---
title: "Case study: Calico enables zero-trust security and policy automation at scale in a multi-cluster environment for Box"
source: "https://www.tigera.io/blog/case-study-calico-enables-zero-trust-security-and-policy-automation-at-scale-in-a-multi-cluster-environment-for-box/"
---

[Company Blog](https://www.tigera.io/category/company-blog/)

# Case study: Calico enables zero-trust security and policy automation at scale in a multi-cluster environment for Box

By [Suki Lam](https://www.tigera.io/blog/author/suki-lam/) on Jun 08, 2023 • 3 min read

Box is a content cloud that helps organizations securely manage their entire content lifecycle from anywhere in the world, powering over 67% of Fortune 500 businesses. As a cloud-first SaaS, the company provides customers with an all-in-one content solution within a highly secure infrastructure, where organizations can work on any content, from projects and contracts to Federal Risk and Authorization Management Program (FedRAMP)-related content.

## Background

Box has two types of operations: cloud-managed Kubernetes clusters in hybrid, multi-cloud, and public cloud environments, and self-managed Kubernetes clusters in co-located data centers. The company runs multiple clusters with sizes of 1,000 nodes and larger. As one of the early adopters of Kubernetes, Box began using Kubernetes much before Google Kubernetes Engine (GKE) or Amazon’s Elastic Kubernetes Services (EKS) was born, and has been on the leading edge of innovation for Kubernetes in areas such as security, observability, and automation.

In collaboration with Tigera, Box shares how Calico helped the company achieve zero-trust security and policy automation at scale in a multi-cluster environment.

***ICYMI***: Watch this recording from the 2022 CalicoCon Cloud Native Security Summit, where Tapas Kumar Mohapatra of Box shares [how Box moved into automated dependency mapping and policy generation with API v3](https://www.tigera.io/lp/calicocon-cloud-native-security-summit-2022/fireside-chat-how-box-moved-into-automated-dependency-mapping-and-policy-generation-with-api-v3/)

## Case study highlights

Once Box moved to Kubernetes, the content cloud opened a shared Kubernetes infrastructure model with a multi-cluster architecture for its services. As the service owner, the Box Kubernetes infrastructure team needed to be the central service provider and overseer to their internal customer user base, the application development team.

### Challenges

Since not all application developers are Kubernetes experts or have the necessary policy-writing expertise, Box’s shared Kubernetes infrastructure and multi-cluster architecture was met with a number of challenges:

- Maintaining a zero-trust posture, enforcing granular workload access controls, and gaining observability into all workload and policy communications on a shared infrastructure in an ephemeral environment with thousands of microservices

- Troubleshooting and ensuring all deployed security policies can run on multiple clusters and are discoverable to other endpoints

- Achieving and maintaining continuous compliance with regional regulations, including PCI DSS, SOC 2, and FedRAMP

- On-demand compliance reporting

### Goals

Quickly realizing workarounds were too time-consuming and costly, the company searched for a security provider to solve these problems, with four major goals:

- Maintain a zero-trust posture for all workloads

- Gain visibility into all workload and policy communications and reduce troubleshooting times

- Automate multi-cluster security policy creation and management

- Ensure continuous compliance with regional regulatory requirements

### Results

After implementing Calico Enterprise, Box achieved zero-trust security and gained observability for all workload communications. The company now has a fully automated policy lifecycle that Calico continuously monitors to ensure compliance with regional regulatory requirements for the company’s shared infrastructure spanning multiple clusters in co-located data centers, and public clouds in different regions.

“Tigera helped Box enforce zero-trust security, workload observability, and cross-regional compliance for our shared, multi-cluster Kubernetes infrastructure.”

—Tapas Mohapatra

Sr. Manager, Site Reliability Engineering, Cloud & Kubernetes at Box

Read the case study: [Calico enables zero-trust security and policy automation at scale in a multi-cluster environment for Box](https://www.tigera.io/box-case-study/)

[Products](https://www.tigera.io/tags/products/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[Technical Blog](https://www.tigera.io/category/technical-blog/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6070 metric#misses=33 metric#hit-ratio=99.5 metric#bytes=2205267 metric#prefetches=0 metric#store-reads=426 metric#store-writes=20 metric#store-hits=421 metric#store-misses=22 metric#sql-queries=38 metric#ms-total=966.61 metric#ms-cache=52.93 metric#ms-cache-avg=0.1189 metric#ms-cache-ratio=5.5 -->
