LinkMesh

Search docs, blog and changelog

ENDE

Features

Four problems. One control plane.

LinkMesh is shaped around the four jobs every platform team eventually has to do with their telemetry. Each gets a first-class capability — not a plugin, not a partner integration, not a roadmap promise.

Telemetry bills grow with volume, not with value. LinkMesh is a self-hosted control plane for your OpenTelemetry collectors — filter, mask and route telemetry before it is billed, priced per collector instead of per gigabyte.

01

Collector Fleet Management

Problem

OpenTelemetry Collectors are great per-host, but managing dozens or hundreds across a fleet means manual config drift, version skew, and SSH-driven ops.

LinkMesh

Enroll every Collector with the LinkMesh control plane over a single port-443 connection — otelcol-contrib via OpAMP, Grafana Alloy via remotecfg. The fleet UI shows status, version, throughput, and config state for every node. Push config changes from one place; collectors apply them with hot-reload where possible, restart where needed.

No SSH. No drift. One pane of glass for every Collector your platform team manages.

How a Collector is modelled in LinkMesh →
The LinkMesh Collectors view — a fleet of OpenTelemetry collectors showing status, version, last-seen, CPU, and memory for every node.
The fleet view: status, version, and host footprint for every managed Collector.

02

PII Masking

Problem

Sensitive fields — credit cards, emails, phone numbers, internal IDs — slip into logs all the time. They reach observability backends where they're indexed, retained, and eventually queried by people who shouldn't see them.

LinkMesh

Apply masking processors at the Collector level, BEFORE telemetry leaves the host. Built-in templates for credit cards, emails, phone numbers; custom regex/OTTL rules for your specific fields. Masking runs client-side in customer infrastructure — sensitive values never reach the network.

Compliance-friendly by construction. Your security review takes minutes instead of months.

How-to: mask PII before egress →
The LinkMesh processor library, including a built-in Credit Card Masking template that redacts Visa, Mastercard, and Amex numbers from log bodies and attributes.
Built-in masking templates — like Credit Card Masking — apply at the source, before egress.

03

Telemetry Refinement

Problem

Most telemetry is noise. Health checks, polling, debug logs, retry storms — they bloat your retention bill and bury the signals you actually need.

LinkMesh

Drop, sample, aggregate, and rate-limit at the source. Filter rules that read clean (drop where service.name = "health-check") instead of OTTL spaghetti. Per-component throughput metering at every stage — receivers, processors, exporters — so you can see exactly where volume is reduced.

Reduce volume before it hits your backend. Same signals, fraction of the storage cost.

How pipelines and processors compose →
The LinkMesh processor preview — a sample log record entering a drop filter on the left, the rule and generated OTTL in the middle, and the dropped-event output on the right.
Preview a real record through a processor — input, rule, and output side by side — before you save.

04

Label-Based Routing

Problem

A single telemetry pipeline can't serve every team. Security wants logs in Splunk; SRE wants metrics in Prometheus; finance wants slow queries in BigQuery.

LinkMesh

Define routes by label, environment, tenant, or service. The same source can fan out to multiple destinations with different processing chains for each. Every route, pipeline, and destination edit lands as a Git commit in the GitOps config repo — full diff and authorship for every change.

One pipeline definition, many backends, predictable cost.

How-to: route to Grafana / Loki →
The LinkMesh Topology view — a collector group routing telemetry to a Grafana Cloud destination, with a live 19 records-per-second rate measured on the connecting edge.
The topology: collectors routed to destinations, with live throughput on every edge.

What you get in each edition

Both editions run the same pipeline and fleet engine. Every capability for collecting, shaping and routing telemetry is ticked in both columns, and a lapsed licence never locks you out: local sign-in and licence upload always work. What differs is commercial (how many Collectors you manage, what it costs, what support you get), plus two capabilities that matter once a team runs the fleet rather than one admin: API automation, and single sign-on with your own identity provider.

LinkMesh capabilities by edition. Every pipeline and fleet capability is included in both Community and Enterprise; the Commercial chapter lists the differences, including API automation and single sign-on.
CapabilityCommunityFreeEnterprisePaid
Fleet management
Centralized Collector fleetEnroll otelcol-contrib over OpAMP and Grafana Alloy over remotecfg, and see status, version and last-seen for every node in one view.IncludedIncluded
Collector groupsManage a set of Collectors as one unit — one config, one set of routes, one place to change them.IncludedIncluded
Token-based enrollmentIssue an enrollment token, install, and the Collector appears in the fleet. No SSH, no per-host secret handling.IncludedIncluded
Discovery and adoptionAdopt Collectors that are already running on a host rather than replacing them.IncludedIncluded
Visual pipeline builderCompose sources, processors and destinations in the UI — not a YAML box with a preview.IncludedIncluded
Topology view with live throughputThe fleet as a graph, with measured records-per-second on the edges between Collectors and destinations.IncludedIncluded
GitOps configuration storeEvery pipeline, route and destination edit lands as a Git commit with a diff and an author.IncludedIncluded
Version history and rollbackRead any earlier version of a configuration and put it back.IncludedIncluded
Telemetry pipeline
SourcesReceivers composed from a catalogue — host metrics, files, OTLP, and the rest of the upstream set.IncludedIncluded
Processor library and templatesFilter, transform, batch and enrich with named rules, saved as reusable templates.IncludedIncluded
Label-based routingFan one source out to several destinations, each with its own processing chain.IncludedIncluded
DestinationsExport to Grafana Cloud, Loki, Splunk, an OTLP endpoint, or anywhere else the Collector can reach.IncludedIncluded
Live data captureTap real records flowing through a running pipeline, redacted, without adding a debug exporter.IncludedIncluded
Processor previewRun a real record through a processor and see input, rule and output side by side before you save.IncludedIncluded
PII maskingRedact credit cards, emails and custom patterns at the Collector, before telemetry leaves the host.IncludedIncluded
SamplingKeep a representative fraction of high-volume signals instead of all of it.IncludedIncluded
Pipeline dry-runValidate a configuration against the Collector that will run it, before it is pushed.IncludedIncluded
Control and reliability
Pipeline and Collector healthPer-entity health, with the failing component named rather than a red dot on the host.IncludedIncluded
Per-component throughputMeasured rates at receivers, processors and exporters, so you can see where volume is actually reduced.IncludedIncluded
Alerting and notification channelsAlert on fleet and pipeline conditions, delivered to the channels you configure.IncludedIncluded
Self-hosted control planeThe control plane runs in your infrastructure. Telemetry goes from your Collectors to your destinations, never through us.IncludedIncluded
Secrets vaultDestination credentials held in a vault and referenced by pipelines, never written into a config file.IncludedIncluded
Support bundle exportOne command collects the state a diagnosis needs, with secrets redacted.IncludedIncluded
Security and access
Roles, groups and scoped permissionsGrant a role over the whole install or scope it to specific Collectors and groups.IncludedIncluded
Audit logWho changed what, when — including every configuration change.IncludedIncluded
Commercial
Managed CollectorsHow many Collectors the edition may enroll.5 unregistered · 25 once registered*Unlimited, priced per Collector
PriceWhat the licence costs. Never a function of how much telemetry you move.Free, foreverUSD 12.50 · CHF 12.00 · EUR 12.50 per Collector / month, billed annually — bill caps at 200 Collectors
SupportWhere a question goes and what we commit to on first response.Documentation and communityPriority — next business day for an outage
API automationService accounts, config-as-code apply, and bulk fleet management driven from your own pipelines rather than the UI.Not includedIncluded
Single sign-on (OIDC)Sign in with your own identity provider. Local accounts keep working on every edition, so a lapsed licence never locks an admin out.Not includedIncluded†
Identity-provider group to role mappingMap groups and claims from your identity provider onto LinkMesh roles. Part of single sign-on.Not includedIncluded†

* An unregistered install manages up to 5 Collectors. Register the deployment in the OpenSight Customer Portal and you get a free 25-Collector Community licence — no card, no time limit. API automation (service accounts, config-as-code apply) and single sign-on (OIDC) are Enterprise capabilities in both cases. Register in the Customer Portal →

† Single sign-on with your own identity provider (OIDC) is included in Enterprise. Local accounts, roles and scoped permissions are in both editions.

The commercial rows in figures — worked examples, the billing cap, and the Enterprise checkout — are on the pricing page.

Ready to manage your Collector fleet from one place?

Install LinkMesh →