Skip to main content

Free O’Reilly Book | Linkerd: Up & Running

Download
close
Linkerd just works

Buoyant Enterprise for Linkerd

Free your engineers from failed encryption audits, availability sacrificed for cross-AZ costs, and operational complexity. Buoyant ensures provable compliance, lower costs, and resiliency for gRPC workloads, with zero code changes or new headcount.

Encrypt all meshed pods and rotate trust anchors

mTLS, FIPS 140-2 & 140-3 validated for FedRAMP

Surface real-time audit data for compliance

SBOM, SLSA, CVE Remediation, OSCAL API

Balance cross-AZ cloud availability and costs

L7-aware high-availability load balancing

Ensure lowest latency on gRPC-based workloads

AI inference, edge-to-cloud, telemetry ingestion etc.

Why your cross-zone bill is so high?

Cloud providers bill for traffic that crosses an availability-zone boundary, charged in each direction. Kubernetes spreads traffic as evenly as it can across pods, so in a typical 3-zone cluster about two-thirds of your traffic crosses a zone boundary and gets billed for it.

$100K–$1M+

Annual cross-zone charges at 1 GB/s on AWS (high-traffic cluster)

≈ 0

Cross-zone cost on Azure — in-zone routing highest-value on AWS & GCP

Where Buoyant Enterprise goes beyond open source Linkerd

Buoyant Enterprise for Linkerd
Open Source Linkerd

Enterprise Operations

Release model
Install, upgrade, and rollback
High-Availability-Zone Load Balancing (HAZL)
Windows Container Support
Windows Nodes Support
External Workload Automation
SemVer Stable releases
Automated
Available
Available
Available
Available
Edge releases
Not available
Not available
Not available
Not available
Not available

Zero-trust Security & Compliance

FIPS-validated builds (140-2 and 140-3)
Software Bill of Materials (SBOM)
Supply-chain Levels for Software Artifacts (SLSA)
Automatic Trust Anchor Rotation
Authorization Policy
Available
Available
Available
Available
Generated from live traffic
Not available (Standard imgs.)
Not available
Not available
Manual
Manual

Deep L7-aware Monitoring & Notifications

Standard in-cluster Dashboard (Incl. FIPS reporting)
Advanced multi-cluster Dashboard (metrics, topology, traffic etc.)
Comprehensive library of customizable alerts
Integrations with PagerDuty, Datadog, Slack and more
Available
Available
Available
Available
Not available
Not available
Not available
Not available

Support & Services

Ticketing Portal
Designated CS Manager
30-day Onboarding Service
Support SLAs
CVE Remediation
24x7 On-call
Available
Available
Available
Supported with SLAs
Not available (Slack via only)
Not available
Not available
Not available
Community-paced
BEL
OSS

Enterprise Operations

Release model
Install, upgrade, and rollback
High-Availability-Zone Load Balancing (HAZL)
Windows Container Support
Windows Nodes Support
External Workload Automation
SemVer Stable releases
Automated
Available
Available
Available
Available
Edge releases
Not available
Not available
Not available
Not available
Not available

Zero-trust Security & Compliance

FIPS-validated builds (140-2 and 140-3)
Software Bill of Materials (SBOM)
Supply-chain Levels for Software Artifacts (SLSA)
Automatic Trust Anchor Rotation
Authorization Policy
Available
Available
Available
Available
Generated from live traffic
(Standard imgs.)
Not available
Not available
Manual
Manual

Deep L7-aware Monitoring & Notifications

Standard in-cluster Dashboard (Incl. FIPS reporting)
Advanced multi-cluster Dashboard (metrics, topology, traffic etc.)
Comprehensive library of customizable alerts
Integrations with PagerDuty, Datadog, Slack and more
Available
Available
Available
Available
Not available
Not available
Not available
Not available

Support & Services

Ticketing Portal
Designated CS Manager
30-day Onboarding Service
Support SLAs
CVE Remediation
24x7 On-call
Available
Available
Available
Supported with SLAs
Not available (Slack only)
Not available
Not available
Not available
Community-paced

Zero-config encryption modules with real-time auditing tools

BEL encrypts all data-in-transit between meshed pods with mTLS and FIPS-validated cryptographic libraries (FedRAMP) with ZERO application code changes. For compliance & auditing, Buoyant includes:

  • Real-time FIPS Dashboard and a OSCAL-based API
  • Distributions with verifiable SLSA and continuous SBOM
  • CVE remediation SLAs
  • Automated trust anchor rotation
bel-dashboard-fips-2

Unblock gRPC workloads with zero-config, ultra-low latency balancing

If your microservices or AI workloads rely on high-throughput gRPC streams, Buoyant's Rust micro-proxy is the only solution that offers:

  • Ultra-low latency performance (see graph)
  • Per-request load balancing with L7 and rate-limit awareness
  • Advanced traffic management (retries, timeouts & more)
  • HAZL to balance GPU/CPU utilization for reliability & cost
gRPC load balancing benchmarks summary

If your microservices or AI workloads rely on high-throughput gRPC streams, Buoyant's Rust micro-proxy is the only solution that offers ultra-low latency performance and load balancing with L7 per-request and rate-limit awareness. BEL's advanced traffic management capabilities (retries, timeouts and more) and HAZL also ensures balanced GPU/CPU utilization for cost efficiency while delivering incredible performance & reliability.

gRPC latency with all pods healthy (baseline)

Access deep L7 multicluster observability with configurable alerts

Unique to BEL, is the deployment of its ultra-light micro-proxy at Layer 7 which enables it to accurately measure success rates, latency and request volume without application code changes. With BEL, you can access:

  • Deep in-cluster or multicluster analytics with topology mapping
  • Real-time metrics, coverage, and compliance status
  • Library of configurable alerts
  • Integrations with PagerDuty, Slack, Teams etc.
bcloud-topo-view-2

Save up to 60% cross-zone network costs with true L7-aware load balancing

Unlike rigid standard routing that forces you to choose between reliability and costs for multi-AZ workloads, BEL's L7 awareness allows cost efficiency and high availability to coexist.

  • In-zone by default for max cost savings
  • Intelligent routing under load/failure (EWMA-based)
  • In-band health checking (HTTP/gRPC)
  • Maintains near 100% success with no tuning by default
Provider
AWS
$0.02/GB
GCP
$0.01/GB
No. of Kubernetes clusters
Availability zones per cluster
Cross-zone traffic volume
select a provider

Select a provider to see your savings.

Without HAZL
per year
With HAZL
60% less
Savings
per year

If your microservices or AI workloads rely on high-throughput gRPC streams, Buoyant's Rust micro-proxy is the only solution that offers ultra-low latency performance and load balancing with L7 per-request and rate-limit awareness. BEL's advanced traffic management capabilities (retries, timeouts and more) and HAZL also ensures balanced GPU/CPU utilization for cost efficiency while delivering incredible performance & reliability.

gRPC latency with all pods healthy (baseline)

Support from the team that created Linkerd

Linkerd is our project. Open a support ticket and it directly reaches the team that maintains it. Every enterprise plan includes a private ticketing portal, 24x7 on-call and a named customer success manager.

✓ Public forums
✓ Documentation
✓ Courses and workshops (Service Mesh Academy)

✓ Private ticketing portal
✓ 24x7 on-call
✓ CVE remediation with SLAs

✓ Designated CS manager
✓ 30-day onboarding
✓ Architecture review on request

Frequently asked questions

How much time and resources does it take to implement BEL?

A typical implementation can be completed in days. Every enterprise plan includes 30-day onboarding support to guide your team and BEL automates all of the ongoing maintenance (installs, upgrades, rollbacks and trust anchor rotation) to eliminate resource overheads over the long term.

How does Buoyant support our audit team or FedRAMP timeline?

The FIPS dashboard reports status per meshed edge to easily track which traffic used FIPS validated modules. You can also generate System Security Plan documentation in OSCAL format along with cryptographically signed attestations of every build, test, scan, and deployment.

Can Buoyant Enterprise for Linkerd support workloads outside Kubernetes?

Yes. BEL supports automated management of non-Kubernetes workloads (VMs, bare metal etc.) with minimum configuration through a feature called mesh expansion. In v2.20, BEL added support for Windows VMs.

Can cross-zone cost savings put our availability at risk?

No. Buoyant's High Availability Load Balancing (HAZL) keeps traffic in-zone while local endpoints have healthy capacity. Due to L7 awareness, the moment there is saturation or failure, HAZL can immediately and confidently spread the load without the need of guessing thresholds.

What does it cost?

Buoyant Enterprise for Linkerd is free to try in non-production for companies of all sizes. However, to run in production with access to our most powerful features & support, we recommend an enterprise license, tailored to your needs. Contact sales for more information.

What it covers, and what it doesn't

Linkerd always provides the golden metrics, and as of 2.20, Linkerd exports distributed tracing spans to OpenTelemetry. You'll still need to pair the mesh with your tracing and APM stack.

Without Buoyant Enterprise for Linkerd

✗  Full APM or application profiling

✗  Long-term metrics storage

✗  Grafana (not bundled since 2.12)

✗  Trust-anchor rotation automation on OSS / pre-2.20

✓  Success rate, RPS, and latency percentiles, every service

✓  Proxy cert auto-rotation (24 h)

✓  Support for cert-manager issuer rotation

✓  Community support

With Buoyant Enterprise for Linkerd

✓  Success rate, RPS, and latency percentiles, every service

✓  Per-service and per-route visibility

✓  Distributed tracing → OpenTelemetry (2.20)

✓  Proxy cert auto-rotation every 24 h

✓  Lifecycle automation

✓  Trust anchor rotation automation (2.20)

✓  Continuous security vulnerability scanning

✓  Dedicated enterprise support