• /
  • EnglishEspañolFrançais日本語한국어Português
  • 로그인지금 시작하기

Linkerd distributed tracing with OpenTelemetry

|View as Markdown (English)

Linkerd 2.19 and later can export a span for every proxied request directly from the mesh sidecar, with no extra tracing backend or cert-manager setup required. Combined with instrumented application pods, these proxy spans connect into end-to-end traces that show exactly how a request moved through your mesh.

How it works

Enabling tracing has two parts:

  1. Mesh-level trace export: The Linkerd proxies export a span per request to your OTel Collector. This alone gives you proxy-level traces (retries, mTLS handshakes, latency per hop) without touching your application.
  2. Application instrumentation: Your app pods propagate the same W3C trace context the proxies use, and export their own spans. Combining both gives you a full waterfall in the same trace: from the client app, through the Linkerd proxy, to the backend app.

Before you begin

Ensure you have:

Set up distributed tracing

As of Linkerd 2.19, proxy trace export is configured directly in the control plane, with no cert-manager or separate port required. Two steps are required: make the collector able to receive traces, then turn on trace export from the proxies.

Step 1: Add trace ingestion to the collector

Unlike the NRDOT chart, the community open-telemetry/opentelemetry-collector chart doesn't include an otlp receiver by default. Add it explicitly, along with the same processors used on the NRDOT tab.

Step 2: Enable proxy trace export

1. Mesh the collector. Linkerd proxies can only export traces to a collector that is itself inside the mesh. Unlike the NRDOT chart's nr-k8s-otel-collector-gateway, nothing in the OTel Collector Contrib manifest or Helm chart injects the collector pod into the mesh by default:

bash
$
kubectl annotate namespace newrelic linkerd.io/inject=enabled
$
kubectl rollout restart deployment/my-opentelemetry-collector -n newrelic

중요

The meshIdentity stanza below is mandatory. Linkerd can only export traces to a collector that is inside the mesh, which is what the command above just did.

2. Enable tracing on the Linkerd proxies:

Step 3: Restart your application's meshed pods

This is separate from the collector restart in Step 2 - it applies the new proxy tracing config to the pods you're actually tracing:

bash
$
kubectl rollout restart deployment -n <YOUR_NAMESPACE>

Instrument your application pods

Add the OTel Java agent (or the agent for your language) to propagate trace context headers. Linkerd supports both W3C Trace Context and B3 formats. The OTel agent handles this automatically.

팁

spec.exporter.endpoint below points at the OTel Collector Contrib with manifest page's Service. If you deployed the NRDOT collector, use http://nr-k8s-otel-collector-gateway.newrelic.svc.cluster.local:4317 instead.

For other languages (Python, .NET, Node.js, Go) and advanced Operator configuration, such as sidecar vs. init-container injection, resource limits, or multi-container pods, see the OpenTelemetry Operator automatic instrumentation docs.

Correlate app metrics with APM (optional)

If your app also exports OTel SDK metrics (not just traces) to the collector, add the following to route them into an APM-compatible metrics pipeline.

Processors to add:

metricstransform/apm_compat:
transforms:
- include: http.server.request.duration
action: insert
new_name: apm.service.transaction.duration

Pipelines to add:

metrics/otlp:
receivers: [otlp]
processors: [memory_limiter, resourcedetection, transform/metadata_nullify, metricstransform/apm_compat, batch]
exporters: [otlp_http/newrelic]

Add both to whichever collector config you deployed, then re-apply it:

If you deployedAdd it toRe-apply with
NRDOT - Helmdeployment.configMap.extraConfig in your values.yamlhelm upgrade nr-k8s-otel-collector newrelic/nr-k8s-otel-collector --namespace newrelic --reuse-values -f values.yaml
NRDOT - Manifestdeployment-configmap.yamlkubectl apply -f rendered/deployment-configmap.yaml -n newrelic && kubectl rollout restart deployment -n newrelic
OTel Collector Contrib - Helmthe config section of your values.yamlhelm upgrade my-opentelemetry-collector open-telemetry/opentelemetry-collector -f values.yaml -n newrelic --create-namespace --install
OTel Collector Contrib - Manifestthe config key of the ConfigMap in otel-collector.yamlkubectl apply -f otel-collector.yaml && kubectl rollout restart deployment/my-opentelemetry-collector -n newrelic

Collect Linkerd proxy logs

Optionally collect linkerd-proxy sidecar container logs.

Metrics reference

Full list of Linkerd metrics and resource attributes collected by the OTel Collector.

Find and query your data

Dashboard walkthrough, NRQL queries, and troubleshooting steps.

Copyright © 2026 New Relic Inc.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.