Linkerd¶
Summary
Linkerd is a CNCF Graduated service mesh for Kubernetes. It is built around linkerd2-proxy, a Rust micro-proxy that runs as a per-pod sidecar (a native sidecar by default since 2.20), and a small Go/Rust control plane. It gives you mTLS by default, with post-quantum hybrid key exchange since 2.19. It also provides latency-aware (EWMA) load balancing, golden metrics, Gateway API-based routing, authorization policy, egress control, rate limiting and federated multicluster, all with little configuration. The current version is 2.20 (2026-06-23). Since February 2024 the open-source project ships only edge releases. Stable, semantically versioned builds come from vendors, mainly Buoyant Enterprise for Linkerd.
Key Facts¶
| Attribute | Detail |
|---|---|
| Latest Version (date) | 2.20 (2026-06-23), corresponding edge edge-26.6.3 |
| Latest Edge Release (date) | edge-26.9.3 (2026-09-16), proxy v2.369.0 |
| Latest Stable Distribution | Buoyant Enterprise for Linkerd 2.20.3 (tagged 2026-09-15; fixes three of the six issues in Buoyant Security Advisory 2026-01). Previous: 2.20.2 (2026-08-26) |
| Release Cadence | Edge: weekly or near-weekly. Major versions: roughly every 4 to 8 months (2.17 Dec 2024, 2.18 Apr 2025, 2.19 Oct 2025, 2.20 Jun 2026). |
| License | Apache-2.0 (code). BEL is a proprietary distribution that needs a license key. |
| Governance | CNCF Graduated (2021-07-28). Steering committee of end users. All maintainers work for Buoyant. |
| Language | Rust (data plane proxy, policy controller), Go (control plane, CLI) |
| Data Plane | linkerd2-proxy sidecar (native sidecar by default since 2.20) |
| Kubernetes Support | 2.20: 1.31 to 1.35 |
| Gateway API Support | 2.20: 1.2.1 to 1.5.1 (CRDs installed separately) |
| Company | Buoyant (creator, main maintainer, BEL vendor) |
| Website / Repo | linkerd.io, github.com/linkerd/linkerd2 |
Architecture¶
The core control plane serves discovery, policy and certificates. Every meshed pod carries a Rust proxy that intercepts its TCP traffic. The full component breakdown is in the Explanation.
flowchart LR
subgraph CP["linkerd namespace"]
DEST["linkerd-destination<br/>(destination + policy + sp-validator)"]
ID["linkerd-identity<br/>(CA)"]
INJ["linkerd-proxy-injector<br/>(webhook)"]
end
subgraph PA["pod A"]
A["app"] --> PXA["linkerd-proxy"]
end
subgraph PB["pod B"]
PXB["linkerd-proxy"] --> B["app"]
end
INJ -.->|"injects at pod create"| PA
PXA -->|"discovery + policy"| DEST
PXA -->|"CSR, 24h cert"| ID
PXA <-->|"mTLS, ML-KEM-768 hybrid"| PXB
Key Features¶
| Feature | Detail | Since |
|---|---|---|
| Automatic mTLS | On for all meshed-to-meshed TCP. TLS 1.3 with hybrid ML-KEM-768 + X25519 key exchange by default. | mTLS 2.3. Post-quantum 2.19. |
| Latency-aware load balancing | Per-request P2C over peak-EWMA for HTTP and gRPC. Optional rate-limit-aware "Load Biaser". | Biaser 2.20 (experimental) |
| Retries and timeouts | Annotations on Gateway API HTTPRoute, GRPCRoute or Service. They compose with each other and with circuit breaking. | 2.16 |
| Circuit breaking | Failure accrual per endpoint: consecutive, or unified (counts 429s) |
2.13, unified 2.20 |
| Dynamic routing and canaries | Gateway API HTTPRoute weights and matches (GAMMA) | 2.14 |
| Authorization policy | Server, AuthorizationPolicy, MeshTLSAuthentication, NetworkAuthentication, audit mode | 2.11+, audit 2.16 |
| Rate limiting | Local, inbound HTTPLocalRateLimitPolicy with per-client fairness |
2.17 |
| Egress visibility and control | EgressNetwork + Gateway API routes, enforced in the sidecar |
2.17 |
| Multicluster | Gateway (hierarchical), flat pod-to-pod, federated services, GitOps link-gen |
2.8, 2.14, 2.17, 2.18 |
| Mesh expansion | VMs and bare metal through ExternalWorkload and SPIFFE/SPIRE |
2.15 |
| Observability | Golden metrics (success rate, RPS, latency), tap, OpenTelemetry tracing, near-parity inbound metrics | Tracing on OTel 2.17, inbound metrics 2.20 |
| Native sidecars | Proxy runs as a restartable init container. This fixes Jobs and startup races. | Alpha 2.15, beta 2.19, default 2.20 |
| IPv6 | IPv6-only and dual-stack (opt-in) | 2.16 |
Evaluation¶
| Pros | Cons |
|---|---|
| Very small proxy footprint. The vendor benchmark measured about 8x less proxy memory than an Istio 1.10 sidecar (numbers). | Sidecar only. There is no sidecar-less mode comparable to Istio ambient. |
| Rust proxy: memory-safe, no GC pauses | No open-source stable or semver artifacts since 2024. OSS users track edge releases. |
| mTLS on by default, with post-quantum hybrid key exchange | BEL features (HAZL, FIPS, Windows, automated trust anchor rotation) need a paid license at 50+ employees |
| Simple install and upgrade, few knobs | Smaller ecosystem and feature surface than Istio. No Wasm or custom filters, no built-in end-user JWT authentication. |
| Standard Gateway API configuration (first Mesh-profile conformant mesh) | Gateway API CRD version must be managed separately (since 2.19) |
| Circuit breaking, rate limiting and egress control are now built in | Rate limiting is local only (no global limiter). Egress policy can be bypassed by workloads that skip the sidecar. |
| Federated multicluster with transparent failover | All maintainers work for one company (Buoyant) |
| Mature: CNCF Graduated, about ten years of production use | Trust anchor and issuer expiry is an operational trap if not automated |
When It Fits¶
- Teams that want mTLS, golden metrics and good gRPC load balancing with the least operational effort.
- Clusters where per-pod resource overhead matters and where L7 needs stay within routing, retries, timeouts, circuit breaking and authorization.
- Multi-cluster estates that want one logical service across clusters (federated services).
When to Look Elsewhere¶
- You need sidecar-less operation, Envoy extensibility (Wasm, ext_authz), or JWT authentication at the mesh: see Istio.
- You only need north-south ingress: see Envoy Gateway.
- You need a supported, semver-stable build but will not buy BEL: budget for tracking edge releases, or choose another mesh.
Licensing and Pricing¶
- Linkerd code: Apache-2.0. Anyone can build and run it. Edge release binaries, images and Helm charts (
https://helm.linkerd.io/edge) are free. - Buoyant Enterprise for Linkerd (BEL): a stable distribution with backports, support options and enterprise-only features. It needs a license key. According to Buoyant, it is free for production use at companies with fewer than 50 employees (no support included). The list price at launch was reported as US$2,000 per cluster per month (The New Stack, 2024). Check the Buoyant pricing page for current terms.
Ecosystem and Compatibility¶
- Kubernetes: 1.31 to 1.35 for 2.20 (full table in Reference). It runs on EKS, GKE (private clusters need firewall rules), AKS, k3s and kind.
- CNI: works with most CNIs. On Cilium, socket-level load balancing must stay in the host namespace.
linkerd-cnichains with the existing CNI. - Certificates: cert-manager and trust-manager for issuer rotation. External CAs such as Vault can issue the issuer certificate.
- Observability: Prometheus metrics on each proxy. OpenTelemetry tracing (see OpenTelemetry).
- Delivery: Gateway API routes work with Flagger and Argo Rollouts. Declarative multicluster links suit Argo CD GitOps.
Topic Map¶
- How-to Guides: install (CLI, Helm, cert-manager), mesh workloads, policy, egress, retries, circuit breaking, multicluster, upgrades, troubleshooting.
- Reference: versions, compatibility matrices, ports, CRDs, annotations, certificate defaults, benchmark numbers.
- Explanation: architecture, proxy internals, identity and trust chain, policy model, load balancing, Gateway API migration, multicluster modes, release model.
Related Topics¶
- Service Mesh Comparison: Istio vs Linkerd vs Envoy Gateway
- Service mesh domain overview
- Istio, the main alternative (sidecar or ambient, Envoy-based)
- Envoy Gateway for north-south traffic alongside Linkerd
- Kubernetes
- Cilium: CNI interaction and an alternative mesh approach
Sources¶
- Linkerd documentation (edge)
- Releases and Versions
- linkerd/linkerd2 releases and edge-26.9.3
- Announcing Linkerd 2.20
- Announcing Linkerd 2.19: Post-quantum cryptography
- Announcing Linkerd 2.18
- Announcing Linkerd 2.17: Egress, Rate Limiting, and Federated Services
- Announcing Linkerd 2.15 (new model for stable releases)
- Architecture
- linkerd2-proxy
- CNCF: Linkerd graduation (2021-07-28)
- CNCF project page
- BEL 2.20 release notes
- BEL FAQ (licensing)
- The New Stack: Buoyant revises release model for Linkerd
Questions¶
Open¶
- Will Linkerd ship a sidecar-less or "ambient-like" mode? The 2.15 announcement said the project is evaluating ambient and other approaches. No design had been published as of 2026-09. See Explanation: Native Sidecars.
- Is there a current, independent benchmark against Istio ambient mode? Only the 2021 vendor benchmark (sidecar vs sidecar) and LiveWyer 2024 exist. See Reference: benchmarks.
- When will ServiceProfiles and the SMI extension be removed, rather than frozen or deprecated? See Explanation: Configuration Model.
- What does BEL cost for companies with 50 or more employees? Buoyant's pricing page (checked 2026-09-28 via search listing) says BEL is free to try and free in production below 50 employees, and its indexed text shows no price for the paid plans.
Answered¶
- Is Linkerd lighter than Istio? Yes, for sidecar vs sidecar. The 2021 benchmark (Linkerd 2.10.2 vs Istio 1.10.0) measured a maximum proxy memory of 17.8 MB vs 154.6 MB, and control plane memory of 324 MB vs 837 MB. Istio ambient changes the comparison. See Reference.
- Does Linkerd have circuit breaking and rate limiting? Yes. Circuit breaking through failure accrual has existed since 2.13. Local rate limiting arrived in 2.17. See Explanation.
- Is Linkerd still open source after the 2024 change? Yes. The code stays Apache-2.0 under CNCF governance. Only stable release artifacts moved to vendors. Edge releases remain open source. See Explanation: Release Model.