Buoyant Enterprise for Linkerd is a production-ready distribution of the Linkerd service mesh that provides critical security and reliability features to Kubernetes applications.
Buoyant Enterprise for Linkerd is a production-ready distribution of the popular Linkerd service mesh, from Buoyant, the creators of Linkerd. BEL provides critical security, reliability, and observability features to Kubernetes applications without requiring any code changes, including mutual TLS (encryption in transit, authentication, workload identities), transparent multi-cluster communication and cluster failover, zero-trust traffic authorization policies, Gateway API conformance, and much more.
Linkerd is the only service mesh to provide a low-overhead, ultrafast implementation in Rust. Unlike other service meshes which rely on complex and buggy C++ proxies, Linkerd's unique microproxy approach is truly zero-trust compatible, maximizing your security posture while minimizing your cost of operations.
BEL is a hardened distribution of the open source Linkerd service mesh that includes additional tools, features, security enhancements, and support, all designed for sustained production use in mission-critical applications.
Highlights
Zero trust security. Linkerd enables true zero trust security in your Kubernetes applications, ensuring all microservices, APIs, and data communications are not just encrypted but authenticated. Protect your applications against internal and external threats with robust security features, including mutual TLS and fine-grained automated policy enforcement.
Cost optimization: Dramatically reduce cloud spend in multi-AZ Kubernetes clusters with High Availability Zone-aware Routing, a unique feature in Buoyant Enterprise for Linkerd that prioritizes in-AZ routing to reduce cross-zone data transfer costs. Unlike Kubernetes's native Topology-Aware Routing, BEL does not sacrifice reliability and is able to gracefully recover from single-zone failures.
Multi-cluster and DR: Seamlessly manage and secure services across multiple Kubernetes clusters with built-in multicluster support that is fully transparent to the application. Deploy advanced traffic management techniques including powerful disaster recovery tooling to ensure your system is always available.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You pay for this service mesh based on usage, billed by container hours. A container hour counts each hour a container runs with the software active. Your cost scales directly with how many containers you run and how long they run. There are no fixed tiers or seat counts on this listing. As you add more containers or run them longer, your total hours rise. As you scale down, your billed hours drop. This single usage dimension keeps billing tied to actual runtime across your Kubernetes clusters.
Top-of-mind questions for buyers
What counts as one container hour for billing?
A container hour counts each hour that one container runs with the software's data plane proxy active. Each meshed container is metered separately. If you run several containers at once, their hours add together. Containers not meshed with the software do not accrue hours.
Am I charged for containers that are stopped or not yet meshed?
Charges accrue only while a container runs with the software's proxy injected. Stopped containers do not add hours. Containers you install but have not meshed also do not accrue software hours, since the proxy is not active on them yet.
Which product features come with this usage-based container hour billing?
Container hour billing covers the hardened service mesh distribution. This includes zero-trust network security with mutual TLS, latency-aware load balancing, retries, timeouts, circuit breaking, multi-cluster communication, and L7 traffic routing. Lifecycle automation for installs and upgrades is also included with the runtime.
docs.buoyant.io+2
Helpful?
Vendor refund policy
Buoyant does not offer refunds.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Buoyant Enterprise for Linkerd Premium Support includes 24x5 access to Linkerd's technical experts through Buoyant's Enterprise Support Portal.
With BEL, getting help is just a click away. Skip the complicated phone trees and canned bot responses - receive hands-on technical support directly from Linkerd's global team of product support engineers and maintainers.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Provides mutual TLS encryption in transit with authentication and workload identities for Kubernetes applications without requiring code changes
Zero-Trust Traffic Authorization
Implements fine-grained automated zero-trust traffic authorization policies for microservices and API communications
Availability Zone-Aware Routing
Supports High Availability Zone-aware routing that prioritizes in-AZ routing to reduce cross-zone data transfer costs while maintaining reliability during single-zone failures
Rust-Based Microproxy Architecture
Implements a low-overhead ultrafast microproxy approach written in Rust for reduced operational overhead compared to C++ proxy-based service meshes
Multi-Cluster Lifecycle Management
Enables lifecycle management and blueprinting support for managed Kubernetes services including Amazon EKS, Azure AKS, Rancher, and RedHat OpenShift across multiple regions and accounts.
GitOps-Based Infrastructure Orchestration
Supports infrastructure orchestration and application deployment through multi-stage, git-triggered pipelines for automated workflows.
Zero-Trust Access Control
Provides controlled and audited access to Kubernetes infrastructure with just-in-time service account creation and user-level credentials management for developers, SREs, and automation systems.
Policy Management via Open Policy Agent
Implements Kubernetes security and governance through policy management using the Open Policy Agent (OPA) framework for cluster-wide policy enforcement.
Disaster Recovery and Migration
Enables backup and restore capabilities for Kubernetes control plane and application data to support disaster recovery and cluster migration scenarios.
Unified Control Plane Management
Single management console to manage Kong Gateway, Kong AI Gateway, Kong Ingress Controller, and Kong Mesh across multiple deployments and zones.
API Lifecycle Management
Capabilities to make APIs discoverable, consumable, and reusable through API Products bundling, Dev Portal with documentation and testing, and Service Hub for service inventory.
Zero-Trust Security Framework
Implementation of zero-trust security protocols, authentication policies, and access management with operational insights into security-related events and usage patterns.
Multi-Gateway Monitoring and Catalog
Gateway Manager functionality to catalog, connect to, and monitor the status of all control planes and data plane nodes in a single interface.
Analytics and Observability
Deep insights into service, route, and application usage with health monitoring data and observability capabilities across managed infrastructure.
Simple deployment has secured service-to-service traffic and reduced operational effort
Reviewed on Apr 30, 2026
Review provided by PeerSpot
What is our primary use case?
Buoyant Enterprise for Linkerd has made it simple for us to deploy and operate Linkerd across our clusters.
The setup process is lightweight, and having mTLS enabled has been a major benefit for securing service-to-service communication without extra complexity.
Overall, it has been an easy way to get a reliable service mesh in place.
How has it helped my organization?
Linkerd is easy to deploy with minimal configuration.
What is most valuable?
Linkerd is lightweight and easy to roll out.
We have spent far less time on setup and ongoing maintenance.
That simplicity has been the biggest improvement for us and one less component to worry about in our Kubernetes environment.
What needs improvement?
We are eager to try the new dashboard.
For how long have I used the solution?
We have used the solution for three years.
Which solution did I use previously and why did I switch?
We started with Linkerd.
What's my experience with pricing, setup cost, and licensing?
The setup cost is fine.
Which other solutions did I evaluate?
We looked at Istio.
What other advice do I have?
The Buoyant Team is passionate about what they do.
reviewer2808858
Service mesh has reduced cross-zone traffic costs and has provided safer, smarter routing
Reviewed on Mar 12, 2026
Review provided by PeerSpot
What is our primary use case?
The solution is a simple and reliable service mesh.
How has it helped my organization?
We have always been a user of OSS Linkerd since version 2. Buoyant Enterprise provides superb support, and the cost savings from HAZL make the license almost cost neutral.
What is most valuable?
HAZL is much better, both safer and more effective, than Kubernetes' native topology-aware routing. If I am already using OSS Linkerd, HAZL might effectively bring me Enterprise support for free.
What needs improvement?
I hope HAZL load bands can be tuned more easily or even automatically.
For how long have I used the solution?
I have used the solution for two years.
What's my experience with pricing, setup cost, and licensing?
Look at how much I spend on cross-AZ traffic within my cluster and estimate how much HAZL could save me.
reviewer2805678
Secure mesh has strengthened zero‑trust traffic and improves compliance visibility
Reviewed on Mar 02, 2026
Review provided by PeerSpot
What is our primary use case?
Our primary use case is providing a secure, observable, and reliable service mesh for our Kubernetes-based microservices architecture.
As a fintech company, we require a solution that handles high-traffic volumes while ensuring zero-trust network security between services without adding significant latency or operational overhead.
How has it helped my organization?
Buoyant Enterprise for Linkerd significantly improved our security posture by enforcing mTLS across all services with minimal operational complexity.
The ability to explicitly define and enforce which services can call each other has been extremely powerful from a compliance and zero-trust standpoint.
What is most valuable?
The most valuable features for us are automatic mTLS with a strong identity model, which is critical for a fintech environment where encrypted east-west traffic is non-negotiable.
Authorization policies are essential because the ability to explicitly define and enforce which services can call each other has been extremely powerful from a compliance and zero-trust standpoint.
Operational simplicity is another valuable feature, as Linkerd’s lightweight design and straightforward control plane reduce cognitive and operational load compared to other meshes.
Lastly, having enterprise support and stability through a supported enterprise build with security patches and predictable releases gives us confidence in production.
What needs improvement?
I would like to see more advanced out-of-the-box dashboard visualizations through Buoyant Cloud.
For how long have I used the solution?
I have used the solution for 3 years.
Which solution did I use previously and why did I switch?
We previously used AWS App Mesh as our service mesh.
As a fintech organization, strong mTLS and identity-based security are critical requirements for us.
While App Mesh provided managed service mesh capabilities, we found that Buoyant Enterprise for Linkerd offered a simpler operational model, better visibility into service-to-service communication, and mTLS capabilities.
Which other solutions did I evaluate?
We evaluated multiple service mesh solutions within the Kubernetes ecosystem, including Istio and other managed offerings.
reviewer2803542
Service mesh has strengthened zero trust security and now supports FIPS-ready compliance
Reviewed on Feb 18, 2026
Review from a verified AWS customer
What is our primary use case?
We were going for FedRAMP compliance, so we needed a service mesh in our platform that is FIPS-enabled. We considered Linkerd because it is a lightweight mesh, so we thought of using it.
How has it helped my organization?
Security and compliance have been enhanced with Zero Trust featuring mTLS, workload identity, and end-to-end encryption without code changes. We leverage FIPS 140-2 / 140-3 validated cryptography for regulated environments and fine-grained authorization using workload identity and HTTP/gRPC routes instead of IP-only rules. For reliability and traffic management, we ensure ultra-high availability with zone/region-aware routing, automated failover, retries, timeouts, and circuit breaking. We can also perform canary/blue-green deployments with automatic rollback. Latency-aware load balancing directs traffic to faster, healthier instances.
To manage costs and operations, we use High Availability Zonal Load Balancing (HAZL) to cut cross-zone traffic and cloud expenses, with some customers reporting significant savings. Additionally, lifecycle automation handles installation, upgrades, and day-2 operations, while mesh expansion automates the inclusion of VMs and non-Kubernetes workloads.
What is most valuable?
The most valuable features are the service mesh and the Linkerd dashboards.
What needs improvement?
Our cluster has improved with the use of mTLS security, which is the best part of the enhancements we've realized.
For how long have I used the solution?
I have used the solution for one year.
Which solution did I use previously and why did I switch?
We started with Linkerd.
What's my experience with pricing, setup cost, and licensing?
The setup cost is fine.
Which other solutions did I evaluate?
We also explored Istio before switching to Linkerd.