What Linkerd Is and Why It Avoids Envoy
Linkerd sits on top of Kubernetes but underneath your application, handling service-to-service networking. It was the fifth project to join the CNCF, which created a new “inception” category for it. The project is now 10 years old. Instead of Envoy, Linkerd uses microproxies written in Rust. They handle a small fraction of what Envoy does, which keeps them small and predictable. The team adopted Rust in 2018 and funded early work on libraries like Tokyo, Tower, and H2 to get the ecosystem production-ready.
Linkerd’s Funding Model: Buoyant Pays Full-Time Maintainers
Every Linkerd maintainer has a full-time job maintaining Linkerd. Buoyant, the company Morgan runs, funds that work by selling an enterprise version of the project. Morgan is explicit about this rather than hiding the vendor relationship. The project is not dependent on VC funding or on large players staying interested in service mesh. Morgan’s stated goal is to keep this model running for 100 years, and the economic engine is what he believes makes that possible.
Three Recent Changes: Post-Quantum TLS, Protocol Declarations, GitOps Multicluster
Linkerd updated its default TLS libraries from Ring to AWS-LC, making them post-quantum ready, with cipher suite and key exchange data now visible in metrics. Protocol declarations let operators set the appProtocol field on services so Linkerd skips protocol detection entirely. That matters under load, where the 10-second detection timeout can fire even for normal HTTP traffic. Multicluster linking now works declaratively through GitOps, which fits teams managing hundreds of clusters rather than the two-cluster case the original design targeted.
Generative AI: Not Inside Linkerd, But Affecting Platform Owners
Linkerd will not embed generative AI. Generative AI is not fast, lightweight, or predictable, and those three properties are non-negotiable for a proxy. What has changed is the workload arriving at the platform. Developers using AI tools produce more deploys, CI/CD pipelines are under more pressure, and agentic workloads running in production can behave unpredictably. The core platform requirements, reliability, security, and observability, remain the same. The surface area for satisfying them has grown.
MCP Prototype: Tool-Call Metrics and Policy in the Proxy
At KubeCon Atlanta, the team demonstrated MCP protocol parsing added directly to Linkerd’s proxies. The prototype exposes latency, success rates, and error rates per tool call, and provides a catalog of all MCP traffic in the cluster. Policy controls let operators allow or block specific tool calls per client. A separate experiment looks at an MCP gateway, handling either ingress or egress MCP traffic, and potentially routing between models. Both are still in prototype phase, and Morgan asked anyone with production MCP workloads to contact the team.
Q&A
Is MCP protocol support as hard to build as async Rust networking was in 2018? The surface area of MCP is much smaller; at the protocol level it is JSON-RPC, so parsing it was manageable. ▶ 26:08
Is Windows support available? Windows support exists but is behind a paywall in the Buoyant enterprise offering. ▶ 26:56
Notable Quotes
linking needs to be fast. It needs to be lightweight. It needs to be predictable. And generative AI is is many things, but it’s not any of those things. So, we’re not going to add AI to linkerty. William Morgan · ▶ 19:49
we’re not at the mercy of VC funding we’re not at the mercy of you know uh kind of big players deciding that link that service mesh is cool and then you know being uninterested and and funding dries up we are a self- sustaining uh project William Morgan · ▶ 10:24
it’s JSON RPC and like plus some weird stuff plus you have to manage state for some reason that makes no sense. William Morgan · ▶ 26:31
do we have like you know all this sketchy vibecoded software hitting our production environment and like we can’t trust it anymore. William Morgan · ▶ 21:52
Key Takeaways
- Linkerd dropped Envoy in favor of small Rust microproxies; the project is 10 years old and CNCF-graduated.
- Protocol declarations remove non-deterministic 10-second detection timeouts under high load.
- MCP proxy parsing is prototype-stage, exposing per-tool-call metrics and allow/deny policy controls.
About the Speaker(s)
William Morgan is the co-founder and CEO of Buoyant, the company that created Linkerd. Before Buoyant, he was an infrastructure engineer at Twitter, where he worked on moving Twitter from a monolithic Ruby on Rails application to a distributed, fault-tolerant architecture.