# How to change a value with Linkerd CLI?

**URL:** <https://linkerd.buoyant.io/t/how-to-change-a-value-with-linkerd-cli/810>\
**Category:** Linkerd General Discussion\
**Tags:** configuration\
**Created:** [September 23, 2025, 1:47pm UTC](https://linkerd.buoyant.io/t/how-to-change-a-value-with-linkerd-cli/810 "2025-09-23T13:47:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![MewanthaB](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@MewanthaB](https://linkerd.buoyant.io/u/MewanthaB)\
**Post date:** [September 23, 2025, 1:47pm UTC](https://linkerd.buoyant.io/t/how-to-change-a-value-with-linkerd-cli/810/1 "2025-09-23T13:47:34Z")

</div>

According to the Linkerd doc:

> #### **Authority Label**
> 
> For metrics with the `direction=inbound` label value, the `authority` label is omitted. This is done as a security measure to prevent malicious clients from being able to cause Linkerd to create an arbitrary number of metrics by sending requests with an arbitrary number of different authority values.
> 
> If this is not a concern in your environment, it is possible to re-enable the `authority` label on these metrics by setting an additional env value in Linkerd’s `values.yml`
> 
> ```auto
> proxy:
> additionalEnv:
> - name: LINKERD2_PROXY_INBOUND_METRICS_AUTHORITY_LABELS
> value: unsafe
> 
> ```

However I have used Linkerd CLI for installation with this command:

> linkerd install --ha --set identity.externalCA=true --set [identity.issuer.scheme=kubernetes.io/tls](http://identity.issuer.scheme=kubernetes.io/tls) | kubectl apply -f -

I have tried to upgrade linkerd with

> linkerd upgrade --ha --set identity.externalCA=true --set [identity.issuer.scheme=kubernetes.io/tls](http://identity.issuer.scheme=kubernetes.io/tls) --set proxy.additionalEnv.LINKERD2\_PROXY\_INBOUND\_METRICS\_AUTHORITY\_LABELS=unsafe | kubectl apply -f -

This gives:

> –identity-issuer-certificate-file must not be specified if --identity-external-issuer=true

I am using an external identity issue but as you can see, my command does not specify “–identity-issuer-certificate-file”. What should I do here?

---

<div class="post-metadata">

**Author:** ![rket022](https://avatars.discourse-cdn.com/v4/letter/r/35a633/32.png) [@rket022](https://linkerd.buoyant.io/u/rket022)\
**Post date:** [February 8, 2026, 2:23pm UTC](https://linkerd.buoyant.io/t/how-to-change-a-value-with-linkerd-cli/810/2 "2026-02-08T14:23:19Z")

</div>

I had the same exact error message too and posting what I finally did to hopefully save someone else hours of troubleshooting. During the upgrade process linkerd was reading from the secret **linkerd-config-overrides**. Ours had the externalCA set to true but also still had certs defined in it. I deleted the certs after ‘scheme: [kubernetes.io/tls’](http://kubernetes.io/tls%E2%80%99) and before ‘identityTrustAnchorsPEM:’ (Note: KEEP identityTrustAnchorsPEM cert). My snippet in my newly modified secret looked like:

> identity:  
> externalCA: true  
> issuer:  
> scheme: [kubernetes.io/tls](http://kubernetes.io/tls)  
> identityTrustAnchorsPEM: |

After making this change running linkerd upgrade worked
