcp-grafana` Model Context Protocol server. Installs the server with `go install`, generates a Grafana service-account token, wires `~/.claude/settings.json` or `~/.cursor/mcp.json` with the `command` + `
Related devops skillsscan passed
Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up CI/CD, containerizing an app, or checking production readiness before a release.
Configure deployment settings for /land-and-deploy.
Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext. Use when starting a Next.js project on Cloudflare, moving an existing app to Workers, choosing between vinext and OpenNext, or setting up vinext for Workers. For setup, migration, or deployment, install vinext's upstream skil
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Instruments code so production behavior is visible and diagnosable. Use when adding logging, metrics, tracing, or alerting. Use when shipping any feature that runs in production and you need evidence it works. Use when production issues are reported but you can't tell what happened from the availabl
Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil