Model or dataset
deepflowio/deepflow avatar
deepflowio/deepflow

DeepFlow: eBPF Observability for Cloud and AI Applications Without Code Changes

eBPF Observability - Distributed Tracing and Profiling

4,285 stars484 forksGoApache-2.0

At a glance

What is it?
DeepFlow Community Edition collects metrics, distributed traces, request logs and function profiles with eBPF, then correlates them through SmartEncoding. It suits Kubernetes and cloud-native teams that cannot instrument every service by hand.
Who is it for?
Adopt DeepFlow Community if you run Kubernetes or cloud hosts and cannot get instrumentation into every service, and if you accept that the agent needs kernel-level access on each node. Do not adopt it if you only need application-level tracing you already control, or if you cannot run privileged workloads.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 3 days ago.
What is it written in?
Mainly Go, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem DeepFlow targets: services nobody will instrument

Most observability plans fail at the same point. Someone has to add an SDK, rebuild the service, and redeploy it. In a cluster with dozens of services in several languages, plus gateways, service meshes, databases and message queues, that work never finishes. DeepFlow's answer is to collect from the kernel instead. The README describes the project as providing "deep observability for complex cloud-native and AI applications" with zero-code collection via eBPF for metrics, distributed tracing, request logs and function profiling. The intended reader is the DevOps or SRE team that owns production but does not own every line of code running in it. That framing also sets the boundary: DeepFlow observes what crosses the machine, so it is strongest where traffic and system calls exist and weakest where business logic lives only inside a process and never touches the network.

How the agent and server split the work

The Community Edition has two components. An agent runs on each Kubernetes node, legacy host and cloud host, and performs AutoMetrics and AutoTracing collection for all application processes on that host. A server runs in a Kubernetes cluster and handles agent management, tag injection, data ingest and query. That split matters operationally: the agent is the part with kernel access and per-node resource cost, and the server is the part that holds state and answers queries. The README states that agents cover application services, AI services and infrastructure services, and that Wasm plugins handle private protocols the built-in parsers do not know. Correlation is the second half of the design. SmartEncoding injects standardized, pre-encoded meta tags (cloud resource, K8s container, K8s labels and annotations, CMDB business attributes) into every signal, and the README claims this reduces storage overhead by 10x compared with ClickHouse String or LowCard methods. Treat that number as the project's own claim, not an independent measurement.

Installing DeepFlow Community and reading your first service map

The README does not inline install commands. It points to the deployment documentation for the Community Edition at the all-in-one install page, and separately to a compile guide for the agent. So the honest first step is to open that page rather than guess at a manifest. The repository does ship the pieces the deployment uses, including a manifests directory and an agent directory with its own build.md. If you want to build the agent yourself instead of using published images, the README gives the compile path directly.

bash
cd agent
# follow agent/build.md for the build steps

The README also offers a hosted Community Demo with the login account deepflow and the password deepflow-2026, which is the fastest way to see what the universal map and trace views look like before you deploy anything. For a real install, the all-in-one documentation is the source of truth for prerequisites, image names and configuration keys; this article cannot reproduce them because the README does not list them. Expect the agent to need elevated privileges on each node, since eBPF collection is the whole point of the product.

Where zero-code collection stops being enough

Kernel-level collection has a hard edge. If a call never leaves the process, or if the protocol is encrypted end to end with keys the agent cannot see, the agent has less to work with. The README's answer to unknown protocols is Wasm plugins, which means private wire formats are your responsibility to describe, not something DeepFlow infers. The profiling claim deserves the same caution: the README states profiling is collected "at a cost of below 1%" and produces OnCPU, OffCPU, GPU, Memory and Network flame graphs, but that figure comes from the project, and the real cost depends on sampling configuration and workload shape. There is also an edition boundary. The Community Edition is described as the core components of the Enterprise Edition, and the Enterprise Edition is positioned for organizations solving team collaboration problems. If your requirement is multi-team governance rather than raw collection, the open source edition may not be the whole answer.

DeepFlow against OpenTelemetry-based tracing

The obvious alternative is an OpenTelemetry pipeline: instrument services with vendor-neutral APIs, ship spans to a collector, and store them in a backend. The README acknowledges OpenTelemetry directly, and DeepFlow can act as a storage backend for it. The difference is where the data originates. OpenTelemetry gives you precise, semantically rich spans because the application emits them, and it can describe logic that never touches the network. DeepFlow gives you coverage without touching the application, and it can see infrastructure that will never be instrumented at all: gateways, service meshes, databases, message queues, DNS and NICs. The README explicitly lists those as part of its tracing coverage. In practice the two are complementary rather than exclusive, and the README's own integration list (Prometheus, OpenTelemetry, SkyWalking, Pyroscope, plus SQL, PromQL and OLTP APIs) suggests the project expects to sit alongside them rather than replace them.

Licence, releases and what upgrades cost you

DeepFlow is released under Apache-2.0, which permits commercial use and modification under the terms of that licence; read the LICENSE file in the repository for the actual terms rather than relying on a summary. The release cadence visible in the repository is steady: v7.1 in March 2026, v7.2.0 in August 2026, and v7.2.1 later the same month, with the last push to the default branch on 2026-09-09. A patch release landing two weeks after a minor release is a normal signal that fixes are being shipped, but it also means you should read CHANGELOG.md before upgrading rather than assuming a drop-in replacement. The upgrade cost sits mostly on the server side, where storage schema and query behaviour live; the agent is deployed per node, so an agent upgrade is a rolling operation across your fleet. Neither cost is documented in the README, so plan to check the deployment documentation for version compatibility before you move.

Editorial conclusion

Adopt DeepFlow Community if you run Kubernetes or cloud hosts and cannot get instrumentation into every service, and if you accept that the agent needs kernel-level access on each node. Do not adopt it if you only need application-level tracing you already control, or if you cannot run privileged workloads. Before committing, verify the eBPF and kernel requirements for your node images, check that your private protocols are covered by a Wasm plugin or a supported parser, and confirm how the server stores and retains data in your own cluster.

Frequently asked questions

Is DeepFlow free to use?

The DeepFlow Community Edition is open source under Apache-2.0, and the README describes it as consisting of the core components of the Enterprise Edition. DeepFlow Enterprise and the DeepFlow Cloud SaaS service are separate editions; the README notes the cloud service is currently in beta.

What is DeepFlow?

DeepFlow is an open-source project that provides observability for cloud-native and AI applications. It collects metrics, distributed tracing, request logs and function profiling with eBPF, using zero-code collection rather than application instrumentation.

What is the DeepFlow app?

The README does not describe a standalone DeepFlow app. It describes two components, an agent that runs on each node or host and a server that runs in Kubernetes, plus a hosted Community Demo you can log into with the account deepflow and the password deepflow-2026.

What is the Google Deep Flow app?

The README makes no mention of a Google product by that name. The project it documents is DeepFlow, an open-source eBPF observability tool for cloud-native and AI applications, hosted at deepflow.io.

What is a deep flow app?

The README does not define a product by that phrasing. It describes DeepFlow as an open-source project with an agent on each node and a server in Kubernetes, which together collect metrics, traces, request logs and profiles.

Official sources

  1. deepflowio/deepflow on GitHub
  2. License: Apache-2.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/deepflowio-deepflow.svg)](https://hysenlabs.com/projects/deepflowio-deepflow)