---
title: Linkerd OpenTelemetry metrics reference
source: https://docs.newrelic.com/docs/opentelemetry/integrations/linkerd/metrics-reference
---

The Linkerd OTel integration collects metrics by scraping the Linkerd proxy admin port (`:4191`) and control plane pods using the OpenTelemetry Collector's [Prometheus receiver](https://github.com/open-telemetry/opentelemetry-collector-contrib/tree/main/receiver/prometheusreceiver).

## HTTP traffic metrics [#http-metrics]

Emitted by every meshed pod's `linkerd-proxy` sidecar.

**HTTP traffic metrics**

| Metric name                        | Type      | Description                                                                                                               |
| ---------------------------------- | --------- | ------------------------------------------------------------------------------------------------------------------------- |
| `request_total`                    | Counter   | Total HTTP requests received (inbound) or sent (outbound). Facet by `direction`, `target_namespace`, `target_deployment`. |
| `response_total`                   | Counter   | Total HTTP responses. Labels: `classification` (`success`/`failure`), `status_code`.                                      |
| `response_latency_ms_bucket`       | Histogram | HTTP response latency in milliseconds. Use `percentile()` for p50/p95/p99.                                                |
| `response_latency_ms_count`        | Counter   | Count of latency observations (denominator for average latency).                                                          |
| `response_latency_ms_sum`          | Counter   | Sum of latency observations in milliseconds.                                                                              |
| `route_request_total`              | Counter   | Per-route request count. Requires HTTPRoute policies to be configured.                                                    |
| `route_response_total`             | Counter   | Per-route response count with `classification` label. Requires HTTPRoute policies.                                        |
| `route_response_latency_ms_bucket` | Histogram | Per-route response latency. Requires HTTPRoute policies.                                                                  |

## TCP metrics [#tcp-metrics]

**TCP metrics**

| Metric name                         | Type      | Description                                                                   |
| ----------------------------------- | --------- | ----------------------------------------------------------------------------- |
| `tcp_open_connections`              | Gauge     | Current open TCP connections, by `direction` (inbound/outbound).              |
| `tcp_open_total`                    | Counter   | Total TCP connections opened.                                                 |
| `tcp_close_total`                   | Counter   | Total TCP connections closed. Labels: `classification` (`success`/`failure`). |
| `tcp_read_bytes_total`              | Counter   | Total bytes read from TCP connections.                                        |
| `tcp_write_bytes_total`             | Counter   | Total bytes written to TCP connections.                                       |
| `tcp_connection_duration_ms_bucket` | Histogram | TCP connection lifetime in milliseconds.                                      |

## Authorization metrics [#authz-metrics]

**Authorization metrics**

| Metric name                      | Type    | Description                                      |
| -------------------------------- | ------- | ------------------------------------------------ |
| `inbound_http_authz_allow_total` | Counter | HTTP requests allowed by authorization policy.   |
| `inbound_http_authz_deny_total`  | Counter | HTTP requests denied by authorization policy.    |
| `inbound_tcp_authz_allow_total`  | Counter | TCP connections allowed by authorization policy. |
| `inbound_tcp_authz_deny_total`   | Counter | TCP connections denied by authorization policy.  |

## Identity and mTLS metrics [#mtls-metrics]

**Identity and mTLS metrics**

| Metric name                                  | Type    | Description                                                                                               |
| -------------------------------------------- | ------- | --------------------------------------------------------------------------------------------------------- |
| `identity_cert_expiration_timestamp_seconds` | Gauge   | Unix timestamp when the proxy's mTLS certificate expires. Alert when this is less than 24 hours from now. |
| `identity_cert_refresh_count`                | Counter | Number of mTLS certificate refreshes. Sudden drops indicate identity service issues.                      |

## Control plane metrics [#control-plane-metrics]

Emitted by Linkerd control plane pods (`destination`, `identity`, `proxy-injector`).

**Control plane metrics**

| Metric name                          | Type    | Description                                                                                                 |
| ------------------------------------ | ------- | ----------------------------------------------------------------------------------------------------------- |
| `control_plane_live_endpoints`       | Gauge   | Number of live endpoints known to the destination controller. Low values indicate service discovery issues. |
| `control_plane_queue_length`         | Gauge   | Pending work items in the destination controller queue. High values indicate overload.                      |
| `control_plane_updates_queue_depth`  | Gauge   | Depth of the endpoint update queue.                                                                         |
| `proxy_injector_cert_rotation_total` | Counter | Proxy-injector webhook certificate rotations.                                                               |
| `proxy_injector_injection_total`     | Counter | Total proxy injections. Labels: `injected` (true/false), `reason`.                                          |

## Process metrics [#process-metrics]

Standard Prometheus process metrics emitted by each proxy.

**Process metrics**

| Metric name                     | Type    | Description                                                                |
| ------------------------------- | ------- | -------------------------------------------------------------------------- |
| `process_cpu_seconds_total`     | Counter | Total user + system CPU time consumed by the proxy process.                |
| `process_resident_memory_bytes` | Gauge   | Resident set size (RSS) of the proxy process in bytes.                     |
| `process_virtual_memory_bytes`  | Gauge   | Virtual memory size of the proxy process.                                  |
| `process_open_fds`              | Gauge   | Number of open file descriptors. High values can indicate connection leak. |
| `process_uptime_seconds_total`  | Counter | Seconds since the proxy process started.                                   |

## Default-off metrics [#default-off]

The following metric groups are disabled by default in the optimized collector config to reduce ingest volume. Remove the corresponding condition from `filter/drop_unused` to re-enable.

> #### 💡 TIP
>
> These groups are off by default because they provide no operational value in steady state. Enable them only when actively debugging the specific issue described.

**Default-off metrics**

| Group                  | Metrics                                                                                 | Re-enable when                   |
| ---------------------- | --------------------------------------------------------------------------------------- | -------------------------------- |
| Version/build info     | `rustls_info`, `proxy_build_info`                                                       | Never                            |
| Prometheus scraper     | `scrape_series_added`, `scrape_duration_seconds`, `scrape_samples_*`                    | Initial collector setup          |
| Proxy stack internals  | `stack_poll_total`, `stack_create_total`, `stack_drop_total`, `stack_poll_total_ms`     | Proxy CPU/overload investigation |
| Tokio async runtime    | `tokio_rt_*`                                                                            | Proxy CPU starvation             |
| HTTP frame sizes       | `*_http_*_frame_size_bytes`, `outbound_http_route_request_frame_size_bytes`             | Large-payload debugging          |
| TCP protocol detection | `inbound_tcp_detect_http_duration_seconds`, `outbound_tcp_detect_http_duration_seconds` | Protocol detection failures      |
| TCP balancer queue     | `outbound_tcp_balancer_queue_*`                                                         | Outbound TCP backpressure        |

## Resource attributes [#resource-attributes]

These attributes are added to every metric by the OTel Collector and can be used as FACET or WHERE filters.

### Common attributes [#common-attributes]

**Common attributes**

| Attribute                  | Description                                                                  |
| -------------------------- | ---------------------------------------------------------------------------- |
| `instrumentation.provider` | Always `opentelemetry`                                                       |
| `k8s.cluster.name`         | Kubernetes cluster name, set via `OTEL_RESOURCE_ATTRIBUTES` env var          |
| `k8s.namespace.name`       | Namespace of the meshed pod                                                  |
| `k8s.pod.name`             | Name of the meshed pod                                                       |
| `k8s.deployment.name`      | Deployment that owns the pod (derived from pod name if not emitted natively) |
| `k8s.node.name`            | Kubernetes node running the pod                                              |

### Linkerd-specific attributes [#linkerd-specific-attributes]

**Linkerd-specific attributes**

| Attribute                         | Description                                                                                                                                  |
| --------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `linkerd_control_plane_ns`        | Namespace where Linkerd control plane is installed (e.g. `linkerd`). Present on all meshed pods. Used as the entity synthesis discriminator. |
| `linkerd_control_plane_component` | Control plane component name (`destination`, `identity`, `proxy-injector`).                                                                  |

### kube-state-metrics attributes [#kube-state-metrics-attributes]

These attributes are added only to metrics scraped from kube-state-metrics.

**kube-state-metrics attributes**

| Attribute             | Description                     |
| --------------------- | ------------------------------- |
| `k8s.deployment.name` | Deployment name from KSM labels |
| `k8s.pod.name`        | Pod name from KSM labels        |
| `k8s.node.name`       | Node name from KSM labels       |

## Related articles [#related-articles]

[Linkerd distributed tracing with OpenTelemetry](https://docs.newrelic.com/docs/opentelemetry/integrations/linkerd/distributed-tracing)

Enable proxy trace export and instrument your application pods to correlate mesh spans with APM traces.

[Collect Linkerd proxy logs](https://docs.newrelic.com/docs/opentelemetry/integrations/linkerd/proxy-logs)

Optionally collect `linkerd-proxy` sidecar container logs.

[Find and query your data](https://docs.newrelic.com/docs/opentelemetry/integrations/linkerd/find-data)

Dashboard walkthrough, NRQL queries, and troubleshooting steps.
