Official agent skill

Beyla

by grafana in grafana/skills

Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Beyla

skills CLI
$ npx skills add grafana/skills --skill beyla -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills beyla --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-core/beyla .claude/skills/beyla && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
beyla
GitHub stars
281
Token cost
~1.1k tokens
SKILL.md length
168 words
Files
3 (incl. references)
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart.

  • Works in 3 steps: Instrument a single binary with Docker → Deploy as a cluster-wide DaemonSet → Send to Grafana Cloud via Alloy
  • Adding observability to a service you cant recompile
  • SKILL.md covers Prerequisites, Common Workflows, Troubleshooting and Resources
  • Calls curl, kubectl and docker

What it does

Beyla is an agent skill from grafana/skills, published by the product's own GitHub organization. Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart. Covers requirements (Linux 5.8+ with BTF, CAPSYSADMIN, host PID), language matrix (Go / Java / Python / Ruby / Node / .NET / Rust / C++ / PHP), Docker + Helm + DaemonSet install, port- / process- / Kubernetes-metadata discovery, OTLP traces + Prometheus metrics export, routes decorator (cardinality control), trace sampling, and Grafana Cloud via Alloy. Use when adding observability to a service…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/config.md` and `references/kubernetes.md`).

It sits in DevOps & Cloud, covering Monitoring and alerting and Container orchestration. It works with Grafana, OpenTelemetry, Kubernetes and Docker. The licence is Apache-2.0.

When your agent uses it

  • Adding observability to a service you cant recompile
  • Instrumenting a closed-source binary
  • Getting RED metrics + spans onto Tempo/Mimir without touching the app
  • Rolling Beyla as a cluster-wide DaemonSet — even when the user says zero-code APM

Example prompts

  • “zero-code APM”
  • “instrument legacy app”
  • “trace this binary”
  • “/beyla”

Requirements

  • Python 3
  • Docker

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Instrument a single binary with Docker
  2. Deploy as a cluster-wide DaemonSet
  3. Send to Grafana Cloud via Alloy

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • kubectl
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • grafana.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Beyla loads about 1.1k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 212 tokens; SKILL.md has 168 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~212
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 168 words, ~1,057 tokens.

Download SKILL.mdSave it as .claude/skills/beyla/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
beyla
description
Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart. Covers requirements (Linux 5.8+ with BTF, CAP_SYS_ADMIN, host PID), language matrix (Go / Java / Python / Ruby / Node / .NET / Rust / C++ / PHP), Docker + Helm + DaemonSet install, port- / process- / Kubernetes-metadata discovery, OTLP traces + Prometheus metrics export, routes decorator (cardinality control), trace sampling, and Grafana Cloud via Alloy. Use when adding observability to a service you can't recompile, instrumenting a closed-source binary, getting RED metrics + spans onto Tempo/Mimir without touching the app, or rolling Beyla as a cluster-wide DaemonSet — even when the user says "zero-code APM", "instrument legacy app", "trace this binary", "eBPF observability", or "no SDK" without naming Beyla.
license
Apache-2.0

Grafana Beyla

Docs: https://grafana.com/docs/beyla/latest/

Zero-code HTTP / gRPC / DB instrumentation via eBPF. Emits OTLP traces + Prometheus metrics.

Prerequisites

  • Linux kernel 5.8+ with BTF enabled (ls /sys/kernel/btf/vmlinux must exist)
  • Root or CAP_SYS_ADMIN (or privileged: true in Kubernetes + hostPID: true)
  • x86_64 or ARM64
  • An OTLP receiver (Tempo, Alloy, OTel Collector) reachable from Beyla

Common Workflows

1. Instrument a single binary with Docker
bash
# 1. Run Beyla against the app's port (the app must already be running, listening on 8080)
docker run --privileged --pid=host \
  -v /sys/kernel/debug:/sys/kernel/debug:ro \
  -e BEYLA_OPEN_PORT=8080 \
  -e BEYLA_PROMETHEUS_PORT=8999 \
  -e OTEL_EXPORTER_OTLP_ENDPOINT=http://otel-collector:4318 \
  -p 8999:8999 \
  grafana/beyla

# 2. Generate some traffic
curl http://localhost:8080/ ; curl http://localhost:8080/api/users/42

# 3. Verify Beyla emitted metrics — should list http_server_request_duration_seconds + counters
curl -s http://localhost:8999/metrics | grep -E '^http_(server|client)_request_duration'

# 4. Verify traces — in Grafana Explore on Tempo, search by service.name (default = process name)
#    Or: query Tempo's search API for spans with service.name="<app>"
2. Deploy as a cluster-wide DaemonSet

Full DaemonSet + RBAC YAML lives in references/kubernetes.md. After applying:

bash
# 1. Verify DaemonSet rollout
kubectl -n monitoring rollout status ds/beyla

# 2. Verify pods are Running, one per node
kubectl -n monitoring get pods -l app=beyla -o wide

# 3. Verify eBPF probes attached (no errors mentioning BTF or "permission denied")
kubectl -n monitoring logs ds/beyla --tail=50 | grep -Ei 'error|fail|btf' || echo "clean"

# 4. Verify telemetry is flowing — check the Tempo/Alloy receiver for spans from the cluster
#    Or scrape one pod directly:
kubectl -n monitoring port-forward ds/beyla 8999:8999 &
curl -s localhost:8999/metrics | head
3. Send to Grafana Cloud via Alloy
yaml
# beyla-config.yml
otel_traces_export:  { endpoint: http://alloy:4318 }
otel_metrics_export: { endpoint: http://alloy:4318 }
bash
# Verify Alloy is forwarding — check Alloy UI (localhost:12345) for the
# otelcol.receiver.otlp.beyla component showing received spans/metrics > 0.

Full Alloy + Beyla YAML: references/config.md.

Troubleshooting

  • failed to load BPF object → kernel < 5.8 or BTF missing; check /sys/kernel/btf/vmlinux
  • No spans in Tempo, but Prometheus metrics show → check OTEL_EXPORTER_OTLP_ENDPOINT, protocol (http vs grpc), and ports (4318 http / 4317 grpc)
  • HTTP route cardinality explosion → set routes.unmatched: heuristic and add patterns (see references/config.md)
  • Pod restarts with CrashLoopBackOff → likely missing hostPID: true or privileged: true / required capabilities

Resources

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/grafana-core/beyla of grafana/skills.

  • SKILL.md
  • references/config.md
  • references/kubernetes.md

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Beyla next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Beyla compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Beyla this skillgrafana/skills281—~1.1kAutomated safety check: PassApache-2.0
Signozqjoly/GitOps112—~6.1kAutomated safety check: PassWTFPL
Grafana Dashboardpando85/kaniop131—~987Automated safety check: PassAGPL-3.0
Cloud Infra Supply Chainzhaji2333/CkSKILLS114—~688Automated safety check: WarnMIT
Kubernetes Deploymentaiskillstore/marketplace4305 repos~839Automated safety check: PassNone
Tsh Implementing ObservabilityTheSoftwareHouse/copilot-collections284—~2kAutomated safety check: PassMIT

Similar skills

  • Signoz

    qjoly/GitOps

    Manage the self-hosted SigNoz observability stack in this GitOps repo.

    112 GitHub stars~6.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Grafana Dashboard

    pando85/kaniop

    Improve and validate the Kaniop Grafana dashboard against repository metrics and the grigri live cluster.

    131 GitHub stars~987 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Infra Supply Chain

    zhaji2333/CkSKILLS

    当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。

    114 GitHub stars~688 tokensUpdated 24 days ago
    DevOps & CloudAuto-check: warnings
  • Kubernetes Deployment

    aiskillstore/marketplace

    Kubernetes deployment workflow for container orchestration, Helm charts, service mesh, and production-ready K8s configurations.

    430 GitHub starsUsed in 5 repos~839 tokens
    DevOps & CloudAuto-check passed
  • Tsh Implementing Observability

    TheSoftwareHouse/copilot-collections

    Observability patterns for logging, monitoring, alerting, and distributed tracing.

    284 GitHub stars~2k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Grafana

    magnus919/agent-skills

    Operate, configure, provision, secure, and troubleshoot Grafana OSS, Enterprise, and Cloud, including dashboards, folders, data sources, annotations, alert rules, contact points, notification…

    116 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    281 GitHub stars~678 tokensUpdated yesterday
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    281 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    281 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    281 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    281 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    281 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Beyla

What does Beyla do?

Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart. Beyla is an agent skill from grafana/skills, published by the product's own GitHub organization. Auto-instrument an application's HTTP / gRPC / DB traffic with Grafana Beyla eBPF — no code changes, no SDK, no restart.

When should I use Beyla?

Beyla fits situations like: adding observability to a service you cant recompile; instrumenting a closed-source binary; getting RED metrics + spans onto Tempo/Mimir without touching the app; rolling Beyla as a cluster-wide DaemonSet — even when the user says zero-code APM.

How do I install Beyla in Claude Code?

Run `npx skills add grafana/skills --skill beyla -a claude-code`. Or copy the skill folder (skills/grafana-core/beyla in grafana/skills) into .claude/skills/beyla in your project. Claude Code loads it when a task matches its description.

How do I install Beyla in Codex?

Run `npx skills add grafana/skills --skill beyla -a codex`. Or copy the skill folder (skills/grafana-core/beyla in grafana/skills) into .agents/skills/beyla in your project. Codex loads it when a task matches its description.

Can I use Beyla in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill beyla -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/beyla, .gemini/skills/beyla, .github/skills/beyla and .opencode/skills/beyla in your project.

What does Beyla need to run?

Going by SKILL.md and its folder, Beyla needs the command-line tools its instructions call (curl, kubectl and docker). Our summary lists: Python 3; Docker.

Does Beyla access the network?

SKILL.md names 2 domains. As links in the text: grafana.com and github.com. This is read from the text; nothing was executed.

Is Beyla safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Beyla use?

Beyla is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Beyla use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Beyla?

Skills that share tags, products or a category with Beyla: Signoz (qjoly/GitOps, 112 stars), Grafana Dashboard (pando85/kaniop, 131 stars), Cloud Infra Supply Chain (zhaji2333/CkSKILLS, 114 stars) and Kubernetes Deployment (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Beyla?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 281 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.