{"data":{"slug":"kubeshark-kubeshark","name":"kubeshark","tagline":"eBPF-powered network observability for Kubernetes","github_url":"https://github.com/kubeshark/kubeshark","owner":"kubeshark","repo":"kubeshark","owner_avatar_url":"https://avatars.githubusercontent.com/u/99263827?v=4","primary_language":"Go","stars":12056,"forks":545,"topics":["cloud-native","devops","docker","ebpf","golang","grpc","incident-response","kubernetes","mcp","network-analysis","network-engineering","network-observability","network-security","observability","pcap","rest","root-cause-analysis","sniffer","sre","wireshark"],"archived":false,"github_pushed_at":"2026-08-25T06:18:46+00:00","maintenance_label":"Very active","stars_delta_30d":42,"url":"https://www.graphcanon.com/tools/kubeshark-kubeshark","markdown_url":"https://www.graphcanon.com/tools/kubeshark-kubeshark.md","api_url":"https://www.graphcanon.com/api/graphcanon/tools/kubeshark-kubeshark","graph_url":"https://www.graphcanon.com/api/graphcanon/graph?tool=kubeshark-kubeshark","description":"eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.","homepage_url":"https://kubeshark.com","license":"Apache-2.0","open_issues":146,"watchers":71,"ai_summary":"Provides full L4/L7 traffic indexing, TLS decryption without keys, accessible via dashboard and by AI agents through MCP in a Kubernetes environment.","readme_excerpt":"## Install\n\n| Method | Command |\n|--------|---------|\n| Helm | `helm repo add kubeshark https://helm.kubeshark.com && helm install kubeshark kubeshark/kubeshark` |\n| Homebrew | `brew install kubeshark && kubeshark tap` |\n| Binary | [Download](https://github.com/kubeshark/kubeshark/releases/latest) |\n\n[Installation guide →](https://docs.kubeshark.com/en/install)\n\n---","github_created_at":"2021-04-19T10:29:56+00:00","created_at":"2026-07-11T11:49:20.596662+00:00","updated_at":"2026-08-26T00:02:34.297285+00:00","categories":[{"slug":"evaluation-observability","name":"Evaluation & Observability","url":"https://www.graphcanon.com/categories/evaluation-observability","markdown_url":"https://www.graphcanon.com/categories/evaluation-observability.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/evaluation-observability"}],"tags":[{"slug":"cloud-native","name":"cloud-native"},{"slug":"devops","name":"devops"},{"slug":"docker","name":"docker"},{"slug":"ebpf","name":"ebpf"},{"slug":"golang","name":"golang"},{"slug":"grpc","name":"grpc"},{"slug":"incident-response","name":"incident-response"},{"slug":"kubernetes","name":"kubernetes"}],"trust":{"provenance":{"is_fork":false,"github_id":359419233,"owner_type":"Organization","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-08-26T00:02:33.580Z","maintenance":{"label":"Very active","score":96,"methodology":"github_public_v1","releases_90d":1,"days_since_push":0,"last_release_at":"2026-08-13T20:09:32Z","stars_delta_30d":42,"open_issues_delta_30d":5},"security_summary":{"status":"no_manifest","scanner":null,"low_count":0,"high_count":0,"last_scan_at":"2026-07-11T11:49:21.773Z","medium_count":0,"scan_profile":"mcp_manifest","critical_count":0}},"capability_facts":{"scan":{"source":"repo_scan","observed_at":"2026-08-26T00:02:34.022Z"},"languages":{"value":["go"],"source":"github.language","observed_at":"2026-08-26T00:02:34.022Z"},"license_spdx":{"value":"Apache-2.0","source":"github.license","observed_at":"2026-08-26T00:02:34.022Z"}},"decision_facts":{"hosting":null,"pricing":null,"requirements":null,"constraints":null,"when_to_use":["- When you need to perform deep inspection of Kubernetes traffic on both layer 4 (transport) and layer 7 (application), with contextual information from the Kubernetes environment","- For situations where real-time TLS decryption is needed but access to TLS keys is not available or feasible"],"when_not_to_use":["- If your primary focus is on a different cloud platform as Kubeshark is deeply integrated with Kubernetes and provides its full context along side traffic observations","- When the system does not support eBPF, which is critical for Kubeshark's operation"],"source":"enrich:decision_facts","observed_at":"2026-07-16T20:21:32.993Z"},"constraint_facets":null,"decision_summary":[{"label":"Adopt for","value":"Kubeshark is an eBPF-powered network observability tool for Kubernetes that offers full L4/L7 traffic indexing and TLS decryption without needing keys."}]}}