---
title: "What’s new in Calico Enterprise 3.16: Egress gateway on AKS, Service Graph optimizations, and more!"
source: "https://www.tigera.io/blog/whats-new-in-calico-enterprise-3-16-egress-gateway-on-aks-service-graph-optimizations-and-more/"
description: "Check out the early preview of Calico Enterprise 3.16 and learn how this latest release extends the active security platform's capabilities."
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# What’s new in Calico Enterprise 3.16: Egress gateway on AKS, Service Graph optimizations, and more!

By [Giri Radhakrishnan](https://www.tigera.io/blog/author/giri-radhakrishnan/) on Feb 28, 2023 • 3 min read

We are excited to announce the early preview of Calico Enterprise 3.16. This latest release extends the active security platform’s support for egress access controls, improves the usability of network-based threat defense features, and scales visualization of Kubernetes workloads to 100s of namespaces. Let’s go through some of the highlights of this release.

## Egress gateways for Microsoft Azure and AKS

[Egress gateways](https://docs.tigera.io/calico-enterprise/3.16/networking/egress/) allow you to identify the source of traffic at the namespace or pod level when it leaves a Kubernetes cluster to communicate to external resources. This makes it highly beneficial for security teams to apply access controls to specific traffic instead of opening up a larger set of IP addresses. Calico Enterprise 3.16 has added egress gateway support for Microsoft Azure and AKS in addition to our support for AWS and EKS. Check out our documentation, [Configure egress gateways, Azure](https://docs.tigera.io/calico-enterprise/3.16/networking/egress/egress-gateway-azure), to learn more.

## Operator-managed deployments of egress gateways[​](https://docs.tigera.io/calico-enterprise/3.16/release-notes/#operator-managed-deployments-of-egress-gateways)

Calico Enterprise now includes operator-managed deployments of egress gateways. This reduces operational overhead and eliminates additional steps required during software upgrades. With the Tigera Operator, egress gateways will always be automatically upgraded.

## UI for workload-based web application firewalls[​](https://docs.tigera.io/calico-enterprise/3.16/release-notes/#ui-for-workload-based-web-application-firewalls) (WAF)

Calico Enterprise’s unique workload-centric web application firewall (WAF) offers runtime threat detection for application-layer traffic in your Kubernetes cluster. It builds on Calico’s Envoy-as-DaemonSet architecture to provide an operationally simpler alternative to a service mesh, enabling visibility into application-layer (layer 7) traffic and the detection of potential indicators of compromise. Calico Enterprise 3.16 features a new [Manager UI](https://docs.tigera.io/calico-enterprise/3.16/threat/web-application-firewall#manager-ui) that can be used to enable and configure a workload-based WAF. This update will simplify your WAF deployments and allow you to manage alerts right from the Manager UI.

## Service Graph performance optimizations[​](https://docs.tigera.io/calico-enterprise/3.16/release-notes/#service-graph-performance-optimizations)

Our Dynamic Service and Threat Graph has become the focal point of many Calico Enterprise deployments, as it provides a way to visualize the communication between applications and services, initiate and retrieve packet captures, troubleshoot issues, and much more. This release of Calico Enterprise includes several optimizations to improve the performance of the Service Graph for clusters with larger numbers of namespaces.

![Calico Enterprise's Service Graph visualizes application communication, enabling troubleshooting and packet capture](https://www.tigera.io/app/uploads/2023/02/unnamed-2.png)Fig 1: Dynamic Service and Threat Graph with Calico Enterprise

Fig 1: Dynamic Service and Threat Graph with Calico Enterprise

## Support for multiple external networks[​](https://docs.tigera.io/calico-enterprise/3.16/release-notes/#support-for-multiple-external-networks)

Some of the largest telecommunications providers in the world use Calico to run their 5G networks on Kubernetes. Calico Enterprise now includes networking options that allow pods from different namespaces to [egress onto different external networks](https://docs.tigera.io/calico-enterprise/3.16/networking/egress/external-network) (virtual routing functions or VRFs) that may have overlapping IPs with each other. This also enables administrators to configure which service IPs are advertised for a network by the service IP advertisement feature.

## Improved product security with more restrictive SecurityContext[​](https://docs.tigera.io/calico-enterprise/3.16/release-notes/#improved-product-security-with-more-restrictive-securitycontext)

Calico Enterprise has updated its components to apply a more restrictive SecurityContext where applicable. This includes:

- Non-root context whenever possible and added drop `ALL Capabilities`

- Root context and privilege escalation are used only when necessary

- SeccompProfile is set to RuntimeDefault

For more information on the early preview release of Calico Enterprise 3.16, please refer to the [release notes](https://docs.tigera.io/calico-enterprise/3.16/release-notes/).

## Conclusion

We hope you’ll enjoy these product upgrades and enhancements. We will continue to deliver new releases with innovative solutions to solve container and Kubernetes security challenges. Watch this space for future updates.

***Check out our [self-paced workshops](https://www.tigera.io/events/workshop/) for an in-depth product experience.***

 

[Products](https://www.tigera.io/tags/products/)[Release](https://www.tigera.io/tags/release/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6153 metric#misses=17 metric#hit-ratio=99.7 metric#bytes=2185636 metric#prefetches=0 metric#store-reads=411 metric#store-writes=21 metric#store-hits=422 metric#store-misses=6 metric#sql-queries=38 metric#ms-total=919.63 metric#ms-cache=54.59 metric#ms-cache-avg=0.1267 metric#ms-cache-ratio=5.9 sample#redis-hits=52119378 sample#redis-misses=8226578 sample#redis-hit-ratio=86.4 sample#redis-ops-per-sec=236 sample#redis-evicted-keys=0 sample#redis-used-memory=103631992 sample#redis-used-memory-rss=94076928 sample#redis-memory-fragmentation-ratio=0.9 sample#redis-connected-clients=2 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=59009 -->
