linkerd/linkerd
46.6
Weak · 22 September 2026
36.5k
lines of production code
Scala
with JavaScript
4
measurements over time
What this system is
This system is a service mesh infrastructure that provides dynamic service discovery, routing, and protocol translation for distributed applications. It manages name resolution across diverse backends like Kubernetes, Consul, and ZooKeeper, while offering a centralized delegation service (Namerd) to configure routing rules. The platform supports multiple protocols including HTTP/2, gRPC, and Thrift, with built-in observability for metrics, tracing, and logging.
How it got here
2016 — Namerd and protocol expansion
100 changes.
This period focused on introducing Namerd as a dedicated service for managing name delegation and configuration, alongside a major expansion of supported protocols including Thrift, HTTP/2, and Consul. The team also overhauled the admin interface, refactored the internal configuration and initialization architecture, and added extensive test coverage for these new features.
2017 — HTTP/2 and gRPC protocol support
60 changes.
This period focused on implementing full HTTP/2 and gRPC protocol support within Finagle and Linkerd, including Netty4-based transports, response classification, and failure accrual. The work also expanded the admin dashboard with service-oriented views and introduced new telemetry providers for StatsD, InfluxDB, and Prometheus.
2018–2020 — Service discovery and admin interface expansion
8 changes.
This period focused on expanding service discovery capabilities by adding support for Rancher, Marathon, and Consul backends, alongside a new gRPC-based destination interface. The admin interface was enhanced to expose internal namer state and delegate configurations, while error messaging and test coverage were improved for better diagnostics and security.
Features
Add Apache Curator namer for ZooKeeper-based service discovery
Users can now configure a namer that resolves service instances from an Apache ZooKeeper cluster using the Curator library. This adds support for discovering services registered in ZooKeeper, with automatic SSL port detection and metadata propagation. The change includes the CuratorNamer implementation, its service initializer registration, and associated unit tests.
namer/curator · high confidence
Add Consul-backed interpreter
Users can now use Consul as a service discovery backend. A new Consul interpreter has been added to Linkerd, enabling the system to interpret Consul-based routing configurations. This includes the registration of the Consul interpreter initializer and corresponding test coverage to ensure correct parsing of Consul host, port, and namespace settings.
interpreter/consul · medium confidence
Add DC/OS bootstrap utility for initializing Namerd storage
A new DcosBootstrap application is introduced to handle the initial setup of Namerd's ZooKeeper-based storage. This utility reads a configuration file, extracts ZooKeeper connection details, and creates a default namespace with a pre-defined dtab. It serves as a bootstrap tool to ensure the required storage paths and data are present before the main Namerd service starts.
namerd/dcos-bootstrap/src/main/scala/io · high confidence
Add DNS SRV record name resolution capability
Users can now resolve service addresses via DNS SRV records. This change introduces the DnsSrvNamer, which supports configuration of refresh intervals and DNS host lists, and registers itself as a service provider for the naming system.
namer/dnssrv · high confidence
Add H2Instances to provide header and request type classes for HTTP/2
A new file, H2Instances.scala, was added to the router/h2 module. This introduces implicit instances (HeadersLike and RequestLike) that enable the router to handle HTTP/2 headers and requests, allowing the router to process and inspect HTTP/2 specific header data.
router/h2/src/main/scala/io/buoyant/router · high confidence
Add InfluxDB telemetry support
A new InfluxDB telemeter is introduced, exposing metrics in the InfluxDB line protocol format via the /admin/metrics/influxdb admin endpoint. The implementation maps the internal MetricsTree to InfluxDB-friendly fields and tags, including special handling for root-level metrics and common routing/server/client labels.
telemetry/influxdb/src/main, telemetry/zipkin · high confidence
Add Istio and Google RPC/Protobuf schema definitions
The \istio-proto\ module now includes the core Protocol Buffer definitions for Istio Mixer and Google RPC. This adds the \mixer/v1\ service contracts (including \check\, \quota\, and \attributes\ messages) alongside the necessary Google \protobuf\ and \rpc\ schema files (such as \status.proto\ and \error\_details.proto\). These files provide the foundational data structures and API contracts required for Mixer client-server communication and error handling.
istio-proto · high confidence
Add Istio integration for request routing and authorization
Introduces new components to support Istio service mesh integration, including an \IstioNamer\ for service discovery via the Istio Pilot API, an \IstioRequestAuthorizerFilter\ to enforce Mixer preconditions, and \IngresssTrafficIdentifier\/\InternalTrafficIdentifier\ to route traffic based on Istio VirtualService and DestinationRule configurations. The change also adds helper classes for parsing Istio paths and reporting metrics to Mixer.
istio/src/main · high confidence
Add JSON serialization support for mesh interpreter types
The mesh interpreter now supports JSON serialization for internal types including BoundNameTree, Endpoint, and Path. This is enabled by new ConfigSerializer implementations (BoundNameTreeSerializer, EndpointSerializer, PathSerializer) and a StreamState class for tracking gRPC stream metadata, allowing these structures to be serialized to JSON.
interpreter/mesh/src/main · high confidence
Add Kubernetes and Namespaced Kubernetes Namers
Users can now resolve Kubernetes service names directly through the namer. This change registers three new namer initializers—K8sExternal, K8s, and K8sNamespaced—allowing the system to interact with Kubernetes resources using standard Kubernetes naming conventions.
namer/k8s/src/main · high confidence
Add Kubernetes third-party store for Dtabs
Namerd can now store Dtab configurations in a Kubernetes cluster using the Kubernetes third-party API. This introduces a new \K8sDtabStore\ implementation that persists Dtabs as Kubernetes resources, enabling dynamic updates via Kubernetes watch streams. The change includes the necessary Scala classes, service provider files, and configuration tests to support this storage backend.
namerd/storage/k8s · high confidence
Add Prometheus Telemeter for Metrics Export
A new Prometheus telemeter has been introduced to the telemetry system, allowing users to export metrics in the Prometheus exposition format via an admin endpoint. The implementation supports configurable paths and metric prefixes, handles histogram snapshots for stat metrics, and includes proper escaping for metric labels and keys. Tests confirm that counters, gauges, and stat summaries (including quantiles) are correctly formatted and that exception/failure metrics are properly labeled.
telemetry/prometheus · high confidence
Add Rancher service discovery namer
Introduces a new namer for Rancher, enabling the system to resolve service addresses by querying the Rancher API. The implementation includes the core namer logic in \RancherNamer.scala\, which parses configuration (such as port mappings) and performs lookups based on stack and service names. A service initializer (\RancherInitializer\) is registered to make the namer available, and tests confirm correct parsing of Rancher container responses and configuration.
namer/rancher · high confidence
Add StatsD telemetry implementation
Introduces a new StatsD-based telemetry provider, adding \StatsDTelemeter\, \StatsDStatsReceiver\, and \Metric\ classes to export counters, gauges, and stats to a StatsD endpoint. The module is registered via a new \TelemeterInitializer\ service file, enabling users to configure StatsD as their metrics backend.
telemetry/statsd/src/main · high confidence
Add TLS certificate and key files for namerd
Added example certificate files (namerd-cacert.pem, namerd-cert.pem, namerd-key.pk8, namerd-cakey.pk8) to the examples/certs directory, providing the necessary keys and certificates to enable TLS-secured communication for the namerd namer interface.
namerd/examples/certs · high confidence
Add TTwitter Thrift routing support
The Thrift protocol module now supports TTwitter routing, enabling Linkerd to intercept and route Thrift requests using a custom client and server filter chain. This change introduces new Scala components (TTwitterClientFilter, TTwitterServerFilter, and related preparation modules) that handle protocol upgrades, trace ID propagation, and context passing for Thrift traffic, allowing Linkerd to manage TTwitter-based services.
linkerd/protocol/thrift/src/main · high confidence
Add Thrift IDL for PingService
A new Thrift IDL file (ping.thrift) was added to the router/thrift-idl module, defining a PingService with a ping method that accepts and returns a string message. This establishes the interface for a simple ping/pong interaction, likely intended for end-to-end testing as suggested by the commit message.
router/thrift-idl · high confidence
Add Thrift interface serializers and observer caching for namerd
The namerd Thrift interface now includes new JSON serializers for address and binding requests and responses, enabling proper serialization of these types over the API. Additionally, an ObserverCache with active/inactive caching and TTL-based eviction has been introduced to manage observer lifecycle and prevent resource leaks by closing inactive observers.
namerd/iface/interpreter-thrift/src/main · high confidence
Add Tracelog Telemeter for Trace Logging
A new 'io.l5d.tracelog' telemeter is introduced, enabling trace logging capabilities. The implementation includes a new TelemeterInitializer and associated tests that verify configuration parsing, including the acceptance of integer values for the 'sampleRate' parameter and support for log levels such as 'trace'.
telemetry/tracelog · high confidence
Add ZooKeeper-based DtabStore implementation for Namerd
Users can now store and manage name delegation tables (dtabs) in Apache ZooKeeper. This change introduces a new \ZkDtabStore\ implementation that persists dtabs as UTF-8 encoded nodes under a configurable ZooKeeper prefix, supporting create, update, delete, and observe operations with appropriate ACL handling and session management.
namerd/storage/zk · high confidence
Add ZooKeeper-based leader election namer
Introduces a new ZooKeeper-based leader election namer that resolves to the addresses stored in the data of the elected leader. The namer accepts paths in the form /\<zkHosts\>/\<zkPath\>, where zkHosts is a list of ZooKeeper host:port pairs delimited by ::. This includes the Scala implementation, Java interfaces for leader candidacy, and service registration to enable the feature.
namer/zk-leader · high confidence
Add admin endpoints to expose bound names and delegate configuration
New HTTP handlers have been added to the admin interface to expose internal namer state. The BoundNamesHandler now exposes a JSON list of all currently bound names, allowing users to inspect active name resolutions. Additionally, the new DelegateHandler provides a web UI for viewing and managing DNS-based routing (dtab) configurations, including a timeout state for failed requests. These changes make internal namer state and delegate routing information accessible via the admin API.
admin/names · high confidence
Add assets for Twitter Server admin endpoints
The \jquery-ui.min.js\ file is added to the admin resources, providing the necessary JavaScript assets for the Twitter Server admin endpoints.
admin/src/main/resources/io/buoyant/admin/twitter-server · high confidence
Add configurable gRPC response classifiers for HTTP/2
Introduces a new gRPC response classifier for HTTP/2 streams, enabling users to control how gRPC status codes and HTTP/2 errors are classified as retryable or non-retryable failures. The change adds a \GrpcClassifier\ implementation that parses gRPC status codes from HTTP/2 trailers and provides several pre-configured strategies: \Default\ (marks \Unavailable\ as retryable), \Compliant\ (adheres to gRPC HTTP/2 standards by marking specific HTTP 429/502/503/504 and \REFUSED\_STREAM\ as retryable), \AlwaysRetryable\, \NeverRetryable\, and a custom \RetryableStatusCodes\ option. These classifiers are registered via \ResponseClassifierInitializer\ with config IDs such as \io.l5d.h2.grpc.default\ and \io.l5d.h2.grpc.compliant\.
linkerd/protocol/h2/src/main/scala/io/buoyant/linkerd/protocol/h2/grpc · high confidence
Add etcd client and integration tests
Introduces a new \io.buoyant.etcd\ package providing an asynchronous Etcd client built on Finagle-HTTP, including support for key operations and a \watch\ utility that models a key's state as a \com.twitter.util.Activity\. This change adds the client implementation, integration tests that boot a local etcd instance, and unit tests for key operations like create, delete, and watch.
etcd · high confidence
Add etcd-backed Dtab storage
Users can now store and manage dtab namespaces using an etcd backend. This introduces the EtcdDtabStore implementation, which supports creating, updating, and deleting dtab entries with versioning and conflict detection. The configuration allows specifying the etcd host, port, path prefix, and TLS settings for secure communication with the etcd cluster.
namerd/storage/etcd · high confidence
Add example configuration files for Linkerd services
New example configuration files have been added for Linkerd, including 'cat', 'dog', 'default', and 'thrift' entries. These files define service configurations, such as the 'thrift' file which maps to port 9991, supporting the introduction of Thriftmux and service management features.
linkerd/examples/io.l5d.fs · medium confidence
Add experimental ThriftMux protocol support
Users can now configure routers to use the ThriftMux protocol, which supports both client and server-side settings for framing and protocol selection (e.g., TCompactProtocol). The change introduces a new protocol initializer and associated server preparation logic, enabling per-client configuration for ThriftMux-based services.
linkerd/protocol/thriftmux · medium confidence
Add filesystem-based name interpreter
Users can now use a filesystem-based name interpreter, which allows configuration of a dtab file path via the 'io.l5d.fs' config ID. This new capability is registered via the standard Java SPI mechanism (META-INF/services) and includes tests to verify the registration and configuration parsing.
interpreter/fs · high confidence
Add filesystem-based service discovery namer
Users can now configure a 'fs' namer that discovers services by reading files in a specified directory. The implementation includes a new \FsInitializer\ and \UpRegSerializer\ to handle configuration and serialization, and supports weighted addresses in the discovered service files. Tests confirm that the namer correctly parses configuration, binds to the root directory, and respects address weights.
namer/fs · high confidence
Add gRPC interop test service and client implementations
Added protobuf definitions (empty.proto, messages.proto, test.proto) and Scala implementations (Client.scala, Server.scala) for the gRPC interop test suite. This introduces the standard test service definitions and client/server logic required to run interop tests against a gRPC endpoint.
grpc/interop/src/main · high confidence
Add io.l5d.destination interface for Linkerd2 service discovery
Introduces a new \io.l5d.destination\ interface that exposes a gRPC service for service discovery, allowing clients to subscribe to updates about endpoints. The implementation includes the \Destination\ service definition and \net.proto\ types, with the server listening on localhost port 8086 by default. The interface supports configuring socket options (e.g., \noDelay\, \reuseAddr\, \reusePort\) and handles updates for new endpoints, removed endpoints, and cases where no endpoints exist.
namerd/iface/destination · high confidence
Add localhost and port transformers for address manipulation
Users can now configure transformers to modify address properties. A new LocalhostTransformer allows routing traffic to all local network interfaces, while a new PortTransformer enables rewriting destination ports to a fixed value, supporting scenarios where a local reverse-proxy handles traffic on a specific port.
interpreter/per-host/src/main/scala · high confidence
Add protobuf definitions for gRPC examples
Added new protobuf schema files (base.proto and eg.proto) that define the message types, enums, and service definitions used in the gRPC examples. This includes the base Unit and Exception messages, as well as the core Eg messages (Seq, Map, Option, etc.), the Enumeration types, and the Eggman service with its RPC methods.
grpc/eg/src/main · high confidence
Add recent requests telemetry
A new 'Recent Requests' telemetry module has been added, providing a dashboard view of recent network requests. This includes a new Telemeter implementation that registers an admin handler at /requests and adds a corresponding navigation item, allowing users to view a table of recent requests with details like timestamp, source, server, router, and destination.
telemetry/recent-requests · high confidence
Add subnet-based address filtering and gateway selection
The system now supports filtering and routing traffic based on network subnets. A new \SubnetLocalTransformer\ allows routing to only addresses on the same subnet as a specified local IP, while \SubnetGatewayTransformer\ and \MetadataGatewayTransformer\ enable selecting gateway addresses that share a subnet or metadata field with the original address. These changes introduce netmask-based transformers that filter bound names to only include addresses within the same subnet, improving network isolation and locality-aware routing.
interpreter/subnet · medium confidence
Added H2 Classified Failure Accrual
Introduced H2FailureAccrualFactory, a new component that applies failure accrual logic specifically for HTTP/2 connections. This allows the router to track and react to failures on a per-connection basis, improving resilience by marking dead endpoints and probing for recovery.
router/h2/src/main/scala/com · high confidence
Added HTTP/2 stream buffering benchmarks
A new JMH benchmark suite was added to the Finagle benchmarking module, introducing performance tests for HTTP/2 stream operations. The suite includes a baseline stream test, a buffered stream test, and a fanout test that measures the performance of forking multiple streams from a single buffered stream, allowing users to evaluate the overhead of stream buffering and fanout operations.
finagle/benchmark · high confidence
Added Istio interpreter for Kubernetes service discovery
The Istio interpreter has been moved to its own module, introducing a new \IstioInterpreter\ component that maps Kubernetes service routes to Finagle name trees. This change includes the core implementation in \IstioInterpreter.scala\, a service initializer registration, and corresponding unit tests in \IstioInterpreterTest.scala\.
interpreter/istio · high confidence
Added MaxCallDepthFilter to prevent infinite request loops
A new MaxCallDepthFilter has been introduced in the HTTP router base to terminate requests that exceed a configurable maximum call depth, protecting against potential proxy loops. The implementation includes a new HeadersLike type class for header abstraction and a corresponding test suite verifying that requests exceeding the hop limit are rejected with a MaxCallDepthExceeded error.
router/base-http · high confidence
Added Thrift-specific routing and tracing capabilities
The router/thrift module now includes new components to support Thrift protocol routing and observability. A new Dest object provides thread-local storage for the current request's destination path, enabling downstream components to access routing context. A TracingFilter has been added to automatically record RPC method names in trace spans for Thrift client requests. Additionally, the Identifier logic has been updated to support an optional 'method in destination' mode, allowing the router to include the Thrift method name in the resolved destination path, which is verified by new tests in IdentifierTest.
router/thrift · medium confidence
Added ZkClient for recursive path creation in DC/OS bootstrapping
A new ZkClient implementation has been added to support DC/OS bootstrapping, providing functionality to recursively create ZooKeeper paths and manage persistent nodes with automatic session handling.
namerd/dcos-bootstrap/src/main/scala/com · high confidence
Added ZooKeeper leader election implementation
Added CandidateImpl, a new class that implements leader election for small groups of candidates using Apache ZooKeeper. This implementation manages group membership, tracks the current leader, and notifies candidates when they are elected or defeated.
. · high confidence
Added default discovery service configuration example
A new example file has been added to the namerd examples directory, providing a default configuration for a discovery service. The file specifies a local address (127.0.0.1) and port (9990) for the service, serving as a reference for how to configure namerd with a standard discovery endpoint.
namerd/examples/disco · high confidence
Added diagnostics state tracking for Marathon v2 API calls
A new WatchState class has been introduced to track the state of Marathon v2 API interactions. This component records HTTP request details and response data, along with timestamps for the last request and response, providing a mechanism for diagnostics and state monitoring within the Marathon integration.
marathon/src/main · high confidence
Added in-memory Dtab store implementation
An in-memory implementation of the DtabStore interface has been added to namerd, allowing users to store name delegation data in memory rather than a persistent backend. This includes the core InMemoryDtabStore class and its service initializer, enabling quick, non-persistent testing or development environments where state is lost on restart.
namerd/storage/in-memory/src/main · high confidence
Added per-host name transformers
The service loader configuration for io.buoyant.namer.TransformerInitializer has been updated to include three new transformer initializers: LocalhostTransformerInitializer, PortTransformerInitializer, and SpecificHostTransformerInitializer. This enables the system to apply specific host-based name transformations.
interpreter/per-host/src/main/resources · high confidence
Added usage reporting protocol buffer definitions
A new protobuf definition (usage.proto) was added to define the structure for usage telemetry data. This introduces message types for tracking router configurations, counters, and gauges, enabling the system to collect and report usage statistics such as protocol types, interpreter details, and operating system information.
linkerd/core/src/main/protobuf · low confidence
Expanded Linkerd configuration examples for service mesh, observability, and protocol support
The \linkerd/examples\ directory has been significantly overhauled to provide comprehensive, ready-to-use configuration templates for a wide range of Linkerd capabilities. New and updated YAML files now cover HTTP/2 routing, mutual TLS, and various service discovery backends including Consul, Kubernetes, ZooKeeper (Curator and Serversets), and the filesystem. The examples also demonstrate advanced client-side features such as configurable load balancing, socket options, and retry policies. For observability, the examples now include configurations for exporting metrics to StatsD, Prometheus, and InfluxDB, as well as tracing via Zipkin and console logs. Additionally, the directory now contains a Scala test suite (\ExamplesTest.scala\) that validates all example configurations for correctness.
linkerd/examples · high confidence
Initial definition of the namerd Namer and Delegation Thrift interfaces
This change introduces the Thrift IDL for the namerd service, defining the Namer and Delegation interfaces. The Namer interface enables name resolution, returning a BoundTree that includes support for weighted nodes (WeightedNodeId) and alternative paths. The Delegation interface allows clients to query the delegation tree, which includes support for transformations and weighted children. Additionally, the Dtab interface is defined for managing name translation tables.
namerd/iface/interpreter-thrift-idl · high confidence
Introduce Consul as a storage backend for Namerd
Users can now store and manage dtab configurations in a Consul cluster. This change adds a new \ConsulDtabStore\ implementation that supports configuring the Consul host, port, token, and datacenter. It also allows setting read and write consistency modes (e.g., stale or consistent) and enables TLS encryption with client authentication (certificates and keys) for secure communication with the Consul backend.
namerd/storage/consul · high confidence
Introduce Consul client configuration and health status handling
Adds support for configuring the Consul HTTP client with authentication tokens and host headers, and introduces a HealthStatus enumeration to represent and serialize/deserialize Consul health states (passing, warning, critical, maintenance). The change also adds instrumentation for Consul API calls, allowing the system to track request/response metadata for monitoring purposes.
consul/src/main/scala · high confidence
Introduce Consul namer implementation
Added a new Consul namer that supports configurable consistency modes, service address preferences, node tag weights, and metadata transfer, while exposing namer state via an admin handler for monitoring.
namer/consul/src/main/scala · high confidence
Introduce HTTP/2 (H2) router support
Adds new filters to the H2 router stack, including \ClassifiedRetryFilter\ for stream-based retry logic, \ClassifierFilter\ to set success-class headers, \DupRequest\ to duplicate requests, \H2AddForwardedHeader\ to inject the Forwarded header, and \ProxyRewriteFilter\ to handle proxy requests. These components enable HTTP/2 stream classification, metrics, and retry capabilities within the router.
router/h2/src/main/scala/io/buoyant/router/h2 · high confidence
Introduce HTTP/2 protocol support in Finagle
Adds a new HTTP/2 implementation to Finagle, including core components such as the H2 transport, stream handling, connection header validation, and tracing filters. This enables clients and servers to communicate using the HTTP/2 protocol, supporting features like header validation, stream multiplexing, and distributed tracing for HTTP/2 requests.
finagle/h2/src/main/scala/com/twitter/finagle/buoyant/h2 · high confidence
Introduce JavaScript tooling and test infrastructure for the admin UI
The admin UI now includes a full JavaScript development and testing environment. An ESLint configuration (.eslintrc.json) and ignore list (.eslintignore) are added to enforce code quality, while a Karma configuration (karma.conf.js) and test runner setup enable running Jasmine-based unit tests. The README documents how to install Node dependencies and run linters and tests, and precompiled Handlebars templates are supported via a build step. Additionally, an empty openssl.cnf is added to satisfy PhantomJS requirements.
admin/src/main/resources/io/buoyant/admin · high confidence
Introduce Namerd service for managing Linkerd name delegation
Adds the Namerd service, a new component for managing Linkerd name delegation. This includes the core \DtabHandler\ and \DtabListHandler\ for serving delegation data, along with \NamerdAdmin\ to wire up the admin dashboard, static assets, and logging endpoints. The \Main\ entry point now supports configuration validation and graceful shutdown via SIGINT/SIGTERM signals.
namerd/core/src/main, namerd/main/src/main/scala · high confidence
Introduce Netty4-based HTTP/2 transport implementation
Adds a new set of Netty4-specific components for HTTP/2, including a client dispatcher, server listener, transporter, writer, and upgrade handler. This implementation supports both plaintext (h2c) and TLS-encrypted connections, handling HTTP/1.1 upgrade headers and HTTP/2 connection prefaces to establish multiplexed streams over a single connection.
finagle/h2/src/main/scala/com/twitter/finagle/buoyant/h2/netty4 · high confidence
Introduce admin API for delegation and logging
The admin service now exposes structured JSON endpoints for delegation and logging. A new \DelegateApiHandler\ provides a \/delegate\ endpoint that returns the current delegation tree as JSON, supporting both reading the current state and submitting a new delegation tree to update it. Additionally, a \LoggingHandler\ and \LoggingApiHandler\ are added to the admin interface, allowing users to view all configured loggers and their current levels via a GET request, and update a specific logger's level via a POST request. These changes add new capabilities to the admin interface for inspecting and modifying runtime state and logging configuration.
project · high confidence
Introduce core name resolution and transformation infrastructure
Adds the foundational components for name resolution and transformation, including the \NameTreeTransformer\ interface and its implementations (\ConstTransformer\, \ReplaceTransformer\) to modify resolved name trees. It also introduces the \RewritingNamer\ trait and specific namers (\hostportPfx\, \porthostPfx\, \rinet\, \domainToPath\) that rewrite incoming paths, alongside the \Delegator\ interface for delegation. This change establishes the core abstractions for configuring and applying transformations to name resolution results.
namer/core/src/main · high confidence
Introduce gRPC code generation entry point for Finagle
A new Scala entry point (Main.scala) has been added to the grpc/gen module, implementing the gRPC code generation logic for Finagle. This change introduces the primary interface for generating gRPC code, utilizing the Generator class to parse requests and produce the corresponding output. This aligns with the stated goal of implementing gRPC code generation for Finagle, providing a concrete implementation for the code generation process.
grpc/gen · medium confidence
Introduce gRPC runtime support for Linkerd
Added new Scala files in the gRPC runtime module (Codec, H2Headers, ServerDispatcher) that provide the core infrastructure for handling gRPC traffic. This includes a Codec for encoding/decoding Protobuf messages, H2Headers for managing HTTP/2 headers, and a ServerDispatcher that routes incoming gRPC requests to the appropriate service and RPC handler. This enables Linkerd to understand and proxy gRPC traffic.
grpc/runtime/src/main · high confidence
Introduce io.linkerd.mesh gRPC interface for name resolution and interpretation
Adds a new gRPC service interface (io.linkerd.mesh) defined in protobuf files (codec.proto, delegator.proto, dtab.proto, interpreter.proto, resolver.proto) and Scala converters. This introduces new RPCs for reading/writing dtabs and paths, delegating name lookups, interpreting path bindings, and resolving concrete endpoints, enabling thin clients to perform naming and resolution without implementing parsing and formatting logic.
mesh/core · high confidence
Introduce the core telemetry subsystem and MetricsTree
Added the foundational telemetry components: a hierarchical MetricsTree for organizing metrics, a Telemeter trait to receive stats and traces, and a TelemeterInitializer to support plugin-based telemeter configuration. This establishes the internal structure for the new telemetry system.
telemetry/core/src/main · high confidence
Introduce the io.linkerd.mesh gRPC interface for Namerd
Namerd now exposes a new gRPC interface, io.linkerd.mesh, which allows external services to interact with the name resolution and delegation system. This interface provides services for resolving service endpoints (ResolverService), binding paths to name trees (InterpreterService), and querying delegation trees (DelegatorService). The implementation includes a new initializer (MeshIfaceInitializer) that registers this interface, supporting configuration for access logging, TLS, and socket options. Tests confirm that the resolver service correctly strips transformer prefixes when resolving addresses.
namerd/iface/mesh · high confidence
NamerdHandler interface definition
The NamerdHandler interface is introduced, providing the contract for handling Namerd requests. This change establishes the core handler structure for the Namerd interpreter, enabling request interception and destination information processing as part of the Namerd service.
interpreter/namerd/src/main/scala · medium confidence
New /admin/metrics.json endpoint for exporting metrics
A new admin endpoint at /admin/metrics.json now exports metrics as JSON. Counters and gauges are served live, while histogram values are snapshotted at a configurable interval (defaulting to every minute) to provide summary statistics. The endpoint supports a ?tree=1 parameter to output a hierarchical JSON structure instead of a flat map, and a ?q= parameter to filter the output to a specific subtree of the metrics tree.
telemetry/admin-metrics-export · high confidence
New CI scripts for coverage, Docker publishing, and testing
Added new shell scripts to the CI directory to automate build and test workflows. coverage-publish.sh handles code coverage reporting via Coveralls. docker-publish.sh manages Docker image building and pushing for Linkerd and Namerd, supporting both standard and DCOS tags. h2.sh provides a test harness for HTTP/2 protocol support, including downloading h2spec and nghttpd, and running Linkerd against them. test.sh orchestrates unit tests, end-to-end tests, and binary assembly, with parallelization across CI nodes. twitter-develop.sh fetches and publishes local dependencies from Twitter's develop branches. update.sh triggers dependency updates.
ci · high confidence
New HTTP API endpoints for name resolution and management
The control HTTP interface now exposes a suite of new endpoints for managing and querying name resolution state. Users can now retrieve bound names, resolve paths to addresses, and inspect delegation trees via new handlers (AddrHandler, BindHandler, ResolveHandler, BoundNamesHandler). Additionally, the existing Dtab and Delegate endpoints have been refactored to support JSON content types and streaming responses, while the Dtab handler now validates for null entries in dtab strings, returning a 400 Bad Request for invalid input.
namerd/iface/control-http/src/main/scala · high confidence
New utility classes for state management and retry logic
The Finagle Buoyant library introduces new utilities to improve state management and retry handling. A new \ExistentialStability\ object provides \stabilizeExistence\ methods for \Var\ and \Activity\, allowing an \Option\-based state to be split into inner and outer variables that track existence changes separately from value changes. Additionally, a new \RetryFilter\ is added, which manages request retries with configurable policies, timers, and budgeting, while also exposing specific retry-related statistics. The \package.scala\ file also adds helper methods for conditionally applying \Stack.Params\ and re-exports \ResponseClassificationSyntheticException\.
finagle/buoyant/src/main/scala/com/twitter/finagle/buoyant · medium confidence
Register HttpControlServiceInitializer for namerd
A new service provider file has been added to register io.buoyant.namerd.iface.HttpControlServiceInitializer, enabling the HTTP control interface for namerd to be automatically discovered and initialized.
namerd/iface/control-http/src/main/resources · high confidence
Registered UsageDataTelemeter via Java SPI
The UsageDataTelemeter is now automatically discovered and initialized by the telemetry framework through the Java Service Provider Interface (SPI) mechanism. This change registers io.buoyant.linkerd.telemeter.UsageDataTelemeterInitializer in the META-INF/services/io.buoyant.telemetry.TelemeterInitializer file, ensuring the usage data collection component is loaded at runtime without manual configuration.
linkerd/telemeter/usage · high confidence
Updated build tooling and project governance files
The repository now includes new documentation and configuration files to support development and community governance. A new BUILD.md file provides a comprehensive guide for building Linkerd from source using sbt, including instructions for running unit, end-to-end, and integration tests, as well as packaging instructions. The project has adopted a Developer Certificate of Origin (DCO) in place of a CLA, and added a GOVERNANCE.md file defining maintainer and super-maintainer roles and decision-making processes. Additionally, a MAINTERS.md file lists the current maintainers, and an ADOPTERS.md file lists organizations using Linkerd in production. The sbt build script has been updated to use version 1.2.8, and the .gitignore file has been expanded to include more build artifacts and IDE files.
(repo-wide) · high confidence
Removals
Removal of experimental Kubernetes namer implementation
The experimental Kubernetes namer implementation (io.l5d.experimental.k8s) has been removed from the codebase. This change eliminates the ability to configure a Kubernetes namer using the specific host, port, TLS, and authentication token file parameters previously supported by this component. Users relying on this configuration method will need to adopt alternative namer configurations.
linkerd/namer/k8s · high confidence
Removal of filesystem-based namer implementation
The filesystem-based namer implementation (io.l5d.fs) has been removed from the Linkerd codebase. This change eliminates the ability to configure namers that resolve service names based on the local filesystem, as the associated initializer class and its configuration parser are no longer available.
linkerd/namer/fs · high confidence
Removed deprecated name resolution components
The \Delegator\ trait and \WebDelegator\ service, which previously handled name resolution and exposed it via a JSON API, have been removed from the admin server. This eliminates the legacy name resolution path in favor of the new \NameInterpreter\-based architecture.
linkerd/admin/src/main/scala/io/buoyant/linkerd/admin/names · high confidence
Architecture
Refactored Kubernetes API client into modular components
The Kubernetes API client implementation has been refactored into a set of distinct, reusable components. The previous monolithic \Json\ object for serialization has been replaced by a \SerializationModule\ and \package.scala\-based JSON handling. New files introduce an \AuthFilter\ for Bearer token injection, a \ClientConfig\ trait for building HTTP clients with specific Finagle settings (such as disabling tracing and handling reader discards), and an \InstrumentedWatch\ class to track the state of Kubernetes watch streams. The core watch logic has been moved into a \Watchable\ abstract class that handles retry policies, status code handling, and stream processing, while \resources.scala\ defines the \Resource\, \Version\, and \ListResource\ hierarchy. This change reorganizes the internal structure of the k8s namer to improve modularity and observability.
k8s/src/main · high confidence
Behavioural changes
Add H2 protocol support with pluggable identifiers, classifiers, and trace propagators
The H2 protocol implementation is now registered via Java SPI service files, enabling automatic discovery of H2-specific components. This includes new identifier initializers for header, path, and ingress routing (including Istio and K8s ingress patterns), a protocol initializer for H2, an authorizer initializer for Istio requests, and a comprehensive set of response classifiers for handling 5xx errors and gRPC status codes. Additionally, trace propagation is extended to support both Linkerd and Zipkin headers, making tracing pluggable for HTTP/2 traffic.
linkerd/protocol/h2/src/main/resources · high confidence
Add ZooKeeper-based service announcement support
Users can now announce services via ZooKeeper using the new ZkAnnouncer implementation, which registers service instances in ZooKeeper paths. This change also updates the Announcer API to return a Closable interface, allowing for proper resource cleanup when stopping announcements.
linkerd/announcer/serversets · high confidence
Add clear context functionality for H2 requests
The H2 protocol implementation now includes a \clearServerModule\ that clears Linkerd-specific context headers (deadline, dtab, sample, trace, and misc) from incoming HTTP/2 requests. This allows for explicit cleanup of request context, ensuring that downstream services do not receive Linkerd metadata headers that were intended only for the local router instance.
linkerd/protocol/h2/src/main/scala/com · high confidence
Add support for disabling failure accrual
Users can now explicitly disable failure accrual by selecting the 'none' policy. This is achieved through a new NoneInitializer and NoneConfig, which register a no-op FailureAccrualPolicy that records successes without marking hosts as dead on failure.
linkerd/failure-accrual/src/main · high confidence
Added H2 diagnostic tracer and pluggable response classifiers
The H2 protocol module now includes a diagnostic tracer (H2DiagnosticTracer) that intercepts H2 TRACE requests to return identification, delegation, and service address information. Additionally, the module introduces a pluggable response classifier system (H2ClassifierConfig and H2Classifiers) that allows users to configure how H2 responses are classified for retry and failure accrual purposes, with predefined options for retryable and non-retryable 5XX errors.
linkerd/protocol/h2/src/main/scala/io/buoyant/linkerd/protocol/h2 · medium confidence
Added buffering connect delay handler for outbound writes
A new \BufferingConnectDelay\ channel handler has been introduced in the Netty 4 implementation. This handler buffers outbound writes and delays their execution until the underlying channel connection is fully established. This ensures that requests are not lost or failed prematurely during the connection phase, improving reliability for clients that send data before the connection is fully active.
finagle/buoyant/src/main/scala/com/twitter/finagle/netty4 · high confidence
Adds per-destination-path tracing and stats reporting
The router now introduces a new set of components to support per-destination-path metrics and tracing. A new \PathRegistry\ maintains a registry of destination paths, enabling the router to apply specific filters for each unique destination. \ClassifiedTracing\ is added to annotate traces with response classifications (success, retryable, failure) based on the active response classifier. Additionally, \LocalClassifierStatsFilter\ and \PerDstPathStatsFilter\ are introduced to report request statistics scoped to each logical destination path, ensuring that metrics are accurately attributed to the correct service and client contexts.
router/core/src/main/scala/io · high confidence
Admin UI and logging improvements
The admin interface now wraps HTML responses with standard assets (jQuery, Bootstrap) and supports plugin-defined navigation items. Logging is updated to include the system's configured timezone in all log entries, improving time correlation across distributed systems.
admin/src/main/scala · medium confidence
Admin UI styling and layout updates
The admin interface received a visual refresh and layout adjustments. A new dashboard stylesheet introduces a dark theme with specific color coding for success and failure metrics, alongside updated typography using the Source Sans Pro font. The delegator (dtab) UI was restructured to improve readability and layout, including changes to panel styling, list groups, and the dtab editor. Additionally, the logging page received table styling updates, and several CSS files were moved to a shared admin location.
admin/src/main/resources/io/buoyant/admin/css · medium confidence
Admin dashboard templates migrated to Handlebars with new metric and router components
The admin dashboard's frontend templates have been converted from the legacy \.template\ format to compiled Handlebars templates (\.handlebars\ and \compiled\_templates.js\). This migration introduces new UI components for displaying router and client metrics, including bar charts, latency tables, and request totals. The delegator UI now supports primary path indication, weight display, and exception messaging, while the dashboard gains a new service-oriented view with expanded/collapsed client states and server connection displays.
admin/src/main/resources/io/buoyant/admin/js/template · medium confidence
Default logging configuration for Namerd
A default log4j.properties file has been added to configure logging for Namerd. The configuration sets the root logger to WARN level and uses an AsyncAppender to write logs to the console, including the date, time, and time zone in the log output.
namerd/main/src/main/resources · high confidence
Enable Consul consistency mode and health status configuration
Users can now configure Consul's consistency mode and filter nodes by health status. This is achieved by registering new configuration deserializers and serializers for ConsistencyMode and HealthStatus, allowing these settings to be properly parsed and persisted in the configuration.
consul/src/main/resources · medium confidence
Enable early HTTP/2 response classification
The system now supports classifying HTTP/2 responses based on the final frame of the response stream, not just the initial response. A new \H2Classifier\ trait allows defining logic for both immediate responses and stream-level classification, while a corresponding context object (\H2ClassifierCtx\) makes this classifier available to the client stack for reporting statistics.
finagle/h2/src/main/scala/com/twitter/finagle/buoyant/h2/service, router/h2/src/main/scala/io/buoyant/router/context · low confidence
Enhanced error messages for connection and routing failures
The system now provides more detailed and user-friendly error messages for connection failures and routing issues. Specifically, connection failures now include the remote address and routing context, while 'No Brokers Available' errors now display the service name, base dtab, and override dtab to help users understand why routing failed.
router/core/src/main/scala/com/twitter/finagle/naming · high confidence
HTTP protocol module refactored with new diagnostic tracer and path identifier
The HTTP protocol module was reorganized into the new \linkerd/protocol/http\ package, introducing a \DiagnosticTracer\ that intercepts HTTP TRACE requests to return router context information, while also adding a configurable \io.l5d.path\ identifier that can optionally strip off consumed path segments, and a \StatusCodeStatsFilter\ that records HTTP status code metrics.
linkerd/protocol/http/src/main/scala/io/buoyant/linkerd/protocol/http · medium confidence
HTTP protocol service registrations for identifiers, authorizers, classifiers, and trace propagators
The HTTP protocol module now registers its components via Java SPI service files, enabling automatic discovery of HTTP-specific implementations. This includes initializers for various request identifiers (header, header token, method and host, path, static, K8s ingress, Istio, and Istio ingress), an Istio request authorizer, response classifiers (non-retryable 5XX, retryable idempotent/read/all 5XX, and all-successful), and trace propagators (Linkerd and Zipkin).
linkerd/protocol/http/src/main/resources · high confidence
HTTP request identification is now pluggable via a new configuration interface
The previous hardcoded HTTP request identification logic in HttpInitializer has been replaced by a new, pluggable HttpIdentifierConfig interface. This change allows users to configure and customize how HTTP requests are identified for routing purposes, supporting different identification strategies through the new abstract class that integrates with the existing router and stack parameter system.
linkerd/protocol/http/src/main/scala/io/buoyant/linkerd/protocol · medium confidence
HTTP service closure delayed until responses complete
The HTTP protocol implementation now includes a new 'DelayedRelease' module that prevents an HTTP service from being closed until its response completes. This ensures that active requests are allowed to finish before the service is shut down, improving reliability during service lifecycle transitions.
linkerd/protocol/http/src/main/scala/com · medium confidence
Improved tracing efficiency and failure accrual configuration
Tracing for unbound destinations and client connections now uses conditional checks to avoid unnecessary work when tracing is inactive, and trace keys are renamed (e.g., 'namer.dtab.base' to 'dtab.base') for clarity. Additionally, the failure accrual mechanism now reads the response classifier from the request local context, allowing for more dynamic and accurate failure detection based on the specific request's configuration.
router/core/src/main/scala/com/twitter/finagle/buoyant · high confidence
Introduce RequireJS module loading and jQuery 3.1.1 upgrade
The admin interface now uses RequireJS for module loading, with new entry points for Linkerd and Namerd admin pages. This change upgrades jQuery to version 3.1.1 and configures dependencies for lodash, Handlebars, Bootstrap, and Smoothie. The JavaScript initialization logic is restructured to support dynamic routing for different admin pages (dashboard, delegator, namerd, logging, and services).
admin/src/main/resources/io/buoyant/admin/js · high confidence
Istio namer implementation moved to its own module
The Istio namer implementation has been moved into its own module, with the service provider interface now pointing to io.buoyant.namer.k8s.istio.IstioInitializer. This change isolates the Istio namer code, which may affect how the namer is discovered and initialized within the application.
namer/istio · low confidence
Kubernetes interpreters and transformers are now auto-discovered via service providers
The Kubernetes interpreter and transformer implementations are now registered via Java's Service Provider Interface (SPI) mechanism. Specifically, ConfigMapInterpreterInitializer is registered for Kubernetes ConfigMaps, while DaemonSet and LocalNode transformers are registered for their respective resources. This change enables automatic discovery and initialization of these components without requiring explicit configuration or manual registration, simplifying the setup for users interacting with Kubernetes ConfigMaps, DaemonSets, and local nodes.
interpreter/k8s/src/main · medium confidence
Marathon namer adds HTTP basic authentication support
The Marathon namer now supports HTTP basic authentication for API requests. A new service loader configuration registers the Marathon namer initializer, and a BasicAuthenticatorFilter is introduced to inject the Authorization header into requests, allowing the namer to authenticate with Marathon instances that require credentials.
namer/marathon/src/main · medium confidence
Mux protocol adds configurable server port and service/client options
The Mux protocol implementation now exposes a configurable server port (defaulting to 4141) and introduces new configuration options for services and clients. Users can now specify server ports and define service and client configurations via the MuxConfig class, allowing for more granular control over Mux-based routing and server setup.
linkerd/protocol/mux · medium confidence
New config parsing infrastructure with JSON/YAML support and streaming
The config module introduces a new JSON and YAML parsing system, including a \JsonStreamParser\ for handling large streaming JSON objects, which addresses previous memory leak issues. It also adds deserializers and serializers for various configuration types (such as Dtab, Path, LogLevel, InetAddress, and PathMatcher) and enforces strict duplicate property detection to prevent configuration errors.
config · high confidence
Redesign of the Linkerd admin dashboard and navigation
The Linkerd admin interface has been redesigned with a new dashboard layout, a dedicated help page, and updated navigation. The previous summary, metrics, and delegator pages have been replaced by a new dashboard that displays request totals, server and client information, and process stats. A new help page provides troubleshooting steps and links to the Linkerd documentation, Discourse, and Slack. The navigation bar now includes a router label dropdown for filtering the dashboard view, and the layout uses a grid system for better responsiveness.
linkerd/admin/src/main/scala/io/buoyant/linkerd/admin · high confidence
Redesigned admin dashboard with service-oriented and client-specific views
The admin dashboard has been restructured to support both service-oriented and client-specific views. A new 'service' dashboard type allows users to view metrics for individual services, while the existing client dashboard now displays detailed metrics for each client, including success rates, latency, and load balancer status. The UI now supports collapsing and expanding client sections to improve performance when many clients are present. Additionally, the delegator UI has been updated to use POST requests for data transfers, and the dashboard now displays server connections, request totals, and retry budget status.
admin/src/main/resources/io/buoyant/admin/js/src · high confidence
Refactor HTTP router filters and tracing into the router-http module
The HTTP router filters (e.g., Forwarded, Via, Content-Length, Classifier) and tracing logic have been moved from the \com.twitter.finagle.buoyant\ package to \io.buoyant.router.http\. This refactoring consolidates HTTP-specific middleware and tracing annotations within the router-http module, removing the previous implementations from the \com.twitter.finagle.buoyant\ package.
router/http/src/main · high confidence
Refactor linkerd startup and admin initialization
The linkerd application entry point has been refactored from the \io.buoyant.Linkerd\ object to \io.buoyant.linkerd.Main\. This change introduces explicit initialization of the admin server and HTTP identifier endpoint, adds graceful shutdown handling for SIGINT/SIGTERM signals, and moves the admin server initialization logic out of the main application object into a dedicated \initAdmin\ method. An end-to-end test (\EndToEndTest\) is added to verify the new interpreter state endpoint.
linkerd/main · high confidence
Refactored Istio request and response handling for HTTP/1.1 and HTTP/2 protocols
The Istio protocol handling logic has been refactored into protocol-specific implementations for HTTP/1.1 and HTTP/2. New files have been added to manage Istio requests and responses for both protocols, including dedicated request handlers that support redirect and rewrite operations. This change prepares the codebase for adding Mixer precondition checks.
linkerd/protocol/h2/src/main/scala/io/buoyant/linkerd/protocol/h2/istio, linkerd/protocol/http/src/main/scala/io/buoyant/linkerd/protocol/http/istio · medium confidence
Refactored linkerd configuration and initialization architecture
The linkerd package structure was refactored to replace the legacy \NamerInitializer\ and \ProtocolInitializers\ with a new, pluggable configuration model. New abstract classes such as \Client\, \Svc\, \FailureAccrualConfig\, and \TracePropagator\ are introduced to support polymorphic configuration via Jackson annotations, allowing users to define client, service, and tracing behaviors through structured config objects. The old \NamerInitializers\ and \ProtocolInitializers\ traits and their associated parsing utilities (\Parsing.scala\) were removed, indicating a shift from a service-discovery-based initialization model to a more explicit, configuration-driven approach for components like announcers, identifiers, and response classifiers.
linkerd/core/src/main/scala · medium confidence
Register Consul namer initializer
The Consul namer implementation is now registered as a service provider via the \META-INF/services/io.buoyant.namer.NamerInitializer\ file, enabling automatic discovery and initialization of the Consul namer.
namer/consul/src/main/resources · high confidence
Register Namerd HTTP and standard interpreters via Java SPI
Added the META-INF/services/io.buoyant.namer.InterpreterInitializer file to register io.buoyant.namerd.iface.NamerdHttpInterpreterInitializer and io.buoyant.namerd.iface.NamerdInterpreterInitializer, enabling automatic discovery of these interpreters at runtime.
interpreter/namerd/src/main/resources · high confidence
Removal of MuxTraceInitializer
The MuxTraceInitializer component, which previously configured trace ID generation for the Mux stack, has been removed from the codebase.
router/mux · high confidence
Removal of legacy admin CSS stylesheets
The admin interface's existing CSS files (admin.css, metrics.css, summary.css) have been removed. This change eliminates the previous styling for the header, navigation, metrics, and summary pages, likely to be replaced by a new styling approach or framework.
linkerd/admin/src/main/resources/io/buoyant/linkerd/admin/css · high confidence
Removed legacy admin JavaScript and dependencies
The legacy admin interface scripts (admin.js, delegate.js) and their dependencies (jQuery 2.1.1, Handlebars v4.0.5) have been removed from the admin UI. This cleanup removes unused or deprecated client-side code, reducing the admin page's JavaScript footprint and eliminating reliance on older library versions.
linkerd/admin/src/main/resources/io/buoyant/linkerd/admin/js · high confidence
Removed obsolete admin template files
The admin interface templates for 'interfaces' and 'metrics' have been removed. These files previously rendered lists of network interfaces and metrics, but are no longer used in the admin UI.
linkerd/admin/src/main/resources/io/buoyant/linkerd/admin/template · high confidence
Replace Netty's Http2FrameCodec with a custom H2FrameCodec implementation
The HTTP/2 frame codec has been replaced with a custom H2FrameCodec implementation to address instability in Netty's original API, particularly regarding initial settings and flow control. This change includes a server upgrader to support HTTP/2 upgrades and introduces aggressive window update acknowledgment (0.99 ratio) for improved flow control.
finagle/h2/src/main/scala/io · high confidence
ServersetNamer now supports dtabs with shard fragments
The ServersetNamer implementation has been updated to handle paths containing shard fragments, allowing the namer to correctly resolve and bind names that include shard identifiers in their path structure. This change ensures that clients can rely on Name.Bound IDs being Paths that resolve back to the same Name.Bound, improving consistency in name resolution for serverset-based services.
namer/serversets/src/main · medium confidence
Updated JavaScript libraries: Handlebars 4.0.5 and jQuery 3.1.1
The admin interface now uses updated versions of the Handlebars and jQuery libraries. Specifically, Handlebars has been added at version 4.0.5, and jQuery has been upgraded to version 3.1.1. These updates provide the latest features and bug fixes from these libraries for the admin UI.
admin/src/main/resources/io/buoyant/admin/js/lib · high confidence
Test coverage
Add TLS end-to-end test for HTTP/2; Add tests for namerd example configurations; Added AccessLogger benchmark; Added H2 router client stack tests; Added JVM metrics fixture for frontend tests; Added JavaScript unit tests for the admin dashboard components; Added and refactored tests for the Linkerd admin dashboard and handlers; Added and updated tests for HTTP router filters and identifiers; Added comprehensive tests for the Consul namer; Added end-to-end tests for HTTP streaming and TLS configuration; Added end-to-end tests for HTTP/2 routing and flow control; Added end-to-end tests for the H2 protocol implementation; Added gRPC interop and end-to-end tests; Added gRPC interop tests; Added integration test for X-Forwarded-Client-Cert header handling; Added integration tests for HTTP TLS client and server configurations; Added test coverage for ServersetNamer and Serversets configuration parsing; Added test utilities for H2 stream handling; Added test utilities for assertions, retries, and JSON comparison; Added tests for H2 failure accrual logic; Added tests for H2 protocol support; Added tests for H2 router filters; Added tests for HTTP/2 buffering and tracing; Added tests for InfluxDB telemetry integration; Added tests for Istio integration components; Added tests for K8s and K8sExternal namers; Added tests for K8s transformers; Added tests for Kubernetes API and namer components; Added tests for Linkerd configuration parsing and client setup; Added tests for Marathon namer, authentication, and configuration; Added tests for MeshInterpreterInitializer; Added tests for Namerd Thrift interpreter interface; Added tests for Namerd configuration and Dtab store validation; Added tests for Netty4 H2 client and server dispatchers; Added tests for Thrift protocol initialization and configuration; Added tests for TraceInitializer and DstBindingFactory; Added tests for failure accrual configuration and policies; Added tests for host/port namers and moved HTTP namer tests; Added tests for log formatting and security filtering; Added tests for mesh interpreter client and buffer serialization; Added tests for namerd interpreters; Added tests for path matching and existential stability; Added tests for router core components; Added tests for the Kubernetes ConfigMap interpreter; Added tests for the Marathon v2 API client; Added tests for the in-memory Dtab store; Added tests for the telemetry core subsystem; Added unit tests for Consul v1 API clients; Added unit tests for StatsD telemetry components; Refactored Kubernetes API test suite for improved reliability; Updated tests for the Linkerd admin name resolution and delegation API.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 46 → 47 (+0.3)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 46 → 68 (+21.4)
- Architecture 100 → 96 (-4.2)
- Maturity 36 → 48 (+12.3)
- Readiness 52 → 59 (+6.4)
- Security 66 → 59 (-6.8)
- Accessibility 35 (new)
Resolved (50)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Dependency hygiene not measured — no supported dependency manifest was read
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- High CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- …and 30 more
New (177)
- (anonymous) (cognitive 16) (admin/src/main/resources/io/buoyant/admin/js/src/router_clients.js)
- (anonymous) (cognitive 18) (admin/src/main/resources/io/buoyant/admin/js/src/router_summary.js)
- (anonymous) (cognitive 21) (admin/src/main/resources/io/buoyant/admin/js/src/utils.js)
- (anonymous) (cognitive 22) (admin/src/main/resources/io/buoyant/admin/js/src/delegator.js)
- (anonymous) (cognitive 24) (admin/src/main/resources/io/buoyant/admin/js/src/router_client.js)
- (anonymous) (cyclomatic 16) (admin/src/main/resources/io/buoyant/admin/js/src/router_summary.js)
- (anonymous) (cyclomatic 17) (admin/src/main/resources/io/buoyant/admin/js/src/utils.js)
- (anonymous) (cyclomatic 20) (admin/src/main/resources/io/buoyant/admin/js/src/router_client.js)
- (anonymous) (cyclomatic 29) (admin/src/main/resources/io/buoyant/admin/js/src/delegator.js)
- AddrSerializer.serialize (cognitive 18) (namerd/iface/interpreter-thrift/src/main/scala/io/buoyant/namerd/iface/AddrSerializer.scala)
- Api.toAddresses (cognitive 20) (marathon/src/main/scala/io/buoyant/marathon/v2/Api.scala)
- AppIdNamer.getAndMonitorAddr (cognitive 23) (namer/marathon/src/main/scala/io/buoyant/namer/marathon/AppIdNamer.scala)
- CI installs an unverified third-party binary (.circleci/config.yml)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Critical CVE: [GHSA redacted] (admin/src/main/resources/io/buoyant/admin/package-lock.json)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile is in a format this engine cannot resolve)
- …and 157 more
Architecture
- Containers 0 added · 0 removed · contexts 1 added · 2 removed · edges 0 added · 0 removed
Added bounded contexts (1)
- repository
Removed bounded contexts (2)
- .
- project
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
linkerd/linkerd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ea82499d386e44e8958be58e0386f593e639645b — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-be726e82e277.