---
title: "From Zero to Azure: Network Policy Comes to ACS Engine"
source: "https://www.tigera.io/blog/from-zero-to-azure-network-policy-comes-to-acs-engine/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# From Zero to Azure: Network Policy Comes to ACS Engine

By [Andrew Randall](https://www.tigera.io/blog/author/andrewrandall/) on Mar 28, 2017 • 2 min read

When Microsoft announced availability of Kubernetes on Azure Container Service (ACS), we were very excited – finally, an officially blessed way to run Kubernetes on Azure! Interestingly, and uniquely among the major cloud operators, the underlying deployment technology — ACS Engine — was open sourced, enabling third parties to extend it.

Working with our friends at Microsoft and Jetstack, we got started on the integration to enable ACS Engine to deploy Project Calico along with Kubernetes. We’re pleased to announce that this has now been upstreamed into the core of ACS Engine.

“Network policy will be crucial for meeting the strict security requirements of many enterprises,” said Brendan Burns, Partner Architect at Microsoft. “We were excited to see Calico integration make it into upstream ACS Engine, and are looking forward to hearing from the community as they get their hands on this capability.”

As background, the default ACS Kubernetes configuration (without Calico) does not include support for Network Policy. This new Kubernetes API, currently in beta, provides the ability to restrict network traffic based on Kubernetes labels and/or namespaces, providing greater security for micro-services, regulatory compliance, or multi-tenant environments. Calico is one of the leading implementations of network policy and fully supports this API (as well as a few more powerful capabilities).

The upshot is that anyone using upstream ACS Engine can now easily deploy Calico with their Kubernetes clusters, in order to get the benefits of micro-segmentation via the Kubernetes built-in Network Policy API.

Check it out by [**installing ACS Engine**](http://github.com/Azure/acs-engine/blob/master/docs/kubernetes.md), and including the **`”networkPolicy”: { “value”: “calico” }`**option (see: [http://github.com/Azure/acs-engine/blob/master/docs/kubernetes.md#optional-enable-network-policy-enforcement-using-calico](http://github.com/Azure/acs-engine/blob/master/docs/kubernetes.md#optional-enable-network-policy-enforcement-using-calico) for details).

[Open Source](https://www.tigera.io/tags/open-source/)[Partner/Integration](https://www.tigera.io/tags/partner-integration/)[Project Calico](https://www.tigera.io/tags/project-calico/)

## Related posts

[![What’s new in Calico: Spring 2026 Release](https://www.tigera.io/app/uploads/2026/06/Whats-New-in-Calico-NEW-TEMPLATE-2026.png)](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[Company Blog](https://www.tigera.io/category/company-blog/)

#### [What’s new in Calico: Spring 2026 Release](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on Jun 2, 2026

Kubernetes has come a long way since its debut in 2014. It’s gone from running a couple of containerized microservices to orchestrating fleets of production workloads spanning everything from AI agents to full scale VMs...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-spring-2026-release/)

[![Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/app/uploads/2026/05/Kubernetes-Operational-Maturity-Secure-and-Resilient-Cluster-Federation-with-Cluster-Mesh.png)](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

#### [Kubernetes Operational Maturity: Secure and Resilient Cluster Federation with Cluster Mesh](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

By [Veronika Smolik](https://www.tigera.io/blog/author/veronika-smolik/)
on May 25, 2026

Practically no one runs a single Kubernetes cluster in production these days. Maybe that’s how it started but data sovereignty requirements, acquisitions, AI initiatives and the need for edge servers, among other considerations, have pulled...

[Read more](https://www.tigera.io/blog/kubernetes-operational-maturity-secure-and-resilient-cluster-federation-with-cluster-mesh/)

[![What’s New in Calico v3.32](https://www.tigera.io/app/uploads/2026/05/Green-Please-use-a-different-background-color-alternately-1.png)](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

#### [What’s New in Calico v3.32](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

By [Reza Ramezanpour](https://www.tigera.io/blog/author/rezar/)
on May 13, 2026

We’re excited to announce the release of Calico Open Source v3.32! 🎉 This release corresponds with Kubernetes v1.36 (Codename Haru) and it goes beyond just sharing a cat as the mascot of the release, it...

[Read more](https://www.tigera.io/blog/whats-new-in-calico-v3-32/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6273 metric#misses=17 metric#hit-ratio=99.7 metric#bytes=2235815 metric#prefetches=0 metric#store-reads=416 metric#store-writes=16 metric#store-hits=429 metric#store-misses=6 metric#sql-queries=32 metric#ms-total=1214.69 metric#ms-cache=62.40 metric#ms-cache-avg=0.1448 metric#ms-cache-ratio=5.1 sample#redis-hits=45423118 sample#redis-misses=7824378 sample#redis-hit-ratio=85.3 sample#redis-ops-per-sec=321 sample#redis-evicted-keys=0 sample#redis-used-memory=82254696 sample#redis-used-memory-rss=84586496 sample#redis-memory-fragmentation-ratio=1.0 sample#redis-connected-clients=2 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=25535 -->
