Skip to content

Linkerd

Summary

Linkerd is a CNCF Graduated service mesh for Kubernetes. It is built around linkerd2-proxy, a Rust micro-proxy that runs as a per-pod sidecar (a native sidecar by default since 2.20), and a small Go/Rust control plane. It gives you mTLS by default, with post-quantum hybrid key exchange since 2.19. It also provides latency-aware (EWMA) load balancing, golden metrics, Gateway API-based routing, authorization policy, egress control, rate limiting and federated multicluster, all with little configuration. The current version is 2.20 (2026-06-23). Since February 2024 the open-source project ships only edge releases. Stable, semantically versioned builds come from vendors, mainly Buoyant Enterprise for Linkerd.

Key Facts

Attribute Detail
Latest Version (date) 2.20 (2026-06-23), corresponding edge edge-26.6.3
Latest Edge Release (date) edge-26.9.3 (2026-09-16), proxy v2.369.0
Latest Stable Distribution Buoyant Enterprise for Linkerd 2.20.3 (tagged 2026-09-15; fixes three of the six issues in Buoyant Security Advisory 2026-01). Previous: 2.20.2 (2026-08-26)
Release Cadence Edge: weekly or near-weekly. Major versions: roughly every 4 to 8 months (2.17 Dec 2024, 2.18 Apr 2025, 2.19 Oct 2025, 2.20 Jun 2026).
License Apache-2.0 (code). BEL is a proprietary distribution that needs a license key.
Governance CNCF Graduated (2021-07-28). Steering committee of end users. All maintainers work for Buoyant.
Language Rust (data plane proxy, policy controller), Go (control plane, CLI)
Data Plane linkerd2-proxy sidecar (native sidecar by default since 2.20)
Kubernetes Support 2.20: 1.31 to 1.35
Gateway API Support 2.20: 1.2.1 to 1.5.1 (CRDs installed separately)
Company Buoyant (creator, main maintainer, BEL vendor)
Website / Repo linkerd.io, github.com/linkerd/linkerd2

Architecture

The core control plane serves discovery, policy and certificates. Every meshed pod carries a Rust proxy that intercepts its TCP traffic. The full component breakdown is in the Explanation.

flowchart LR
    subgraph CP["linkerd namespace"]
        DEST["linkerd-destination<br/>(destination + policy + sp-validator)"]
        ID["linkerd-identity<br/>(CA)"]
        INJ["linkerd-proxy-injector<br/>(webhook)"]
    end
    subgraph PA["pod A"]
        A["app"] --> PXA["linkerd-proxy"]
    end
    subgraph PB["pod B"]
        PXB["linkerd-proxy"] --> B["app"]
    end
    INJ -.->|"injects at pod create"| PA
    PXA -->|"discovery + policy"| DEST
    PXA -->|"CSR, 24h cert"| ID
    PXA <-->|"mTLS, ML-KEM-768 hybrid"| PXB

Key Features

Feature Detail Since
Automatic mTLS On for all meshed-to-meshed TCP. TLS 1.3 with hybrid ML-KEM-768 + X25519 key exchange by default. mTLS 2.3. Post-quantum 2.19.
Latency-aware load balancing Per-request P2C over peak-EWMA for HTTP and gRPC. Optional rate-limit-aware "Load Biaser". Biaser 2.20 (experimental)
Retries and timeouts Annotations on Gateway API HTTPRoute, GRPCRoute or Service. They compose with each other and with circuit breaking. 2.16
Circuit breaking Failure accrual per endpoint: consecutive, or unified (counts 429s) 2.13, unified 2.20
Dynamic routing and canaries Gateway API HTTPRoute weights and matches (GAMMA) 2.14
Authorization policy Server, AuthorizationPolicy, MeshTLSAuthentication, NetworkAuthentication, audit mode 2.11+, audit 2.16
Rate limiting Local, inbound HTTPLocalRateLimitPolicy with per-client fairness 2.17
Egress visibility and control EgressNetwork + Gateway API routes, enforced in the sidecar 2.17
Multicluster Gateway (hierarchical), flat pod-to-pod, federated services, GitOps link-gen 2.8, 2.14, 2.17, 2.18
Mesh expansion VMs and bare metal through ExternalWorkload and SPIFFE/SPIRE 2.15
Observability Golden metrics (success rate, RPS, latency), tap, OpenTelemetry tracing, near-parity inbound metrics Tracing on OTel 2.17, inbound metrics 2.20
Native sidecars Proxy runs as a restartable init container. This fixes Jobs and startup races. Alpha 2.15, beta 2.19, default 2.20
IPv6 IPv6-only and dual-stack (opt-in) 2.16

Evaluation

Pros Cons
Very small proxy footprint. The vendor benchmark measured about 8x less proxy memory than an Istio 1.10 sidecar (numbers). Sidecar only. There is no sidecar-less mode comparable to Istio ambient.
Rust proxy: memory-safe, no GC pauses No open-source stable or semver artifacts since 2024. OSS users track edge releases.
mTLS on by default, with post-quantum hybrid key exchange BEL features (HAZL, FIPS, Windows, automated trust anchor rotation) need a paid license at 50+ employees
Simple install and upgrade, few knobs Smaller ecosystem and feature surface than Istio. No Wasm or custom filters, no built-in end-user JWT authentication.
Standard Gateway API configuration (first Mesh-profile conformant mesh) Gateway API CRD version must be managed separately (since 2.19)
Circuit breaking, rate limiting and egress control are now built in Rate limiting is local only (no global limiter). Egress policy can be bypassed by workloads that skip the sidecar.
Federated multicluster with transparent failover All maintainers work for one company (Buoyant)
Mature: CNCF Graduated, about ten years of production use Trust anchor and issuer expiry is an operational trap if not automated

When It Fits

  • Teams that want mTLS, golden metrics and good gRPC load balancing with the least operational effort.
  • Clusters where per-pod resource overhead matters and where L7 needs stay within routing, retries, timeouts, circuit breaking and authorization.
  • Multi-cluster estates that want one logical service across clusters (federated services).

When to Look Elsewhere

  • You need sidecar-less operation, Envoy extensibility (Wasm, ext_authz), or JWT authentication at the mesh: see Istio.
  • You only need north-south ingress: see Envoy Gateway.
  • You need a supported, semver-stable build but will not buy BEL: budget for tracking edge releases, or choose another mesh.

Licensing and Pricing

  • Linkerd code: Apache-2.0. Anyone can build and run it. Edge release binaries, images and Helm charts (https://helm.linkerd.io/edge) are free.
  • Buoyant Enterprise for Linkerd (BEL): a stable distribution with backports, support options and enterprise-only features. It needs a license key. According to Buoyant, it is free for production use at companies with fewer than 50 employees (no support included). The list price at launch was reported as US$2,000 per cluster per month (The New Stack, 2024). Check the Buoyant pricing page for current terms.

Ecosystem and Compatibility

  • Kubernetes: 1.31 to 1.35 for 2.20 (full table in Reference). It runs on EKS, GKE (private clusters need firewall rules), AKS, k3s and kind.
  • CNI: works with most CNIs. On Cilium, socket-level load balancing must stay in the host namespace. linkerd-cni chains with the existing CNI.
  • Certificates: cert-manager and trust-manager for issuer rotation. External CAs such as Vault can issue the issuer certificate.
  • Observability: Prometheus metrics on each proxy. OpenTelemetry tracing (see OpenTelemetry).
  • Delivery: Gateway API routes work with Flagger and Argo Rollouts. Declarative multicluster links suit Argo CD GitOps.

Topic Map

  • How-to Guides: install (CLI, Helm, cert-manager), mesh workloads, policy, egress, retries, circuit breaking, multicluster, upgrades, troubleshooting.
  • Reference: versions, compatibility matrices, ports, CRDs, annotations, certificate defaults, benchmark numbers.
  • Explanation: architecture, proxy internals, identity and trust chain, policy model, load balancing, Gateway API migration, multicluster modes, release model.

Sources

Questions

Open

  • Will Linkerd ship a sidecar-less or "ambient-like" mode? The 2.15 announcement said the project is evaluating ambient and other approaches. No design had been published as of 2026-09. See Explanation: Native Sidecars.
  • Is there a current, independent benchmark against Istio ambient mode? Only the 2021 vendor benchmark (sidecar vs sidecar) and LiveWyer 2024 exist. See Reference: benchmarks.
  • When will ServiceProfiles and the SMI extension be removed, rather than frozen or deprecated? See Explanation: Configuration Model.
  • What does BEL cost for companies with 50 or more employees? Buoyant's pricing page (checked 2026-09-28 via search listing) says BEL is free to try and free in production below 50 employees, and its indexed text shows no price for the paid plans.

Answered

  • Is Linkerd lighter than Istio? Yes, for sidecar vs sidecar. The 2021 benchmark (Linkerd 2.10.2 vs Istio 1.10.0) measured a maximum proxy memory of 17.8 MB vs 154.6 MB, and control plane memory of 324 MB vs 837 MB. Istio ambient changes the comparison. See Reference.
  • Does Linkerd have circuit breaking and rate limiting? Yes. Circuit breaking through failure accrual has existed since 2.13. Local rate limiting arrived in 2.17. See Explanation.
  • Is Linkerd still open source after the 2024 change? Yes. The code stays Apache-2.0 under CNCF governance. Only stable release artifacts moved to vendors. Edge releases remain open source. See Explanation: Release Model.