---
title: "Announcing Tigera Secure Enterprise Edition 2.2"
source: "https://www.tigera.io/blog/announcing-tigera-secure-enterprise-edition-2-2/"
---

[Company Blog](https://www.tigera.io/category/company-blog/)

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Announcing Tigera Secure Enterprise Edition 2.2

By [Vince Lau](https://www.tigera.io/blog/author/vincetigera-io/) on Oct 18, 2018 • 3 min read

## Tigera Now Enabling Security Forensics and Operations Support

Tigera is excited to unveil several new capabilities with [Tigera Secure Enterprise Edition](https://www.tigera.io/tigera-products/compare-products/) 2.2, including the ability to enable security forensics for Kubernetes. Tigera’s modern search and visualization capabilities provide real-time enterprise-wide visibility into Kubernetes traffic. This release empowers businesses to detect and respond to untrusted and unauthorized Kubernetes traffic, often indicative of advanced attacks such as zero-day malware, data exfiltration, and nation-state espionage. Tigera accelerates investigations and provides direct access to large sets of Kubernetes flow logs. The solution allows:

- Platform teams to discover and identify communications between upstream and downstream Kubernetes microservices to better support DevOps and Security teams objectives.

- DevOps teams to troubleshoot and isolate the root cause related to Kubernetes workload connectivity issues.

- Security teams to monitor for anomalies and perform forensics investigations on suspicious Kubernetes workloads.

Traditional network monitoring tools generate inaccurate data for Kubernetes as they fail to capture traffic state denied by network policy. Additionally, these dated methods only capture 5-tuple information which is ineffective in a highly ephemeral Kubernetes environment.

Tigera addresses traditional monitoring limitations with network flow logs that provide context for Kubernetes workloads. Network flow logs are captured at the workload level and appended with Kubernetes context such as namespace, pod, labels, and metadata. This enables [accurate visibility](https://www.tigera.io/features/intrusion-detection-system/) into the communications between short-lived ephemeral workloads. Bi-directional flow logs are generated for all pods as well as host connections providing critical insight around suspicious east-west traffic.

### Tigera Secure Enterprise Edition 2.2 also brings the following additional capabilities:

- - [Application Layer Policy](https://www.tigera.io/blog/introducing-application-layer-policy/)– Protect against application threats with multi-factor workload authentication and multi-layer enforcements. Tigera attaches an identity to each workload for authentication and authorization based on multiple attributes including network identity and cryptographic identity. The solution provides multiple points of enforcement at the network layer with iptables and at the application layer with Istio and Envoy proxy. Fine-grained application layer access control governs service-to-service communication such as HTTP request attributes and web methods. The Application Layer Policy capability is currently in Beta; please [contact Tigera](https://www.tigera.io/contact/) for more information.

 

- - Encryption – Defend against eavesdropping, sniffing and man-in-the-middle (MitM) attacks with encryption that can be enabled for all traffic within and across Kubernetes environments. Traffic is encrypted at the application layer using [mutual Transport Layer Security (mTLS)](https://www.tigera.io/blog/inspecting-kubernetes-traffic-with-tls-v1-3/) leveraging x.509 certificates. Encryption is transparent to the application and requires no code or configuration changes.

 

- BGP Templates – [Customize BGP](https://www.tigera.io/blog/bgp-unumbered/) (Bird) configuration to fit your needs. BGP templates enable features such as Dual top of rack (ToR) peering or Password-protected BGP peering.

 

### Highlights of Tigera Secure Enterprise Edition 2.2

Kubernetes environments are often challenging to investigate because of the dynamic nature of workloads. Most conventional security approaches and tools weren’t built to provide visibility into Kubernetes environments. Tigera Secure Enterprise Edition 2.2 accelerates security forensic activities to determine indicators of compromise (IOC) and cause of attacks. Our new release also helps reduce resolution time associated with workload connectivity issues. Additional capabilities defend against application layer and network eavesdropping attacks.

Please [schedule a demo](https://www.tigera.io/demo/) for more information.

[Products](https://www.tigera.io/tags/products/)[Release](https://www.tigera.io/tags/release/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6148 metric#misses=17 metric#hit-ratio=99.7 metric#bytes=2228903 metric#prefetches=0 metric#store-reads=410 metric#store-writes=16 metric#store-hits=422 metric#store-misses=6 metric#sql-queries=34 metric#ms-total=1538.14 metric#ms-cache=188.52 metric#ms-cache-avg=0.4436 metric#ms-cache-ratio=12.3 -->
