Buoyant recently updated its Linkerd service mesh platform with security features it claims make it the obvious choice among Kubernetes- and container-focused service mesh offerings.  

The Linkerd 2.11 update includes a new network policy feature that extends zero-trust security capabilities to Kubernetes environments. Buoyant CEO William Morgan explained that this is a "milestone" for the platform as "now you can use Linkerd to control which types of communication are available or are possible on your cluster.”

The update also offers more control over network policy regulations that allow Kubernetes administrators to verify communication requirements for workloads, and also allows organizations to deploy microsegmentation to control data flows within the cluster.

Zero Trust to the Top

Linkerd also relies on mutual TLS (mTLS), a method for mutual identification based on cryptographic security, to provide encryption and fine-grained user identification. Morgan explained that when combined with the new policy features, organizations in regulated industry can protect sensitive data when building applications on top of Kubernetes.

“We're never going to trust anything that we don't absolutely have to trust, and Linkerd, the mutual TLS, and the policy is all done in a zero-trust way,” he said.

The enhanced platform also helps control traffic between namespaces at the platform level in a Kubernetes environment. “Now with Linkerd’s policy feature in 2.11, you can easily say this type of traffic is not allowed between these namespaces or the opposite.”

Morgan boasted that these updates fortify the platform beyond what is available through other service mesh products in the market.

“If you want to have a Kubernetes cluster that has zero-trust security, has microsegmentation, that's built on CNCF (Cloud Native Computing Foundation) open-source technology, has a foundation of security that starts all the way from rust, [and has] all the way up to features like policy and microsegmentation, then Linkerd is the obvious choice,” Morgan boasted in an interview.

Security Above Others

Linkerd was developed as an open-source network proxy designed to be deployed as a service mesh. A service mesh is a dedicated layer for managing, controlling, and monitoring service-to-service communication within an application.

It was adopted as a hosted project within the CNCF in 2017, and recently became the first service mesh to graduate from the open source-focused organization. That distinction is notable for the project, which has seen its first-mover advantage overtaken by the marketing power and adoption strength behind the Google-backed Istio project. 

However, Istio's progress stalled last year after Google decided to dock the Istio service mesh project within the newly formed Open Usage Commons (OUC) group rather than donate the project to the CNCF, as the open source community expected. This has also led to the launch of a number of other service mesh projects.

Morgan, who has long been a vocal critic of Istio, recently told SDxCentral in an interview that Istio carries the danger of not being more than “empty calories” as a result of over-complication.

“I think there is a tendency among many infrastructure projects, including Istio, to want to do more, and to want to solve broader classes of problems,” Morgan said. “And I think that’s the wrong approach for infrastructure. I think that’s where you end up with things that are very complicated and have a whole lot of marketing momentum, but then there’s nothing behind the scenes.”

In contrast, Morgan said Linkerd remains focused on simplicity and user experience as staples of the project. “If there’s nothing else that I want Linkerd to be remembered for, it’s carrying that message of simplicity and user empathy forward in the infrastructure space,” Morgan said.