---
title: "Kubernetes Network Security"
source: "https://www.tigera.io/tigera-products/kubernetes-network-security/"
description: "Secure Kubernetes with Calico network security, using microsegmentation, network policy, and threat detection to stop lateral movement and protect workloads."
---

Solution

# Kubernetes Network Security

High-availability networking and simplified network security for Kubernetes workloads.

[Start Free](https://www.calicocloud.io/)
[Get a Demo](https://www.tigera.io/demo/)

![Kubernetes network security dashboard showing policies, packet traffic, endpoints, and process instances for](https://www.tigera.io/app/uploads/2024/06/Hero-Container-Networking-1200x628-1.png)

## Benefits

Enable simplified network security through extensive network policies, rich policy tools, and policy deployment automation using GitOps practices

![Network icon](https://www.tigera.io/app/uploads/2024/05/icon-networking.svg)

### Highly Available Networking

Fast, scalable, and highly available pod-to-pod networking. Pluggable dataplane—eBPF, Linux, and Windows HNS

![Padlock icon with network connections.](https://www.tigera.io/app/uploads/2024/05/icon-network-security.svg)

### Simplified Network Security

Secure egress traffic with DNS policies and networksets. Get policy recommendations for workload isolation

![Magnifying glass icon with an exclamation mark.](https://www.tigera.io/app/uploads/2023/04/icon-Intrusion-detection-prevention.svg)

### Network Observability and Troubleshooting

Gain end-to-end traffic visibility to view service connectivity, identify security gaps, and troubleshoot performance issues

## Trusted by Customers Worldwide

[![Orange logo](https://www.tigera.io/app/uploads/2022/03/logo-Orange.png)](http://www.orange.com/en)

[![Essentra logo](https://www.tigera.io/app/uploads/2022/04/logo-Essentra.png)](https://www.essentra.com/en)

[![Siemens Healthineers logo](https://www.tigera.io/app/uploads/2022/09/logo-siemens-healthineers.png)](https://www.siemens-healthineers.com/)

[![RBC logo](https://www.tigera.io/app/uploads/2024/05/logo-RBC.png)](https://www.rbcroyalbank.com/)

[![Marsh McLennan logo](https://www.tigera.io/app/uploads/2022/03/logo-Marsh-and-McLennan.png)](http://www.mmc.com/)

[![Presidio logo](https://www.tigera.io/app/uploads/2024/05/logo-Presidio.png)](https://www.presidio.com/)

[![Box logo](https://www.tigera.io/app/uploads/2022/03/logo-box.png)](http://www.box.com/home)

[![Nvidia logo](https://www.tigera.io/app/uploads/2024/05/logo-Nvidia.png)](https://www.nvidia.com/)

[![FM Global logo](https://www.tigera.io/app/uploads/2023/03/logo-FM-Global.png)](https://www.fmglobal.com/)

[![Upwork logo](https://www.tigera.io/app/uploads/2022/12/logo-upwork.png)](https://www.upwork.com/)

[![GoDaddy logo](https://www.tigera.io/app/uploads/2023/03/logo-GoDaddy.png)](https://www.godaddy.com/)

[![Arvato Systems logo](https://www.tigera.io/app/uploads/2025/01/logo-Arvato-systems.png)](https://www.arvato-systems.com/)

[![Aldagi logo](https://www.tigera.io/app/uploads/2022/10/logo-aldagi.png)](https://aldagi.ge/en/)

[![NBC Universal logo](https://www.tigera.io/app/uploads/2022/09/logo-NBC-Universal.png)](https://www.nbcuniversal.com/)

[![Chipotle logo](https://www.tigera.io/app/uploads/2024/05/logo-Chipotle.png)](https://www.chipotle.com/)

[![Meridianlink logo](https://www.tigera.io/app/uploads/2022/03/logo-Meridianlink.png)](http://www.meridianlink.com/)

[![Mulligan Funding logo](https://www.tigera.io/app/uploads/2022/03/logo-MulliganFunding.png)](https://www.mulliganfunding.com/)

[![HanseMerkur logo](https://www.tigera.io/app/uploads/2022/03/logo-HanseMerkur.png)](http://www.hmrv.de/en)

[![Fiserv logo](https://www.tigera.io/app/uploads/2022/12/logo-fiserv.png)](https://www.fiserv.com/)

[![Berenberg logo](https://www.tigera.io/app/uploads/2022/03/logo-BERENBERG.png)](http://www.berenberg.de/en/)

[![eHealth logo](https://www.tigera.io/app/uploads/2023/10/logo-eHealth.png)](https://www.tigera.io/ehealth-case-study/)

[![Coinmetrics logo](https://www.tigera.io/app/uploads/2022/03/logo-coinmetrics.png)](http://coinmetrics.io/)

## Solution Architecture

![Self service | CI/CD integration - architecture diagram](https://www.tigera.io/app/uploads/2025/02/Solution-Architecture-for-Container-Networking-and-Security-2025.svg)

![Service mesh dashboard view showing policies, traffic, endpoints, and DNS latency, illustrating observability features](https://www.tigera.io/app/uploads/2024/05/Networking-Dashboards.png)

### High-Availability Networking

Low-latency, high-availability, scalable networking for cloud-native applications with your choice of dataplane: eBPF, Linux, and Windows HNS.

[Learn More](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-k8s-networking)

![Universal Firewall Integration diagram](https://www.tigera.io/app/uploads/2021/09/Universal-Firewall-Integration-diagram02.png)

### Egress Gateway and Universal Firewall Integration

Enable firewalls to identify the source of traffic when it leaves a Kubernetes cluster.

Eliminate the need to change firewall rules and the risk of exposing entire IP CIDR ranges of nodes.

Enable workloads to access resources such as databases and legacy applications residing behind firewalls.

[Learn More](https://www.tigera.io/tigera-products/egress-gateway/)

![Cluster Management Connected Screen](https://www.tigera.io/app/uploads/2023/04/Managed-Clusters-3.png)

### Cluster Mesh

Run applications on cluster mesh with complete visibility, security, and networking across clusters through a centralized management plane.

Extend network policies to workloads in remote clusters using federated endpoint identity and federated service from a local cluster.

[Learn More](https://www.tigera.io/tigera-products/cluster-mesh/)

![Edit Policy - DNS Policy Screenshot](https://www.tigera.io/app/uploads/2022/09/Edit-Policy-DNS-Policy.png)

### Egress Access Controls

Secure egress access from individual pods in Kubernetes clusters to external resources including databases, external applications, 3rd-party cloud APIs, and SaaS applications.

Enforce DNS policies at the source pod to allow access from a pod or set of pods (via label selector) to external resources.

[Learn More](https://www.tigera.io/features/access-controls/)

![Policies Board Screenshot](https://www.tigera.io/app/uploads/2022/09/Policies-Board-03.png)

### Microsegmentation

Achieve workload isolation and secure lateral communication between pods, namespaces, and services.

Logically divide workloads into distinct security segments and define granular network policies for each segment.

Leverage policy recommendations to deploy network policies based on traffic flows.

[Learn More](https://www.tigera.io/features/microsegmentation/)

![Recommend Policy Screenshot](https://www.tigera.io/app/uploads/2022/09/Recommend-Policy-3.png)

### Network Policy Management

Author, stage, preview, enforce, and manage network policies at the workload level. Generate policies to automatically isolate namespaces.

Understand policies’ impact on the application’s performance and security posture before going into production.

Implement hierarchical policy tiers to enforce higher-precedence policies from the enterprise security organization and platform teams that cannot be circumvented by the DevOps team and application developers.

[Learn More](https://www.tigera.io/features/policy-lifecycle-management/)

![Service Graph Screenshot](https://www.tigera.io/app/uploads/2023/04/service-graph-14.png)

### Observability and Troubleshooting

Get a purpose-built live view of workload activities within the Kubernetes cluster, including workload communication, upstream and downstream dependencies, and network policies.

Built-in troubleshooting capabilities to identify and resolve network security and compliance gaps, performance issues, connectivity breakdowns, anomalous behavior, and network policy violations.

Deploy mitigating network security controls in the event of a breach.

[Learn More](https://www.tigera.io/tigera-products/observability-and-troubleshooting/)

![Compliance report dashboard showing inventory and policy audit results. 100% protected ingress/egress endpoints and](https://www.tigera.io/app/uploads/2024/05/Compliance-Reports-04.png)

### Compliance

Observe, maintain, and enforce continuous compliance to adhere to regulatory and custom frameworks such as PCI, SOC 2, GDPR, and HIPAA.

Use templated compliance reports on demand as evidence for audit reporting, or set a pre-determined schedule.

[Learn More](https://www.tigera.io/features/compliance-and-audit/)

## Available on Microsoft Azure, AWS, and Google Marketplace

Get started right away on Azure, AWS, or Google Cloud—every Calico component you need to get up and running is ready to go.

[On Azure](https://azuremarketplace.microsoft.com/en-ca/marketplace/apps/tigerainc1620235671643.calicocloudsaas?tab=overview)
[On AWS](https://aws.amazon.com/marketplace/pp/prodview-pq3tgvtlj3wce)
[On Google Cloud](https://console.cloud.google.com/marketplace/product/tigera-public/calico-cloud?inv=1&invt=Ab27_g&project=tigera-public)

![Microsoft Azure, AWS, and Google Cloud logos.](https://www.tigera.io/app/uploads/2025/07/Solution-cloud-marketplace-AWS-Azure-03.svg)

## Customer Testimonial

Here’s what our customers are saying about us

![Quotation marks](https://www.tigera.io/app/themes/tigera2021/dist/img/quotes-sign.svg)

Using Calico Enterprise, Aldagi achieved EU GDPR compliance and brought our online services to retail and corporate customers.

Vasili Grigolaia

Vice President of Engineering,
Aldagi

![Aldagi Logo](https://www.tigera.io/app/uploads/2023/03/logo-Algagi-170x60-1.png)

[Read More](https://www.tigera.io/aldagi-case-study/)

Calico is an excellent, lightweight solution that helps Playtech’s developers manage, automate, and troubleshoot security policy and networking operations. Calico’s Policy Lifecycle Management capabilities include visualized graphs and dashboards that are intuitive, user-friendly, and great for daily use.

DevOps Team Leader,
Playtech

![Playtech Logo](https://www.tigera.io/app/uploads/2024/05/logo-Playtech-170x60-1.png)

[Read More](https://www.tigera.io/playtech-case-study/)

[Read Customer Stories](https://www.tigera.io/customer-stories/)

## Featured Resources

Developer-created resources to help you secure your Kubernetes deployment

![Container Networking and Network Security](https://www.tigera.io/app/uploads/2024/05/Featured-resources-Container-Networking-Network-Security.png)

Datasheet

### Container Networking and Network Security

Kubernetes deployments face unique security challenges. See how Calico can help in this solution datasheet.

[Read More](https://info.tigera.io/rs/805-GFH-732/images/Tigera_solution_datasheet_Calico_for_Container_Networking_and_Security.pdf)

![Access Controls for Containerized Workload Protection](https://www.tigera.io/app/uploads/2023/04/Featured-resources-Workload-WP.png)

White Paper

### Access Controls for Containerized Workload Protection

Read our white paper on access controls best practices to secure your containerized workloads.

[Read More](https://www.tigera.io/lp/workload-access-controls/)

![Securing Kubernetes Workloads at Discover Financial Services](https://www.tigera.io/app/uploads/2023/05/Featured-resources-video.png)

Video

### Securing Kubernetes Workloads at Discover Financial Services

Learn how Discover secured its global, multi-cluster, hybrid cloud deployment with Calico.

[Watch the Video](https://tigera.wistia.com/medias/3wfacsc2ys)

[All Resources](https://www.tigera.io/resources/)

![Calico Logo](https://www.tigera.io/app/uploads/2026/01/Calico-logo-2026-black-text.svg)

## Ready to Get Started?

Get started for free or request a demo to see Calico in action

<!-- plugin=object-cache-pro client=phpredis metric#hits=9643 metric#misses=21 metric#hit-ratio=99.8 metric#bytes=2657378 metric#prefetches=0 metric#store-reads=530 metric#store-writes=84 metric#store-hits=566 metric#store-misses=10 metric#sql-queries=44 metric#ms-total=1033.29 metric#ms-cache=71.78 metric#ms-cache-avg=0.1171 metric#ms-cache-ratio=7.0 sample#redis-hits=65194673 sample#redis-misses=8685576 sample#redis-hit-ratio=88.2 sample#redis-ops-per-sec=322 sample#redis-evicted-keys=0 sample#redis-used-memory=132039368 sample#redis-used-memory-rss=107315200 sample#redis-memory-fragmentation-ratio=0.8 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=116180 -->
