---
title: "What’s new in Calico Enterprise 3.9: Live troubleshooting and resource-efficient application-level observability"
source: "https://www.tigera.io/blog/whats-new-in-calico-enterprise-3-9-live-troubleshooting-and-resource-efficient-application-level-observability/"
---

[Company Blog](https://www.tigera.io/category/company-blog/)

# What’s new in Calico Enterprise 3.9: Live troubleshooting and resource-efficient application-level observability

By [Dhiraj Sehgal](https://www.tigera.io/blog/author/dhiraj-sehgal/) on Sep 07, 2021 • 4 min read

We are excited to announce Calico Enterprise 3.9, which provides faster and simpler live troubleshooting using Dynamic Packet Capture for organizations while meeting regulatory and compliance requirements to access the underlying data. The release makes application-level observability resource-efficient, less security intrusive, and easier to manage. It also includes pod-to-pod encryption with Microsoft AKS and AWS EKS with AWS CNI.

## Live troubleshooting

Enterprises that want to carry out live troubleshooting in their production environments face the following challenges when doing packet capture at an organizational scale:

- Difficult to limit access to packet capture by organizational roles

- Takes hours to days to setting up packet capture instead of making part of the code

- Extremely difficult to capture the right amount of data to lessen storage and compute cost

- Spend days and weeks to correlate the data collected from different Kubernetes components such as namespaces, workloads, pods, microservices

### Dynamic Packet Capture

With Dynamic Packet Capture, organizations can enable DevOps, SREs, service owners to collect the data that they need when they need it. They can filter the data based on protocol and port to fine-tune their capture for faster debugging and subsequent analysis for shorter time-to-resolution. With just-in-time data collection and built-in smart correlation, they get workload and Kubernetes context during data aggregation. DevOps, SREs, and service owners don’t need to spend time collecting massive data and building correlations across different services, namespaces, workloads, and pods. All the information, accompanied by workload and Kubernetes context, is available. This means they can pinpoint the problem and resolve it in minutes.

Dynamic Packet Capture also integrates with Kubernetes role-based access control (RBAC). Teams get live, self-service, on-demand troubleshooting capabilities, according to their roles, that provide visibility into their specific application’s behavior, services, service dependencies, external APIs, and service interactions. Assigning access by role reduces security and compliance risk since teams don’t have unrestricted access to all namespaces within a cluster to initiate packet capture. This eliminates the unintentional HIPAA, PCI, SOC2 compliance violations that may occur on Kubernetes workloads due to incorrect initiation of packet capture.

To summarize, the Dynamic Packet Capture available in 3.9 offers the following observability and troubleshooting benefits:

- Standardize packet capture for troubleshooting Kubernetes environments

- Leverage built-in Kubernetes context for workload, microservices, namespaces, and pods for faster analysis

- Enable self-service, on-demand packet capture for troubleshooting based on role permissions defined with Kubernetes RBAC

- Troubleshoot your Kubernetes environment faster with less operational overhead

- Prevent unauthorized access by not circumventing role permissions defined with Kubernetes RBAC

- Ensure regulatory compliance (e.g. PCI, SOC 2) for troubleshooting when doing packet capture and analysis

## Application-level observability

DevOps, SREs, service owners, and platform engineers now have an operationally simpler alternative to service mesh for application-level observability and control. Calico Enterprise 3.9 provides Envoy integration with the data plane as a DaemonSet, making it less invasive to the pods that make up microservices.

![Application-level observability diagram](https://www.tigera.io/app/uploads/2021/09/Sidecar-vs-DaemonSet-approach-to-application-level-observability-.png)Sidecar vs DaemonSet approach to application-level observability

With Calico Enterprise 3.9, operational complexity and performance overhead for application-level observability is reduced due to the following reasons:

- Users only need to manage and operate one Envoy proxy per node, instead of multiple sidecars for each pod, leading to reduced security risk footprint

- Application-level information that includes Kubernetes-related context and correlation with other components allows for easier troubleshooting

- The use of DaemonSet instead of multiple sidecars on a per-node basis leads to less CPU and memory consumption

With 3.9, users also get data-in-transit encryption for node-to-node communication within Microsoft AKS and AWS EKS.

 

***To try these Calico Enterprise features, sign up for a [free trial](https://www.calicocloud.io/) of Calico Cloud.***

 

### Next steps:

- [Talk to an expert](https://www.tigera.io/contact/) to have your questions answered

- [Request a demo](https://www.tigera.io/demo/) to see Calico Enterprise in action

[Products](https://www.tigera.io/tags/products/)[Release](https://www.tigera.io/tags/release/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[Technical Blog](https://www.tigera.io/category/technical-blog/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3371 metric#misses=35 metric#hit-ratio=99.0 metric#bytes=1479753 metric#prefetches=162 metric#store-reads=47 metric#store-writes=18 metric#store-hits=170 metric#store-misses=24 metric#sql-queries=36 metric#ms-total=554.46 metric#ms-cache=18.17 metric#ms-cache-avg=0.2839 metric#ms-cache-ratio=3.3 -->
