A Calico Reference Architecture
Most Kubernetes east-west networking decisions are inherited rather than made: you install a CNI, take its defaults, and find out at 60 nodes that nobody actually chose them. This Calico reference architecture works the choices out deliberately: which data plane enforces policy (iptables, nftables, or eBPF), how pods reach each other (VXLAN, IP-in-IP, or BGP with no overlay), how BGP scales past the full mesh with route reflectors, and how to carve up address space before growth forces the issue. Two worked examples (on-premises OpenShift and AKS in a hub-and-spoke topology) start from nearly identical requirements and land on opposite recommendations, and the variable that separates them is not cluster size, but whether you control the network underneath.
Become an expert in Kubernetes Networking and Security with this self-paced online Calico certification course