---
title: "Case study: Calico helps Upwork migrate legacy system to Kubernetes on AWS and enforce zero-trust security"
source: "https://www.tigera.io/blog/case-study-calico-helps-upwork-migrate-legacy-system-to-kubernetes-on-aws-and-enforce-zero-trust-security/"
---

[Company Blog](https://www.tigera.io/category/company-blog/)

# Case study: Calico helps Upwork migrate legacy system to Kubernetes on AWS and enforce zero-trust security

By [Suki Lam](https://www.tigera.io/blog/author/suki-lam/) on Jun 21, 2023 • 3 min read

Upwork is a freelancing platform that connects a global base of clients to freelancers via job postings. Since going public on the New York Stock Exchange in 2019, the company has become one of the leading freelance platforms worldwide and was named on Time’s list of the 100 Most Influential Companies of 2022.

## Background

Upwork’s platform team was running containerized workloads on Consul and Spring Cloud, which required service owners to manually switch to a new code library each time Upwork’s platform team had a new release, and vice versa. This manual switching happened as often as every two months, which was inefficient for a company with over 800 microservices. Also, service owners were not adopting new libraries immediately and could not add upstream and downstream dependencies as needed without going through a review process. Combined, these problems meant that service owners and the cloud engineering and InfoSec teams lacked visibility, were highly susceptible to zero-day attacks and had a slow incident mitigation response.

To solve these problems, Upwork needed to adopt a distributed architecture from the application layer to the network layer. To do this, they required Kubernetes. The switch to Kubernetes meant Upwork’s containers needed to adhere to cloud-native requirements, including resiliency and security measures.

In collaboration with Tigera, Upwork shares the details of how Calico provided a security solution that enabled the company to implement a zero-trust approach and provided visibility into all workload communications.

## Case study highlights

In its migration to Kubernetes, Upwork required a security solution that could:

- Implement a zero-trust approach

- Provide visibility into all workload communications

- Enforce a zero-trust, default-deny policy on all workload communications and allow authorized communications only

- Provide visibility and security controls to service owners as an application-layer architecture

- Enable the cloud engineering team to see all upstream and downstream dependencies

- Meet the company’s InfoSec team mandate for zero-trust security to ensure the platform, services, and application were fully protected

The platform team ultimately decided to migrate Upwork’s containers to Kubernetes, hosted on Amazon Web Services’ Elastic Kubernetes Platform (AWS EKS). After testing Calico, Upwork’s platform team deployed Calico as its zero-trust security solution to secure the company’s containerized workloads on EKS.

![Upwork quote: Calico is the most-adopted security solution for containers and Kubernetes. Upwork and Tigera logos](https://www.tigera.io/app/uploads/2023/06/Customer-quote-Upwork-01.png)

Find out how Calico helped Upwork secure its EKS clusters in just six months, meet its security team’s zero-trust security mandate, accelerate application rollouts, and more.

Read the case study: [Calico helps Upwork migrate legacy system to Kubernetes on AWS and enforce zero-trust security.](https://www.tigera.io/upwork-case-study/)

[Partner/Integration](https://www.tigera.io/tags/partner-integration/)[Products](https://www.tigera.io/tags/products/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[Technical Blog](https://www.tigera.io/category/technical-blog/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3201 metric#misses=33 metric#hit-ratio=99.0 metric#bytes=1538180 metric#prefetches=0 metric#store-reads=174 metric#store-writes=13 metric#store-hits=167 metric#store-misses=22 metric#sql-queries=31 metric#ms-total=541.18 metric#ms-cache=26.92 metric#ms-cache-avg=0.1447 metric#ms-cache-ratio=5.0 -->
