Skip to main content

Get Service Mesh Certified with Buoyant.

Enroll now!
close

Case Studies

How EarnIn transformed its platform security and stability by migrating to Linkerd

The enterprise architect's guide to the service mesh

Download ebook

Linkerd Production Readiness Pre-Launch Checklist

Download Checklist

About EarnIn

EarnIn is a fintech company on a mission to enable financial independence for millions of Americans living paycheck to paycheck. The company provides early access to wages, so customers are able to do things like pay bills on time and buy groceries without exorbitant fees, overdraft charges, or needing to take out additional loans. The company also offers B2B payroll services that enable employees at partner companies to access their earned wages with minimal fees.

EarnIn's commitment to its mission extends beyond its customers. The company has earned multiple awards, like the “Best in Business” Award from Inc.com, reflecting a strong culture focused on employee benefits and satisfaction. This dedication to excellence applies equally to their technical infrastructure, where reliability and security are paramount in the highly regulated fintech industry.

Managing around 15,000 Pods Across 25 EKS Clusters 

EarnIn's platform team manages a complex Kubernetes infrastructure running entirely on AWS across multiple availability zones. The team of approximately 15 engineers oversees:

  • 25 EKS clusters, including:
    • 4 main production environments
    • PCI environments for sensitive card information
    • Platform clusters for CI/CD 
    • Sandbox clusters for testing upgrades and new features
  • Approximately 7,000 pods running across their main application cluster on average
  • Microservices architecture with services primarily written in Kotlin, Python, and .NET
  • GRPC-based services for the majority of their Kotlin applications
  • Multi-tier architecture with traffic flowing from mobile apps through the main application cluster to PCI Cat 2 environments for money movement, and further to PCI environments for card information access

The Need to Replace AWS App Mesh 

Before adopting Linkerd, EarnIn used AWS App Mesh as their service mesh solution. However, App Mesh proved to be problematic on multiple fronts.

  1. Operational Complexity: App Mesh required managing numerous virtual objects before requests could flow from the load balancer to services. This complex chain of virtual objects created a significant operational burden, and the architecture was difficult to maintain and troubleshoot.
  2. Security and Compliance Gaps: As a fintech company handling sensitive financial data, EarnIn needed mTLS enabled by default. App Mesh required significant additional configuration to enforce mTLS consistently across services, creating a critical security gap for a company managing money movement and card information.
  3. Stability and Incidents: The operational model contributed to high-severity incidents, causing business impact and lost revenue whenever the application became unavailable. Each incident required extensive root cause analysis and heavy scrutiny on the platform team.

These challenges with App Mesh led the team to look for other alternatives. Out-of-the-box mTLS, operational simplicity, and the need for application stability weren't nice-to-haves—they were essential requirements for a company responsible for helping millions of Americans access their wages.

Why Linkerd?

Priya Namasivayam led the evaluation project, comparing Istio and Linkerd as potential replacements for App Mesh. Linkerd emerged as the clear winner for several reasons.

1. Simplicity as a Core Value: The team wanted to reduce the time spent managing a service mesh, so choosing a mesh with operational simplicity was key. 

"I wanted to keep the architecture very simple for the team, where they didn’t have to spend a lot of cycles trying to figure out how it all works out together,” said Namasivayam. “If you enable the Linkerd sidecar proxy, it just works. That's the simplicity that I wanted to have."

2. Security by Default: Linkerd provides mTLS out of the box, immediately addressing one of EarnIn's most critical compliance requirements. 

3. Proven Performance: During evaluation, EarnIn was able to eliminate the performance bottlenecks they experienced with App Mesh by evenly distributing GRPC requests across all pods with intelligent load balancing. 

Zero-Downtime Implementation and Migration

The migration from App Mesh to Linkerd took just over a year and was executed with zero downtime. The service migration phase lasted 8–9 months, followed by 3–4 months dedicated to traffic shifting. We executed the migration in two phases — first running App Mesh and Linkerd in parallel while incrementally migrating microservices by enabling Linkerd sidecar injection (linkerd-proxy), and then performing progressive traffic cutover using AWS Load Balancer weighted routing to safely transition all internal and external traffic without disruption."The migration path was very easy for us. We didn’t have to do any magic to get it working. That's a huge win,” said Namasivayam.

Achieving Security and Stability while Saving Costs

Despite the scale and complexity of the migration, the EarnIn team was quickly able to benefit from switching to Buoyant Enterprise for Linkerd. 

mTLS Enabled Across the Platform: With mTLS working out of the box, EarnIn achieved a fundamental security requirement without additional configuration or management overhead. Service-to-service communication is secured by default through mesh-enforced mTLS.

Authorization Policies: Building on Linkerd's authorization policy capabilities, EarnIn implemented service-to-service access controls. Services can only communicate when explicitly whitelisted, following the principle of least privilege. 

Reduced Operational Burden: The simplicity of Linkerd's architecture meant the team could troubleshoot issues more quickly and spend less time managing the service mesh itself. Team members no longer needed deep expertise in complex virtual object chains to maintain the system.

Hot Pod Problem Solved: The GRPC load balancing issues that plagued their Kotlin services were completely resolved. Requests are now evenly distributed across all pod replicas, enabling efficient resource utilization.

Increased Reliability: EarnIn deployed Linkerd's High Availability Zonal Load Balancing (HAZL) feature to optimize traffic across their multi-availability zone deployment. HAZL automatically manages pod placement and traffic routing across availability zones without manual intervention, ensuring workloads remain available even during AZ outages while minimizing cross-AZ traffic and latency impact. By implementing HAZL, EarnIn has also been able to save money on AWS cloud spend.

Fulfilling its Mission with Linkerd

For a company whose mission is enabling financial independence for millions of Americans, having a stable, secure platform isn't just a technical requirement—it's essential to fulfilling that mission. EarnIn's migration from AWS App Mesh to Buoyant Enterprise for Linkerd demonstrates how choosing the right service mesh can transform operational outcomes for fintech companies by increasing reliability and security.

‍

Interested in what Buoyant Enterprise for Linkerd can do for your team? Contact us to learn more.