The Linkerd OTel integration collects metrics by scraping the Linkerd proxy admin port (:4191) and control plane pods using the OpenTelemetry Collector's Prometheus receiver.
HTTP traffic metrics
Emitted by every meshed pod's linkerd-proxy sidecar.
Metric name
Type
Description
request_total
Counter
Total HTTP requests received (inbound) or sent (outbound). Facet by direction, target_namespace, target_deployment.
response_total
Counter
Total HTTP responses. Labels: classification (success/failure), status_code.
response_latency_ms_bucket
Histogram
HTTP response latency in milliseconds. Use percentile() for p50/p95/p99.
response_latency_ms_count
Counter
Count of latency observations (denominator for average latency).
response_latency_ms_sum
Counter
Sum of latency observations in milliseconds.
route_request_total
Counter
Per-route request count. Requires HTTPRoute policies to be configured.
route_response_total
Counter
Per-route response count with classification label. Requires HTTPRoute policies.
Current open TCP connections, by direction (inbound/outbound).
tcp_open_total
Counter
Total TCP connections opened.
tcp_close_total
Counter
Total TCP connections closed. Labels: classification (success/failure).
tcp_read_bytes_total
Counter
Total bytes read from TCP connections.
tcp_write_bytes_total
Counter
Total bytes written to TCP connections.
tcp_connection_duration_ms_bucket
Histogram
TCP connection lifetime in milliseconds.
Authorization metrics
Metric name
Type
Description
inbound_http_authz_allow_total
Counter
HTTP requests allowed by authorization policy.
inbound_http_authz_deny_total
Counter
HTTP requests denied by authorization policy.
inbound_tcp_authz_allow_total
Counter
TCP connections allowed by authorization policy.
inbound_tcp_authz_deny_total
Counter
TCP connections denied by authorization policy.
Identity and mTLS metrics
Metric name
Type
Description
identity_cert_expiration_timestamp_seconds
Gauge
Unix timestamp when the proxy's mTLS certificate expires. Alert when this is less than 24 hours from now.
identity_cert_refresh_count
Counter
Number of mTLS certificate refreshes. Sudden drops indicate identity service issues.
Control plane metrics
Emitted by Linkerd control plane pods (destination, identity, proxy-injector).
Metric name
Type
Description
control_plane_live_endpoints
Gauge
Number of live endpoints known to the destination controller. Low values indicate service discovery issues.
control_plane_queue_length
Gauge
Pending work items in the destination controller queue. High values indicate overload.
control_plane_updates_queue_depth
Gauge
Depth of the endpoint update queue.
proxy_injector_cert_rotation_total
Counter
Proxy-injector webhook certificate rotations.
proxy_injector_injection_total
Counter
Total proxy injections. Labels: injected (true/false), reason.
Process metrics
Standard Prometheus process metrics emitted by each proxy.
Metric name
Type
Description
process_cpu_seconds_total
Counter
Total user + system CPU time consumed by the proxy process.
process_resident_memory_bytes
Gauge
Resident set size (RSS) of the proxy process in bytes.
process_virtual_memory_bytes
Gauge
Virtual memory size of the proxy process.
process_open_fds
Gauge
Number of open file descriptors. High values can indicate connection leak.
process_uptime_seconds_total
Counter
Seconds since the proxy process started.
Default-off metrics
The following metric groups are disabled by default in the optimized collector config to reduce ingest volume. Remove the corresponding condition from filter/drop_unused to re-enable.
Sugerencia
These groups are off by default because they provide no operational value in steady state. Enable them only when actively debugging the specific issue described.