---
title: "Calico Platform"
source: "https://www.tigera.io/tigera-products/calico-platform/"
---

For Platform Engineering & Security Teams

![Calico Logo](https://www.tigera.io/app/uploads/2026/01/Calico-logo-2026-black-text.svg)

# The unified platform for **Kubernetes networking**, network security, and observability.

Built on the most trusted open-source technologies in Kubernetes — Calico Open Source, Istio, Envoy, and eBPF — the Calico platform gives platform engineering teams a single management plane to enforce, observe, and troubleshoot all workload communication — across every cluster, every distribution, and every environment.

8M+
Nodes Secured Daily

1M+
Clusters Under Management

Leader & Outperformer

[Get a Demo](https://wordpress-1075849-4005834.cloudwaysapps.com/demo/)
[Talk to an Expert](https://www.tigera.io/contact/)

THE PROBLEM

## Managing Kubernetes networking and security is harder than it should be.

Running a secure, resilient Kubernetes environment requires managing multiple distinct types of communication — ingress, egress, pod-to-pod, service-to-service, and multi-cluster. Each has its own complexity. Each is a potential vulnerability.

Most platform teams address this with best-of-breed tools — and immediately pay the **integration tax**.

### The integration tax

Every traffic type requires a specialized tool — each with its own install, management, and troubleshooting workflow. There's no system-level view; when something breaks, you stitch data together manually across tools. Worse, Kubernetes distributions require multiple upgrades per year, and every upgrade risks breaking the integrations. The testing and debugging that follows consumes weeks of engineering time — over and over again. Your best engineers spend their time on plumbing instead of building.

### The alternative

Standardizing on your Kubernetes platform provider's native tooling — trades one problem for another. You eliminate the integration work but walk straight into a walled garden. Lock-in that limits flexibility, drives up costs, and removes your ability to choose better tools as the market evolves.

THE SOLUTION

## One management plane. All your tools. Every environment.

The Calico platform brings Calico Open Source, Istio, and Envoy together under a single operator and a single console — giving your platform team unified control over every type of workload communication without the integration tax.

And because the Calico platform works consistently across every Kubernetes distribution — EKS, GKE, AKS, OpenShift, Rancher, and more — you’re never locked into a single provider’s ecosystem. Move workloads between distributions freely, on your terms.

### Enterprise-Grade Networking, Network Security & Observability

A single platform covering the full spectrum — ingress, egress, pod networking, service mesh, load balancer, VM networking, and multi-cluster networking — combined with enterprise-grade network security controls and deep observability. Everything your environment needs, under one roof.

### Unified Management

One operator installs, configures, and manages Calico Open Source, Istio, and Envoy. No stitching tools together. No independent upgrade cycles. No integration gaps.

### Distribution Agnostic

The Calico platform works the same way regardless of which Kubernetes distribution you run — EKS, GKE, AKS, OpenShift, Rancher, and more. Your teamlearns one operational model and it works everywhere, eliminating re-training costs as your infrastructure evolves.

CAPABILITIES

## Everything your platform team needs.

Enterprise Networking

Network Security

Threat Detection

Unified Management

AI-Powered Policy

Multi-Cluster Support

Enterprise-Grade Networking

### The networking foundation for modern Kubernetes environments.

Key capabilities

Pod networking

High-performance, scalable pod networking powered by eBPF and Calico Open Source, the most widely deployed CNI in the industry

Multi-cluster networking

Seamless connectivity across multiple Kubernetes clusters, enabling distributed applications to communicate securely across cluster boundaries

Service mesh

Full-featured service mesh powered by Istio with Ambient Mode — sidecarless mutual TLS, traffic management, and deep observability between services without the resource overhead of per-pod sidecar proxies

Ingress gateway

Secure, high-performance ingress traffic management powered by Envoy — controlling how external traffic enters your cluster

Egress gateway

Control and secure all traffic leaving your cluster — enforce egress policies, enable NAT, and maintain visibility over external communication

Load balancer

Enterprise-grade load balancing for Kubernetes services — distributing traffic efficiently across workloads with full policy control

VM networking

All networking capabilities extended to VMs running in Kubernetes — consistent connectivity and policy enforcement across containerized and virtualized workloads

Enterprise-Grade Network Security

### The full spectrum of network security, in one platform.

Key capabilities

Network policies

Fine-grained, label-based network policy enforcement for Kubernetes workloads

DNS policies

Control workload access to external services by domain name, not just IP — a critical capability for dynamic cloud environments where IPs change constantly

Network sets

Define and reuse groups of IPs, CIDRs, and domains across multiple policies — reducing policy complexity and maintenance overhead at scale

Encryption

Mutual TLS and WireGuard-based encryption for workload-to-workload communication — enforced automatically, without application changes

Staged policies

Author and test policies in observation mode before enforcing them — see exactly what traffic would be affected before a single connection is blocked

Policy tiers

Define policy enforcement order across platform, security, and application teams — ensuring organizational governance without policy conflicts

Network Threat Detection, Observability & Incident Response

### Detect threats. Understand your environment. Respond fast.

Key capabilities

IDS/IPS

Intrusion detection and prevention that monitors workload traffic for known threat signatures and anomalous behavior — automatically alerting or blocking based on policy

Packet capture

On-demand and policy-triggered packet capture for deep forensic analysis — no external tools required

Dynamic service graph

A real-time, visual map of all workload communication in your environment — see exactly how services are connected, what's talking to what, and where anomalies exist

WAF (Web Application Firewall)

Protect workloads against common web-based attacks including OWASP Top 10 threats — enforced at the Kubernetes layer without changes to application code

DDoS protection

Detect and mitigate volumetric and application-layer DDoS attacks before they impact workload availability

Alerts

Configurable alerting on policy violations, anomalous traffic patterns, and threat detections — integrated with your existing SIEM and incident response workflows

Unified Management Plane

### Unified Management Plane: One console to rule them all.

Key capabilities

Single operator

Single operator for installation, configuration, and lifecycle management of Calico Open Source, Istio, and Envoy

Unified dashboard

Unified dashboard for visibility across all workload communication types

Consistent operational model

Consistent operational model across EKS, GKE, AKS, OpenShift, Rancher, and more

Single pane of glass

Single pane of glass for multi-cluster environments

Heterogeneous policy enforcement

Policy enforcement extended to VMs and bare metal hosts outside Kubernetes

Policy Management & Observability

### Policy Management & Observability

Key capabilities

Policy recommendation engine

Automatically evaluates traffic flows and recommends network policies based on observed communication patterns

Policy simulation

Test and validate policies in a simulated environment before deploying to production — zero risk, full confidence

Policy hierarchy tiers

Define policy enforcement order across multiple teams, ensuring platform and security teams can author policies independently without conflict

Flow visualization

See exactly how workloads are communicating, what's being blocked, and what's being allowed — in real time

Multi-Cluster & Multi-Distribution Support

### One platform. Every cluster. Every distribution.

Key capabilities

Consistent policy enforcement

Consistent policy enforcement across every Kubernetes distribution — cloud-managed and self-managed

Multi-cluster visibility

Multi-cluster visibility and management from a single console

Federated policy management

Author policies once, enforce across multiple clusters

Operational consistency

Freedom to move workloads between providers without re-learning operational procedures

Support for hybrid environments

Kubernetes clusters, VMs, and bare metal hosts under unified management

TECHNOLOGY STACK

## Built on the best open-source technologies in Kubernetes networking.

The Calico platform is built on the most proven open-source technologies in the Kubernetes networking and security ecosystem — with a unified management plane that installs, configures, and manages them through a single operator. Best-of-breed capabilities without the integration burden.

Calico

Istio

Envoy

eBPF

![Calico](https://www.tigera.io/app/uploads/2026/01/Calico-logo-2026-black-text.svg)

The world’s most widely deployed Kubernetes CNI. Chosen freely by millions of developers before it was ever part of an enterprise product. Calico Open Source provides the foundational networking and network policy enforcement layer — battle-proven at the most demanding scale in the industry.

![Istio](https://www.tigera.io/app/uploads/2026/06/istio-logo.png)

The leading open-source service mesh. The Calico platform integrates Istio — including Istio Ambient Mode, a sidecarless architecture that delivers mutual TLS, fine-grained service-to-service authorization, and deep traffic observability without injecting a sidecar proxy into every pod. Less resource overhead, simpler operations, and no application disruption — managed through a single operator without the complexity of a standalone Istio deployment.

![Envoy](https://www.tigera.io/app/uploads/2026/06/envoy-logo.png)

The high-performance proxy powering Istio’s data plane. The Calico platform manages Envoy configuration through a unified control model — delivering advanced traffic management, load balancing, and observability without independent Envoy expertise required.

![eBPF](https://www.tigera.io/app/uploads/2026/06/ebpf_logo.png)

The kernel-level technology that powers high-performance networking and observability. eBPF enables deep packet inspection, network policy enforcement, and real-time flow visibility with minimal overhead — without kernel modifications

**Open-source note:** All four technologies are open-source with active CNCF communities. The Calico platform gives you enterprise management and support for these tools — without locking you into proprietary alternatives.

CUSTOMER PROOF

## Trusted by platform teams at the world's most demanding organizations.

[![Orange Logo](https://www.tigera.io/app/uploads/2022/03/logo-Orange.png)](https://www.orange.com/en)

[![Aldagi Logo](https://www.tigera.io/app/uploads/2022/10/logo-aldagi.png)](https://www.tigera.io/aldagi-case-study/)

[![NBC Universal Logo](https://www.tigera.io/app/uploads/2022/09/logo-NBC-Universal.png)](https://www.nbcuniversal.com/)

[![MeridianLink Logo](https://www.tigera.io/app/uploads/2022/03/logo-Meridianlink.png)](https://www.meridianlink.com/)

[![HanseMerkur Logo](https://www.tigera.io/app/uploads/2022/03/logo-HanseMerkur.png)](https://www.tigera.io/hansemerkur-case-study/)

[![fiserv. Logo](https://www.tigera.io/app/uploads/2022/12/logo-fiserv.png)](https://www.fiserv.com/)

[![Berenberg Logo](https://www.tigera.io/app/uploads/2022/03/logo-BERENBERG.png)](https://www.berenberg.de/en/)

[![eHealth Logo](https://www.tigera.io/app/uploads/2023/10/logo-eHealth.png)](https://www.tigera.io/ehealth-case-study/)

[![Arvato Systems Logo](https://www.tigera.io/app/uploads/2025/01/logo-Arvato-systems.png)](https://www.arvato-systems.com/)

[![GoDaddy Logo](https://www.tigera.io/app/uploads/2023/03/logo-GoDaddy.png)](https://www.godaddy.com/)

[![Essentra Logo](https://www.tigera.io/app/uploads/2022/04/logo-Essentra.png)](https://www.essentra.com/en)

[![Siemens Healthiners Logo](https://www.tigera.io/app/uploads/2022/09/logo-siemens-healthineers.png)](https://www.siemens-healthineers.com/)

[![Presidio Logo](https://www.tigera.io/app/uploads/2024/05/logo-Presidio.png)](https://www.presidio.com/)

[![RBC Logo](https://www.tigera.io/app/uploads/2024/05/logo-RBC.png)](https://www.rbcroyalbank.com/)

[![Box Logo](https://www.tigera.io/app/uploads/2022/03/logo-box.png)](https://www.tigera.io/box-case-study/)

[![Nvidia Logo](https://www.tigera.io/app/uploads/2024/05/logo-Nvidia.png)](https://www.nvidia.com/)

[![Upwork Logo](https://www.tigera.io/app/uploads/2022/12/logo-upwork.png)](https://www.tigera.io/upwork-case-study/)

GET STARTED

## Three ways to run Calico. One consistent experience.

Calico is available in three editions — all built on the same open-source foundation, all delivering the same core networking, security, and observability capabilities. Start with open source and scale into enterprise features as your needs grow, or go straight to the full platform. Choose based on your operational model — not on whether you’re “ready.”

### Calico Open Source

Community-Supported

The foundation. Calico Open Source delivers high-performance pod networking, network policy enforcement, and core networking capabilities — free, open-source, and community-supported. Millions of developers and organizations already run Calico Open Source in production. It’s the most widely deployed CNI in the industry, and it’s the starting point for everything the Calico platform offers.

- High-performance pod networking with eBPF

- Kubernetes network policy enforcement

- Active open-source community and documentation

- The foundation that Calico Cloud and Calico Enterprise build on

[Get Started](https://www.tigera.io/project-calico/)
[Read the Docs](https://docs.tigera.io/calico/latest/about)

### Calico Cloud

SaaS — Managed by Tigera

The fastest way to get the full Calico experience. Calico Cloud is a fully managed SaaS offering: Tigera handles the infrastructure, upgrades, and operations so your team can focus on securing workloads, not managing the platform itself. Everything in Calico Open Source, plus unified management, Istio and Envoy integration, and enterprise-grade security and observability.

- Everything in Calico Open Source, plus:

- Unified management plane for Calico Open Source, Istio, and Envoy

- Policy recommendations and troubleshooting

- Enterprise-grade network security, threat detection, and observability

- Fully managed; no infrastructure to operate

- Free trial available; start immediately, no credit card required

[Get a Demo](https://www.tigera.io/demo/)
[Start Free](https://www.calicocloud.io/home)

### Calico Enterprise

Self-Hosted — Deployed in Your Environment

For organizations that require full control over where their data lives and how the platform is operated. Calico Enterprise deploys in your own environment (on-premises, air-gapped, or in your own cloud) with the same full feature set as Calico Cloud, backed by enterprise support and SLAs from Tigera.

- Everything in Calico Cloud, plus:

- Full control over deployment and data residency

- Supports air-gapped and on-premises environments

- Enterprise support and SLAs

- Designed for organizations with strict compliance and data sovereignty requirements

[Talk to an Expert](https://www.tigera.io/contact/)
[Get a Demo](https://www.tigera.io/demo/)

## Ready to eliminate the **integration tax?**

Join the platform teams at NVIDIA, RBC, Bloomberg, and hundreds of other organizations who trust Calico to secure their most demanding Kubernetes environments.

[Get a Demo](http://www.tigera.io/demo/)
[Talk to an Expert](http://www.tigera.io/contact/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=8896 metric#misses=37 metric#hit-ratio=99.6 metric#bytes=1928398 metric#prefetches=0 metric#store-reads=303 metric#store-writes=87 metric#store-hits=279 metric#store-misses=26 metric#sql-queries=30 metric#ms-total=854.81 metric#ms-cache=91.89 metric#ms-cache-avg=0.2362 metric#ms-cache-ratio=10.8 -->
