
Linkerd Patterns
- 7.9k installs
- 38.3k repo stars
- Updated July 22, 2026
- wshobson/agents
linkerd-patterns is an agent skill for implementing Linkerd service mesh on Kubernetes with mTLS, traffic splits, and authorization policies.
About
The linkerd-patterns skill provides production patterns for Linkerd, the lightweight security-focused Kubernetes service mesh. It covers control plane components including destiny, identity, and proxy-inject alongside data plane sidecar proxies wrapping application pods. Key resources include ServiceProfile for per-route metrics retries and timeouts, TrafficSplit for canary and A/B deployments, Server for server-side policies, and ServerAuthorization for access control. Templates walk through CLI installation, cluster validation, CRD and control plane setup, viz extension install, namespace injection labels, service profile YAML, traffic split manifests, and authorization policies. Use cases span automatic mTLS, canary routing, per-route observability, retry and timeout configuration, and multi-cluster mesh topologies. The skill targets teams wanting minimal-overhead zero-trust networking compared to heavier mesh alternatives. Use when setting up Linkerd, configuring traffic policies, or implementing service mesh security on Kubernetes.
- Linkerd control plane and data plane sidecar architecture overview.
- ServiceProfile for per-route metrics, retries, and timeouts.
- TrafficSplit manifests for canary and A/B traffic routing.
- Server and ServerAuthorization for zero-trust access policies.
- Installation and validation templates from CLI through viz extension.
Linkerd Patterns by the numbers
- 7,928 all-time installs (skills.sh)
- +152 installs in the week ending Jul 28, 2026 (Skillselion tracking)
- Ranked #98 of 1,041 Cloud & Infrastructure skills by installs in the Skillselion catalog
- Security screen: MEDIUM risk (skills.sh audit)
- Data as of Jul 28, 2026 (Skillselion catalog sync)
linkerd-patterns capabilities & compatibility
- Capabilities
- linkerd cli installation and cluster validation · control plane and viz extension setup · namespace proxy injection configuration · serviceprofile per route metrics and timeouts · trafficsplit canary and a/b routing · serverauthorization access control policies
- Works with
- kubernetes
- Use cases
- devops · ci cd · security audit
What linkerd-patterns says it does
Production patterns for Linkerd service mesh - the lightweight, security-first service mesh for Kubernetes.
npx skills add https://github.com/wshobson/agents --skill linkerd-patternsAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 7.9k |
|---|---|
| repo stars | ★ 38.3k |
| Security audit | 2 / 3 scanners passed |
| Last updated | July 22, 2026 |
| Repository | wshobson/agents ↗ |
How do I set up Linkerd on Kubernetes with canary routing, per-route metrics, and automatic mTLS?
Implement Linkerd service mesh on Kubernetes with mTLS, traffic splits, service profiles, retries, and multi-cluster patterns.
Who is it for?
Platform engineers deploying a lightweight security-focused service mesh on Kubernetes clusters.
Skip if: Skip when you need Istio-specific features or non-Kubernetes networking; this skill targets Linkerd only.
When should I use this skill?
User asks to install Linkerd, configure traffic splits, set up service profiles, or implement mesh mTLS.
What you get
Working Linkerd mesh with service profiles, traffic splits, and server authorization policies configured.
- TrafficSplit and ServiceProfile manifests
- mTLS and policy configuration guidance
- Multi-cluster mesh setup steps
Files
Linkerd Patterns
Production patterns for Linkerd service mesh - the lightweight, security-first service mesh for Kubernetes.
When to Use This Skill
- Setting up a lightweight service mesh
- Implementing automatic mTLS
- Configuring traffic splits for canary deployments
- Setting up service profiles for per-route metrics
- Implementing retries and timeouts
- Multi-cluster service mesh
Core Concepts
1. Linkerd Architecture
┌─────────────────────────────────────────────┐
│ Control Plane │
│ ┌─────────┐ ┌──────────┐ ┌──────────────┐ │
│ │ destiny │ │ identity │ │ proxy-inject │ │
│ └─────────┘ └──────────┘ └──────────────┘ │
└─────────────────────────────────────────────┘
│
┌─────────────────────────────────────────────┐
│ Data Plane │
│ ┌─────┐ ┌─────┐ ┌─────┐ │
│ │proxy│────│proxy│────│proxy│ │
│ └─────┘ └─────┘ └─────┘ │
│ │ │ │ │
│ ┌──┴──┐ ┌──┴──┐ ┌──┴──┐ │
│ │ app │ │ app │ │ app │ │
│ └─────┘ └─────┘ └─────┘ │
└─────────────────────────────────────────────┘2. Key Resources
| Resource | Purpose |
|---|---|
| ServiceProfile | Per-route metrics, retries, timeouts |
| TrafficSplit | Canary deployments, A/B testing |
| Server | Define server-side policies |
| ServerAuthorization | Access control policies |
Templates
Template 1: Mesh Installation
# Install CLI
curl --proto '=https' --tlsv1.2 -sSfL https://run.linkerd.io/install | sh
# Validate cluster
linkerd check --pre
# Install CRDs
linkerd install --crds | kubectl apply -f -
# Install control plane
linkerd install | kubectl apply -f -
# Verify installation
linkerd check
# Install viz extension (optional)
linkerd viz install | kubectl apply -f -Template 2: Inject Namespace
# Automatic injection for namespace
apiVersion: v1
kind: Namespace
metadata:
name: my-app
annotations:
linkerd.io/inject: enabled
---
# Or inject specific deployment
apiVersion: apps/v1
kind: Deployment
metadata:
name: my-app
annotations:
linkerd.io/inject: enabled
spec:
template:
metadata:
annotations:
linkerd.io/inject: enabledTemplate 3: Service Profile with Retries
apiVersion: linkerd.io/v1alpha2
kind: ServiceProfile
metadata:
name: my-service.my-namespace.svc.cluster.local
namespace: my-namespace
spec:
routes:
- name: GET /api/users
condition:
method: GET
pathRegex: /api/users
responseClasses:
- condition:
status:
min: 500
max: 599
isFailure: true
isRetryable: true
- name: POST /api/users
condition:
method: POST
pathRegex: /api/users
# POST not retryable by default
isRetryable: false
- name: GET /api/users/{id}
condition:
method: GET
pathRegex: /api/users/[^/]+
timeout: 5s
isRetryable: true
retryBudget:
retryRatio: 0.2
minRetriesPerSecond: 10
ttl: 10sTemplate 4: Traffic Split (Canary)
apiVersion: split.smi-spec.io/v1alpha1
kind: TrafficSplit
metadata:
name: my-service-canary
namespace: my-namespace
spec:
service: my-service
backends:
- service: my-service-stable
weight: 900m # 90%
- service: my-service-canary
weight: 100m # 10%Template 5: Server Authorization Policy
# Define the server
apiVersion: policy.linkerd.io/v1beta1
kind: Server
metadata:
name: my-service-http
namespace: my-namespace
spec:
podSelector:
matchLabels:
app: my-service
port: http
proxyProtocol: HTTP/1
---
# Allow traffic from specific clients
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
name: allow-frontend
namespace: my-namespace
spec:
server:
name: my-service-http
client:
meshTLS:
serviceAccounts:
- name: frontend
namespace: my-namespace
---
# Allow unauthenticated traffic (e.g., from ingress)
apiVersion: policy.linkerd.io/v1beta1
kind: ServerAuthorization
metadata:
name: allow-ingress
namespace: my-namespace
spec:
server:
name: my-service-http
client:
unauthenticated: true
networks:
- cidr: 10.0.0.0/8Template 6: HTTPRoute for Advanced Routing
apiVersion: policy.linkerd.io/v1beta2
kind: HTTPRoute
metadata:
name: my-route
namespace: my-namespace
spec:
parentRefs:
- name: my-service
kind: Service
group: core
port: 8080
rules:
- matches:
- path:
type: PathPrefix
value: /api/v2
- headers:
- name: x-api-version
value: v2
backendRefs:
- name: my-service-v2
port: 8080
- matches:
- path:
type: PathPrefix
value: /api
backendRefs:
- name: my-service-v1
port: 8080Template 7: Multi-cluster Setup
# On each cluster, install with cluster credentials
linkerd multicluster install | kubectl apply -f -
# Link clusters
linkerd multicluster link --cluster-name west \
--api-server-address https://west.example.com:6443 \
| kubectl apply -f -
# Export a service to other clusters
kubectl label svc/my-service mirror.linkerd.io/exported=true
# Verify cross-cluster connectivity
linkerd multicluster check
linkerd multicluster gatewaysMonitoring Commands
# Live traffic view
linkerd viz top deploy/my-app
# Per-route metrics
linkerd viz routes deploy/my-app
# Check proxy status
linkerd viz stat deploy -n my-namespace
# View service dependencies
linkerd viz edges deploy -n my-namespace
# Dashboard
linkerd viz dashboardDebugging
# Check injection status
linkerd check --proxy -n my-namespace
# View proxy logs
kubectl logs deploy/my-app -c linkerd-proxy
# Debug identity/TLS
linkerd identity -n my-namespace
# Tap traffic (live)
linkerd viz tap deploy/my-app --to deploy/my-backendBest Practices
Do's
- Enable mTLS everywhere - It's automatic with Linkerd
- Use ServiceProfiles - Get per-route metrics and retries
- Set retry budgets - Prevent retry storms
- Monitor golden metrics - Success rate, latency, throughput
Don'ts
- Don't skip check - Always run
linkerd checkafter changes - Don't over-configure - Linkerd defaults are sensible
- Don't ignore ServiceProfiles - They unlock advanced features
- Don't forget timeouts - Set appropriate values per route
Related skills
How it compares
Choose linkerd-patterns when a lightweight, security-focused Kubernetes mesh is preferred over heavier mesh platforms with broader feature sets.
FAQ
What Linkerd resources does this skill cover?
ServiceProfile, TrafficSplit, Server, and ServerAuthorization for metrics, canary routing, and access control.
When should I use linkerd-patterns?
When setting up or configuring Linkerd service mesh with mTLS, retries, timeouts, or canary deployments.
Is Linkerd Patterns safe to install?
skills.sh reports 2 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.