-
Notifications
You must be signed in to change notification settings - Fork 393
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: Add high level overview to Readme #650
Conversation
Readme.md
Outdated
@@ -17,6 +17,7 @@ Tracee is composed of the following sub-projects: | |||
- [libbpgo](libbpfgo) - Go library for eBPF programming using Linux's [libbpf](https://github.com/libbpf/libbpf) | |||
|
|||
## Getting started | |||
![High Level Overview](images/highleveloverview.png) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I wouldn't put this under getting started as it doesn't help the user get started. IMO the end user shouldn't even be aware of the intricacies of the internal components, only developers should. In the new readme (#647 ) this would fit under the "components" section. Appreciate if you could rebase on that PR (once merged)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actually, perhaps it would be beneficial to have an architecture.md file, for the sake of introducing contributors to tracee (as opposed to users which have the docs site). at first this doc can just contain this diagram, perhaps in the future we will add content
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah sure I'm OK with that. I can change it live in architecture.md instead.
I need to try excalidraw, diagram looks great! My only comment is the "event detected" by (3). If I understand correctly all of the events are fed to tracee-rules in which case I feel 'event detected' makes more sense to be inside of tracee-rules's box. Perhaps a better thing to put there is "flow of events created by tracee-ebpf"? And the 'events sent' from (2) should be "events created"? |
Right, how about I change it to: |
Signed-off-by: Simarpreet Singh <simar@linux.com>
Signed-off-by: Simarpreet Singh <simar@linux.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The title over the tracee-rules block should say detection, imo. Otherwise lgtm
Signed-off-by: Simarpreet Singh <simar@linux.com>
Fixes: #637
Signed-off-by: Simarpreet Singh simar@linux.com