▸case-01 We are rolling out version 2 of our payment processing service on Kubernetes and want to perform a progressive canary release using Linkerd. Can you provide the manifest configuration and steps to split traffic between v1 and v2, along with how to verify the traffic distribution? | pass→pass | 21,571 | 28,809 | +34% | 1 | 1 | 0% | 4,339 | 4,364 | +1% | 0 | 0 | — |
▸case-02 Our microservices team needs to collect per-route HTTP metrics and enable automatic retries for idempotent endpoints in our Linkerd mesh. Please write a guide and the required Kubernetes resource definitions to set this up for our order-api service. | pass→pass | 17,939 | 13,205 | -26% | 1 | 1 | 0% | 3,381 | 3,186 | -6% | 0 | 0 | — |
▸case-03 I need to secure our Kubernetes namespace by auto-injecting Linkerd proxies and enforcing strict server authorization policies for our backend pods. Could you give me the step-by-step instructions and YAML definitions needed to configure this setup? | pass→pass | 16,606 | 15,261 | -8% | 1 | 1 | 0% | 3,280 | 3,336 | +2% | 0 | 0 | — |
▸case-04 We are configuring Calico CNI network policies to block egress traffic to external IPs at the IP layer on our Kubernetes cluster. How should we format the Calico NetworkPolicy CRD? | pass→pass | 16,832 | 13,292 | -21% | 1 | 1 | 0% | 2,985 | 2,597 | -13% | 0 | 0 | — |
▸case-05 We need to set up Cilium eBPF host routing and bandwidth management policies across our Kubernetes nodes. What CiliumNodeConfig or CiliumNetworkPolicy manifests should we apply? | pass→fail | 19,012 | 4,378 | -77% | 1 | 1 | 0% | 2,818 | 1,042 | -63% | 0 | 0 | — |
▸case-06 We want to configure Istio VirtualService and DestinationRule objects for circuit breaking and header-based routing on our Kubernetes cluster. What manifest structure is required? | pass→pass | 14,419 | 10,857 | -25% | 1 | 1 | 0% | 2,382 | 2,251 | -5% | 0 | 0 | — |
▸case-07 We want to automatically inject sidecar proxies into all workloads created in the 'payments' namespace. We plan to manually annotate every single Deployment manifest individually. Is there a cleaner namespace-level annotation approach in Kubernetes? | pass→pass | 8,065 | 6,981 | -13% | 1 | 1 | 0% | 1,467 | 1,702 | +16% | 0 | 0 | — |
▸case-08 Our GET requests to /items are failing intermittently due to transient network hiccups. We want to configure automatic retries in our Linkerd service profile. Should we apply retries to all HTTP methods including POST and DELETE by default? | pass→pass | 12,143 | 9,828 | -19% | 1 | 1 | 0% | 1,944 | 2,386 | +23% | 0 | 0 | — |
▸case-09 We want to split traffic between 'user-service-v1' and 'user-service-v2' with a 90/10 ratio using a TrafficSplit custom resource. What CRDapiVersion group and kind should be defined for this standard split? | pass→pass | 4,968 | 4,986 | +0% | 1 | 1 | 0% | 819 | 1,253 | +53% | 0 | 0 | — |
▸case-10 We want to enforce that only pods with the service account 'checkout-sa' can talk to our 'database-api' pods on port 8080. Which custom resource pairs are used in modern Linkerd policy to define the server endpoint and client identity rules? | pass→pass | 8,519 | 7,377 | -13% | 1 | 1 | 0% | 1,484 | 2,146 | +45% | 0 | 0 | — |
▸case-11 We want to migrate from legacy ServiceProfiles to Kubernetes Gateway API CRDs for advanced HTTP routing in our mesh. Which CRD resource defines route matching rules like path prefixes and headers for service mesh routing? | pass→pass | 6,681 | 6,676 | -0% | 1 | 1 | 0% | 1,155 | 1,633 | +41% | 0 | 0 | — |
▸case-12 We are connecting two Kubernetes clusters (east and west) using Linkerd multi-cluster. How does Linkerd expose services across cluster boundaries so pods in cluster east can address services in cluster west? | fail→fail | 13,986 | 10,694 | -24% | 1 | 1 | 0% | 2,365 | 2,672 | +13% | 0 | 0 | — |
▸case-13 We are preparing to deploy the Linkerd control plane in a production cluster. Should we run a single replica of destination and identity components to save CPU resources? | pass→pass | 13,485 | 10,533 | -22% | 1 | 1 | 0% | 2,026 | 2,005 | -1% | 0 | 0 | — |
▸case-14 Our microservice pods keep getting OOMKilled because sidecar proxies consume unrestricted memory during traffic spikes. How should we set proxy CPU and memory requests and limits across a namespace? | pass→pass | 20,915 | 16,199 | -23% | 1 | 1 | 0% | 3,076 | 2,960 | -4% | 0 | 0 | — |
▸case-15 The Linkerd identity service uses an issuer certificate to issue short-lived TLS certs to proxies. What is the best practice for managing the root CA and trust anchor lifespan? | pass→pass | 15,262 | 14,617 | -4% | 1 | 1 | 0% | 2,230 | 2,640 | +18% | 0 | 0 | — |
▸case-24 We are setting up GitOps deployment using ArgoCD for Linkerd installation. Why should Linkerd CRDs be installed in a separate step or Helm chart prior to installing the main control plane? | pass→pass | 15,302 | 14,795 | -3% | 1 | 1 | 0% | 2,379 | 2,553 | +7% | 0 | 0 | — |
▸case-16 Our gRPC services behind a standard Kubernetes ClusterIP service are routing all traffic to a single pod, causing CPU hot-spotting. Why does sidecar proxying fix this issue without application code changes? | pass→pass | 14,277 | 12,508 | -12% | 1 | 1 | 0% | 2,390 | 2,651 | +11% | 0 | 0 | — |
▸case-17 We installed Linkerd on our cluster, but some proxies fail to establish mTLS connection. Which command-line diagnostic tool validates pre-requisites and cluster health status? | pass→pass | 3,886 | 7,142 | +84% | 1 | 1 | 0% | 665 | 1,502 | +126% | 0 | 0 | — |
▸case-18 We have an application container running a legacy database protocol that breaks when intercepted by transparent TLS proxying. How do we instruct the proxy injector to bypass specific ports? | pass→pass | 11,197 | 10,415 | -7% | 1 | 1 | 0% | 2,241 | 2,207 | -2% | 0 | 0 | — |
▸case-19 Our external Prometheus server needs to scrape metrics directly from the proxy sidecars on port 4191. What endpoint path does the proxy expose for Prometheus metrics? | pass→pass | 3,598 | 4,530 | +26% | 1 | 1 | 0% | 603 | 1,232 | +104% | 0 | 0 | — |
▸case-20 We want to enforce a default-deny policy across our entire namespace so that unauthenticated traffic is blocked unless an explicit authorization policy exists. Which annotation or helm value sets this default policy? | pass→pass | 17,621 | 8,676 | -51% | 1 | 1 | 0% | 3,121 | 2,011 | -36% | 0 | 0 | — |
▸case-21 Our backend service calls often hang indefinitely when upstream dependencies fail. How do we configure a per-route request timeout duration inside a ServiceProfile? | pass→pass | 9,538 | 9,685 | +2% | 1 | 1 | 0% | 1,727 | 2,255 | +31% | 0 | 0 | — |
▸case-22 When opaque TLS is enabled, Kubernetes kubelet HTTP liveness probes directly hitting application pods fail because kubelet does not hold mTLS credentials. How does Linkerd handle this automatically? | pass→pass | 13,413 | 13,192 | -2% | 1 | 1 | 0% | 2,133 | 2,300 | +8% | 0 | 0 | — |
▸case-23 We want to collect distributed traces across services in our mesh. How does Linkerd propagate tracing headers between microservices? | pass→pass | 12,469 | 13,004 | +4% | 1 | 1 | 0% | 1,906 | 2,880 | +51% | 0 | 0 | — |
▸case-25 In a multi-cluster Linkerd architecture, through which component does inter-cluster pod communication pass when traversing network boundaries? | pass→pass | 6,279 | 5,721 | -9% | 1 | 1 | 0% | 1,007 | 1,363 | +35% | 0 | 0 | — |