Deepflow

eBPF Observability - Distributed Tracing and Profiling

Last verified:

Visit Deepflow

What is Deepflow?

DeepFlow is an automated observability platform for cloud-native developers that provides instant observability for cloud and AI applications using eBPF and Wasm technologies. It delivers zero-code, full-stack observability through AutoTracing, AutoMetrics, AutoTagging, and SmartEncoding, eliminating the need for heavy code instrumentation and significantly reducing resource overhead for back-end data warehouses.

Key features include a Universal Map for any service with zero-code eBPF-based metrics, zero-intrusion distributed tracing for applications in any language covering gateways, service meshes, databases, message queues, DNS and NICs, and continuous profiling with below 1% overhead for OnCPU/OffCPU/GPU/Memory/Network flame graphs. DeepFlow also provides Full Stack golden signals, network performance metrics, file I/O events for each Span, and serves as a storage backend for Prometheus, OpenTelemetry, SkyWalking and Pyroscope with SQL, PromQL and OLTP APIs.

DeepFlow is designed for cloud-native and AI application developers, DevOps teams, and SREs who need deep observability without continually instrumenting code. It covers everything from code to infrastructure, supporting services in any language, third-party services without code, and all cloud-native infrastructure services. The platform is particularly valuable for organizations with complex microservices architectures seeking to eliminate observability blind spots.

Deepflow pricing

Pricing model: Freemium

DeepFlow offers three editions: DeepFlow Community (free for developers), DeepFlow Enterprise (for organizations solving team collaboration problems), and DeepFlow Cloud (SaaS service currently in beta). The DeepFlow Community Edition consists of the core components of the Enterprise Edition and is completely free. A complete DeepFlow Community Demo is available with login account/password: deepflow/deepflow. The Enterprise Edition is for organizations and solves team collaboration problems. DeepFlow Cloud is the SaaS service option that is currently in beta. No specific pricing amounts are published for Enterprise or Cloud editions on the website.

Deepflow pros

  • Zero-code data collection with eBPF for metrics, tracing, logs and profiling
  • AutoTracing enables distributed tracing without generating or propagating TraceID
  • AutoMetrics provides universal map for any service in any language
  • AutoTagging automatically injects cloud resource tags and K8s service tags
  • SmartEncoding reduces storage overhead by 10x compared to ClickHouse
  • Below 1% overhead for continuous profiling data collection
  • Supports applications in any language without code instrumentation
  • Full Stack golden signals calculated for applications and infrastructures
  • Zero-intrusion tracing covers gateways, service meshes, databases, message queues, DNS, NICs
  • Full Stack network performance metrics and file I/O events automatically collected for each Span
  • OnCPU/OffCPU/GPU/Memory/Network flame graphs locate performance bottlenecks
  • Works as storage backend for Prometheus, OpenTelemetry, SkyWalking and Pyroscope
  • Provides SQL, PromQL and OLTP APIs for integration with observability stacks
  • Wasm plugins support for private protocols beyond common protocols
  • DeepFlow Community Edition available free for developers with core components
  • Automatic correlation of eBPF Event, BPF Packet, Thread ID, Coroutine ID
  • K8s Label/Annotation/Env custom tags automatically injected
  • Profiles business functions, library functions, runtime functions, kernel functions, CUDA functions

Deepflow cons

  • Cross-thread request handling limitations (Golang Channel, in-memory message queues)
  • Coroutine scheduling scenarios not fully supported (Erlang, some Golang Goroutine cases)
  • Asynchronous invocations through message queues (Kafka/Redis) have limitations
  • eBPF requires Linux kernel 4.14+ for full functionality
  • Cross-thread communication through memory queues not fully covered by zero-code tracing
  • Enterprise Demo currently available in Chinese only
  • Cross-thread scenarios between receiving and responding requests not fully automated
  • Gateway cross-thread handling (HAProxy/Envoy) has limitations
  • SaaS service (DeepFlow Cloud) still in beta
  • Finer service decomposition needed for maximum eBPF distributed tracing effectiveness

Frequently asked questions about Deepflow

What is DeepFlow?

DeepFlow is an open-source automated observability platform for cloud-native developers that provides deep observability for complex cloud-native and AI applications. It uses eBPF and Wasm technologies to implement zero-code data collection for metrics, distributed tracing, request logs and function profiling, integrated with SmartEncoding for full-stack correlation and efficient access to all observability data.

How does DeepFlow achieve zero-code distributed tracing?

DeepFlow innovatively implements zero-intrusion distributed tracing based on eBPF without generating, injecting, or propagating TraceID. It correlates eBPF Event, BPF Packet, Thread ID, Coroutine ID, Request arrival sequence, and TCP send sequence to achieve AutoTracing. It supports all same-thread call scenarios and some cross-thread call scenarios by parsing protocol headers and X-Request-ID, TraceID/SpanID in MySQL Comments.

What programming languages does DeepFlow support?

DeepFlow supports applications in any language without requiring code instrumentation. Its zero-code distributed tracing powered by eBPF works for services in any language, including C/C++, Golang, Rust, Java applications for continuous profiling. The Universal Map provides observability for application services, AI services, and infrastructure services in any language.

What is SmartEncoding and how does it work?

SmartEncoding injects standardized and pre-encoded meta tags into all observability data, reducing storage overhead by 10x compared to ClickHouse String or LowCard method. Custom tags and observability data are stored separately, making tags available for almost unlimited dimensions and cardinalities with uncompromised query experience like BigTable.

What are the current limitations of AutoTracing?

AutoTracing based on eBPF has limitations with cross-thread request handling where receiving and sending requests are on different threads (using in-memory message queues like Golang Channel), coroutine scheduling scenarios (Erlang, Golang Goroutine), and service communication through message queues (Kafka/Redis). These can often be solved using transaction serial numbers extracted by DeepFlow Wasm Plugin or by extracting TraceID from requests.

How does DeepFlow integrate with existing observability stacks?

DeepFlow can serve as storage backend for Prometheus, OpenTelemetry, SkyWalking and Pyroscope. It provides SQL, PromQL and OLTP APIs to work as data source in popular observability stacks. It supports integration of Prometheus and Telegraf metric data, OpenTelemetry and SkyWalking tracing data, Pyroscope continuous profiling data, and can export tracing data to OpenTelemetry Collector and SkyWalking.

What editions of DeepFlow are available?

There are three editions: DeepFlow Community for developers (free, consists of core components of Enterprise Edition), DeepFlow Enterprise for organizations solving team collaboration problems, and DeepFlow Cloud which is a SaaS service currently in beta. A complete DeepFlow Community Demo is available for experience.

What infrastructure components does DeepFlow cover?

DeepFlow provides zero-code distributed tracing covering gateways, service meshes, databases, message queues, DNS and NICs, leaving no blind spots. It collects Full Stack network performance metrics and file I/O events automatically for each Span, and provides observability for all cloud-native infrastructure services.

What is the performance overhead of DeepFlow profiling?

DeepFlow collects profiling data at a cost of below 1% with zero code. It plots OnCPU/OffCPU/GPU/Memory/Network function call stack flame graphs and locates Full Stack performance bottlenecks across business functions, library and framework functions, runtime functions, shared library functions, kernel functions, and CUDA functions.

How does DeepFlow handle protocol parsing?

DeepFlow analyzes common protocols and supports Wasm plugins for private protocols. It has various application protocol parsing and performance analysis capabilities based on eBPF tracepoint/kprobe, uprobe for Golang HTTP2 and gRPC, and openssl HTTPS. It also supports enhanced standard protocol parsing capabilities using Wasm and so plugins, with plans for Lua plugin support.

Categories

Use cases

Browse all AI tools on NeedAnAI