Observe, don't contain. eBPF traces the agent at the kernel boundary — observability is the security posture. By the eunomia-bpf group (UC Santa Cruz + ShanghaiTech). arXiv 2508.02736