August 5, 2026
- Fixed an issue in
namespace-metadatawhere it could overwrite existing labels and annotations on thelinkerd-buoyantnamespace.
The Buoyant Extension is an aggregate package that includes the Linkerd lifecycle automation operator, the Buoyant Cloud agent, and certain BEL-specific linkerd CLI features.
namespace-metadata where it could overwrite existing
labels and annotations on the linkerd-buoyant namespace.buoyant-cloud-metrics to
Grafana Alloy v1.18.0.namespace-metadata where it could fail due to insufficient
RBAC permissions on the linkerd-buoyant namespace.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.google.golang.org/grpc to remediate
GHSA-hrxh-6v49-42gf.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.buoyant-cloud-metrics to
Grafana Alloy v1.17.1.buoyant-cloud-metrics’s cadvisor scrape
job.buoyant-cloud-agent now automatically sets GOMEMLIMIT based on its
container’s memory limit.buoyant-cloud-agent connectivity to address “Agent not responding”
alerts.buoyant-cloud-agent to remediate
CVE-2026-39822,
CVE-2026-42505,
GHSA-fxhp-mv3v-67qp,
GO-2026-4970, and
GO-2026-5856.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.buoyant-cloud-metrics to
Grafana Alloy v1.17.0.buoyant-cloud-agent to remediate
GHSA-jpcc-p29g-p8mq and
GHSA-xhf5-7wjv-pqxp.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.buoyant-cloud-metrics to
Grafana Alloy v1.16.3.buoyant-cloud-metrics scrape config for Linkerd 2.20 release.metrics.maxShards Helm value for buoyant-cloud-metrics, to
configure maximum amount of concurrent remote_write queues.buoyant-cloud-agent to improve gRPC stream reliability and memory
usage.linkerd-data-plane-operator for the trust-anchor rotation
operator (to be released in BEL 2.20), providing automated, GitOps-friendly
trust anchor rotation, configurable via
dataPlaneOperator.acceleratedWorkloadCertRenewal.buoyant-cloud-agent for the trust-anchor rotation operator,
to send data to Buoyant Cloud.linkerd-control-plane-operator to honor HELM_MAX_HISTORY for BEL
upgrades (default 10).buoyant-cloud-metrics to remediate
CVE-2026-27143,
GHSA-p77j-4mvh-x3m3,
GO-2026-4550,
GO-2026-4762,
GO-2026-5005,
GO-2026-5006,
GO-2026-5017,
GO-2026-5019,
GO-2026-5020,
GO-2026-5021,
GO-2026-5023, and
GO-2026-5026.buoyant-cloud-agent to remediate
CVE-2026-27145,
CVE-2026-42504,
CVE-2026-42507,
GO-2026-5005,
GO-2026-5006,
GO-2026-5013,
GO-2026-5014,
GO-2026-5015,
GO-2026-5016,
GO-2026-5017,
GO-2026-5018,
GO-2026-5019,
GO-2026-5020,
GO-2026-5021,
GO-2026-5023,
GO-2026-5025,
GO-2026-5026,
GO-2026-5027,
GO-2026-5028,
GO-2026-5029,
GO-2026-5030,
GO-2026-5033,
GO-2026-5037,
GO-2026-5038, and
GO-2026-5039.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.buoyant-cloud-agent to mitigate stale
connections.buoyant-cloud-agent to remediate
CVE-2026-33811,
CVE-2026-33814,
CVE-2026-39817,
CVE-2026-39819,
CVE-2026-39820,
CVE-2026-39823,
CVE-2026-39825,
CVE-2026-39826,
CVE-2026-39836,
CVE-2026-42499,
CVE-2026-42501, and
GHSA-fqw6-gf59-qr4w.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.buoyant-cloud-agent to remediate
CVE-2026-25679,
CVE-2026-27137,
CVE-2026-27138,
CVE-2026-27140,
CVE-2026-27142,
CVE-2026-27143,
CVE-2026-27144,
CVE-2026-32280,
CVE-2026-32281,
CVE-2026-32282,
CVE-2026-32283,
CVE-2026-32288,
CVE-2026-32289,
CVE-2026-33810,
GHSA-hfvc-g4fc-pqhx,
GHSA-hr2v-4r36-88hr,
GHSA-mh2q-q3fh-2475,
GHSA-p77j-4mvh-x3m3, and
GHSA-pc3f-x583-g7j2.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.namespaceMetadata.kubernetesApiSvcAddr Helm value, to customize
the address of the Kubernetes API server.buoyant-cloud-agent to remediate
CVE-2025-61726,
CVE-2025-61728,
CVE-2025-61730,
CVE-2025-61731,
CVE-2025-61732,
CVE-2025-68119,
CVE-2025-68121, and
GHSA-9h8m-3fm2-qjrq.buoyant-cloud-metrics to v0.44.8 to remediate
CVE-2024-10963,
CVE-2025-6297,
CVE-2025-8058,
CVE-2025-9230,
CVE-2025-9820,
CVE-2025-13151,
CVE-2025-14831,
CVE-2025-15281,
CVE-2025-15467,
CVE-2025-47912,
CVE-2025-58183,
CVE-2025-58185,
CVE-2025-58186,
CVE-2025-58187,
CVE-2025-58188,
CVE-2025-58189,
CVE-2025-61723,
CVE-2025-61724,
CVE-2025-61725,
CVE-2025-61726,
CVE-2025-61727,
CVE-2025-61728,
CVE-2025-61729,
CVE-2025-61730,
CVE-2025-61731,
CVE-2025-61732,
CVE-2025-68121,
CVE-2025-68160,
CVE-2025-68973,
CVE-2025-69418,
CVE-2025-69419,
CVE-2025-69420,
CVE-2025-69421,
CVE-2026-0861,
CVE-2026-0915,
CVE-2026-22795,
CVE-2026-22796,
GHSA-9mj6-hxhv-w67j,
GHSA-cfpf-hrx2-8rv6,
GHSA-f6x5-jh6r-wrfv, and
GHSA-j5w8-q4qc-rx2x.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.buoyant-cloud-metrics to collect linkerd-multicluster metrics for
BEL 2.19.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.buoyant-cloud-agent to send updates on initContainer changes,
including native sidecar updates.buoyant-cloud-agent to include initContainers in Control Plane
Diagnostic bundles, including native sidecars.containerd dependency to v1.7.29 to remediate
GHSA-m6hq-p25p-ffr2 and
GHSA-pwhc-rpq9-4c8w.crypto dependency to v0.45.0 to remediate
GHSA-f6x5-jh6r-wrfv and
GHSA-j5w8-q4qc-rx2x.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.controlPlaneValidator.resources.memory.limit from 200Mi
to 400Mi.metrics-agent scrape config to collect from new 2.19 Linkerd
control-plane ports.metrics-agent config to skip the Linkerd proxy on outbound port 443.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.--reuse-values could prevent an upgrade.v1.33.4 to remediate
GHSA-4x4m-3c2p-qppc.v3.18.5 to remediate
GHSA-f9f8-9pmf-xv68, and
GHSA-9h84-qmv7-982p.buoyant-cloud-metrics to v0.44.4 to remediate
CVE-2025-22871.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.golang.org/x/oauth2 to 0.29.0 to remediate
CVE-2025-22868v3.17.4 to remediate
GHSA-557j-xg8c-q2mm.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.linkerd-control-plane-operator to support latest BEL and edge
releases. View all supported versions for this release.linkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.metadata.namespace fields.k8s.io/kubernetes to v1.32.2 to remediate
GHSA-jgfp-53c3-624wlinkerd-control-plane-operator to support latest BEL and edge
releases. View all supported versions for this release.buoyant-cloud-metrics to v0.44.2 to remediate
GHSA-v725-9546-7q7m and
GHSA-v778-237x-gjrclinkerd-control-plane-operator to support latest BEL releases.
View all supported versions for this release.opencontainers labels to the linkerd-buoyant image.buoyant-cloud-metrics to v0.43.4.curl image to 8.11.1.metrics-agent-init container from bash to busybox.linkerd-control-plane-operator to support latest BEL and edge
releases. View all supported versions for this release.metrics.updateStrategy Helm value to allow customization of the
buoyant-cloud-metrics DaemonSet update strategy.linkerd-control-plane-operator to support latest BEL and edge
releases. View all supported versions for this release.linkerd-control-plane-operator to support latest BEL and edge
releases. View all supported versions for this release.buoyant-cloud-metrics to v0.43.3.buoyant-cloud-metrics config to collect new HAZL-aware
outbound_tcp_transfer_cost_bytes_total metric, available in edge-24.10.3.ControlPlane CRD fields in favor of new counterparts. The
deprecated fields will continue to work for several more releases:spec.components.linkerd.license =>
spec.components.linkerd.controlPlaneConfig.licensespec.components.linkerd.licenseSecret =>
spec.components.linkerd.controlPlaneConfig.licenseSecretspec.components.linkerd.manageExternalWorkloads =>
spec.components.linkerd.crdsConfig.manageExternalWorkloads and
spec.components.linkerd.controlPlaneConfig.manageExternalWorkloadslinkerd-control-plane-operator to support latest edge releases.
View all supported versions for this release.buoyant-cloud-metrics to v0.42.0.enterprise-2.16.0 was already installed.linkerd-control-plane-operator to support latest edge, enterprise,
and hotpatch releases. View all supported versions for this release.buoyant diagnostics
CLI command.buoyant-cloud-agent to start sending information about CRDs that
were newly added in
Linkerd 2.16 to Buoyant
Cloud.linkerd-control-plane-operator to support latest edge, enterprise,
and hotpatch releases. View all supported versions for this release.linkerd-cni extension is installed.import-helm-config CLI
command to not require identityTrustAnchorsPEM when externalCA is set.linkerd-control-plane-operator to support latest edge and patch
releases. View all supported versions for this release.linkerd-data-plane-operator to support restarting proxies running in
native sidecar containers.buoyant-cloud-agent to fix a serialization issue with v1beta1
Server resources on Linkerd 2.14 clusters.golang.org/x/net dependency to remediate
CVE-2023-45288.linkerd-control-plane-operator to support up to enterprise-2.15.2.
View all supported versions for this release.licenseSecret Helm value to allow users to provide their Buoyant
License via a Kubernetes secret.additionalVolumes and additionalVolumeMounts Helm values to allow
users to mount additional volumes and volumeMounts to any Buoyant Extension
container.spec.components.linkerd.licenseSecret field to the Managed Linkerd
ControlPlane CRD, to allow users to provide their Buoyant License via a
Kubernetes secret.linkerd-buoyant check CLI output to check the
linkerd-control-plane-validator workload, and also point to new doc
versions.github.com/docker/docker dependency to remediate
CVE-2024-21626 and
CVE-2024-24557github.com/golang/protobuf dependency to remediate
CVE-2024-24786google.golang.org/grpc dependency to remediate
CVE-2023-44487linkerd-control-plane-operator not supporting dynamic updates of
enterprise patch releases in some cases.linkerd-control-plane-operator to give all users access to dynamic
updates to the latest Linkerd versions, not just Buoyant Cloud customers.linkerd-control-plane-operator to support up to enterprise-2.15.1.
View all supported versions for this release.linkerd-control-plane-operator to support up to enterprise-2.15.0,
or enterprise-2.15.1 when Buoyant Cloud is installed.
View all supported versions for this release.linkerd-control-plane-operator support for enterprise-2.15 releases.
Unlike enterprise-2.14.10-0, enterprise-2.15 is hosted publicly, and no
longer requires the controlPlaneOperator.helmRepoPrefix and
controlPlaneOperator.helmDockerConfigJSONSecret values.linkerd-control-plane-operator to support up to
enterprise-2.14.9-3. View all supported versions for this release.linkerd-control-plane-operator to support up to
enterprise-2.14.9-1, or enterprise-2.14.9-3 when Buoyant Cloud is
installed. View all supported versions for this release.linkerd-control-plane-operator support for managed upgrades to the new
Buoyant Enterprise for Linkerd preview channel, along with managed
downgrades from preview to enterprise.linkerd-control-plane-operator to support up to
enterprise-2.14.8-1, or enterprise-2.14.9-1 when Buoyant Cloud is
installed. View all supported versions for this release.linkerd-control-plane-operator support for the new Buoyant Enterprise
for Linkerd preview channel. Note: The operator does not currently support
migration to/from the preview channel, only fresh installations.linkerd-control-plane-operator to support up to
enterprise-2.14.7-0, or enterprise-2.14.8-0 when Buoyant Cloud is
installed. View all supported versions for this release.spec.components.linkerd.crdsConfig field to the Managed Linkerd
ControlPlane CRD, to allow configuring linkerd-crds.linkerd-control-plane-operator to support up to
enterprise-2.14.6-0. View all supported versions for this release.linkerd-control-plane-operator to support up to
enterprise-2.14.5-1. View all supported versions for this release.controlPlaneOperator.helmRepoPrefix to allow overriding the
default Buoyant Enterprise for Linkerd Helm registry.controlPlaneOperator.helmNoTLS to allow disabling TLS when
fetching Buoyant Enterprise for Linkerd Helm charts.ControlPlane custom resource ergonomics when installing a
FIPS-enabled Buoyant Enterprise for Linkerd control plane.buoyant-cloud-agent, linkerd-control-plane-operator, and
linkerd-data-plane-operator to better abide by cpu and memory limits, via
automaxprocs.linkerd-control-plane-operator to support up to
enterprise-2.14.1-2, or enterprise-2.14.5-1 when Buoyant Cloud is
installed. View all supported versions for this release.metrics.debugMetrics to enable sending additional debug
metrics to Buoyant.buoyant-cloud-metrics to v0.35.4.buoyant-cloud-metrics could consume excessive memory
when the Linkerd Destination controller exported many server_port_subscribes
metrics.linkerd namespace.linkerd-control-plane-operator now that requires Linkerd’s Helm releases
conform to the default linkerd-crds and linkerd-control-plane names. Users
with non-default Helm release names may run
linkerd-buoyant controlplane migrate-helm-release to migrate.linkerd-control-plane-operator to support up to edge-23.10.3,
stable-2.14.1, and enterprise-2.14.1-2ControlPlane Custom Resources via ArgoCD.controlPlaneOperator.extendedRBAC.enabled, default
changed from true to false. This flag should only be enabled for clusters
with Linkerd 2.12 or below.linkerd.namespace, linkerdJaeger.namespace, and
linkerdMulticluster.namespace--enable-pprof debug flag, defaulted to false, on
buoyant-cloud-agent, linkerd-control-plane-operator, and
linkerd-data-plane-operatorbuoyant-cloud-agent to send TLS certs from webhook secretsbuoyant-cloud to
linkerd-buoyant namespace. Please follow these
one-time migration instructions.linkerd-control-plane-operator to support up to edge-23.9.4,
stable-2.13.7, and enterprise-2.13.6-2linkerd-buoyant migrate-helm-release CLI subcommand, to aide in
migration to a Managed Linkerd installation.enterprise-2.13.6-1controlPlaneOperator.helmDockerConfigJSONSecret, for
Buoyant enterprise registry accessbuoyantCloudEnabled, default true . When set to false,
disable buoyant-cloud-agent, buoyant-cloud-metrics, all communication with
Buoyant Cloudlinkerd-buoyant CLI where it may fail to read
KUBECONFIGlinkerd-control-plane-operator to support up to stable-2.13.6 and
edge-23.8.3linkerd-control-plane-operator to require a controlPlaneConfig
field on all ControlPlane Custom Resources. This ensures the ControlPlane
CR is the ground source of truth for the Linkerd installation. This is a
breaking change and will require modifying existing ControlPlane Custom
Resources.linkerd-control-plane-validator component, to validate
ControlPlane Custom Resources are well-formed.linkerd-buoyant controlplane import-helm-config CLI command, to
assist in migrating from an existing Helm or ControlPlane -based Linkerd
installation to a new ControlPlane CR with a controlPlaneConfig field.resources Helm config fields to support configuring memory and CPU
requests and limitslinkerd-control-plane-operator to disallow skipping major versions
during upgrades and downgradeslinkerd-control-plane-operator to support up to edge-23.7.2HTTPRoute resources from the Gateway
APIHTTPRoute resources
from LinkerdstartupProbe
Helm valuesyncTimeout Helm value — useful for installing the agent on large clusterslogFormat Helm valuelinkerd-control-plane-operator to support up to edge-23.6.3 and
stable-2.13.5buoyant-cloud-metrics to start collecting outbound TCP write metricslinkerd-data-plane-operator to work with Argo RolloutsHTTPRoute resources to support all versions
up to v1beta3linkerd-control-plane-operator to support up to edge-23.5.3 and
stable-2.13.3linkerd-control-plane-operator to support up to edge-23.4.3 and
stable-2.12.5linkerd-control-plane-operator RBAC failure when Linkerd was installed
with PodMonitor--no-tls flag from the install commandlinkerd-data-plane-operator to work with custom Linkerd proxysecurityContext on initContainers in buoyant-cloud-agent and
buoyant-cloud-metricslinkerd-data-plane-operatoraffinityimagePullSecretslimit and requesttolerationspriorityClassName (buoyant-cloud-metrics only)linkerd-control-plane-operator to support up to edge-23.3.2 and
stable-2.12.4buoyant-cloud-agentcontrolPlaneOperator.enabled : Enable/disable
linkerd-control-plane-operatordataPlaneOperator.enabled : Enable/disable linkerd-data-plane-operatorfreeTier : Install the agent with limited free-tier featuresmanaged : Enable/disable managed features. Deprecated in favor of
controlPlaneOperator.enabled and dataPlaneOperator.enabledlinkerd-control-plane-operator to support up to edge-23.3.1 and
stable-2.12.4linkerd-data-plane-operatorlinkerd-control-plane-operator to support up to edge-22.12.1 and
stable-2.12.4linkerd-control-plane-operator failing to upgrade the Linkerd control
plane if a SelfSubjectRulesReview check encountered an authorizer on the
cluster that did not support rules evaluationbuoyant-cloud-metrics-agent to collect and send Linkerd control
plane metrics to Buoyant Cloudbuoyant-cloud-agent to send Pod updates if the status of any
container in the pod changes. This allows tracking the full lifecycle of
containers.ghcr.io/buoyantioghcr.io/buoyantio/linkerd-buoyant from
debian:bullseye-20221024-slim base image to scratchbuoyant-cloud-metrics-agent base Docker image to resolve OpenSSL
vulnerabilities
CVE-2022-3602 and
CVE-2022-3786. While the
vulnerable version of OpenSSL was not used by the running container, its
inclusion in the base image was being reported by security scanners
nonetheless. This has been fixed.linkerd-control-plane-operator to support up to edge-22.12.1 and
stable-2.12.2linkerd-control-plane-operator and linkerd-data-plane-operator to
emit Kubernetes events, and updated buoyant-cloud-agent to send these events
to Buoyant Cloudlinkerd-control-plane-operator to support edge-22.10.1,
edge-22.10.2, and stable-2.12.2buoyant-cloud-agent not collecting trust root information from some
Linkerd control plane componentslinkerd-control-plane-operator unnecessarily toggling between
Updating and Pending statesstable-2.11.5, stable-2.12.0,
and edge-22.9.2linkerd-buoyant check command to verify CRD existenceControlPlane custom resources with an empty
status fieldHTTPRoute gathering for Buoyant Cloudbuoyant-cloud-org-credentials secretlinkerd-buoyant check to validate linkerd-control-plane-operator
and linkerd-data-plane-operator workloadslinkerd-buoyant check to warn rather than fail on missing labels on
the buoyant-cloud-org-credentials secretbuoyant-cloud-org-credentials
secretstable-2.12.0managed : trueextendedRBAC.enabled : truestable-2.12.0-rc2ControlPlane and DataPlane
resources that previously existed on your clusteredge-22.8.2ControlPlane CRD’s lastUpdateAttempt and lastUpdateAttemptMessage
fields not always updatingstable-2.11.4 and edge-22.7.3edge-22.6.2edge-22.6.1edge-22.5.2 and edge-22.5.3ControlPlaneUpdate => ControlPlaneDataPlaneUpdate => DataPlanestable-2.10.x => edge upgrade pathsstable-2.10.xedge-22.5.1