Solution

Kubernetes Network Security

High-availability networking and simplified network security for Kubernetes workloads.

Kubernetes network security dashboard showing policies, packet traffic, endpoints, and process instances for

Benefits

Enable simplified network security through extensive network policies, rich policy tools, and policy deployment automation using GitOps practices

Network icon

Highly Available Networking

Fast, scalable, and highly available pod-to-pod networking. Pluggable dataplane—eBPF, Linux, and Windows HNS
Padlock icon with network connections.

Simplified Network Security

Secure egress traffic with DNS policies and networksets. Get policy recommendations for workload isolation
Magnifying glass icon with an exclamation mark.

Network Observability and Troubleshooting

Gain end-to-end traffic visibility to view service connectivity, identify security gaps, and troubleshoot performance issues

Solution Architecture

Self service | CI/CD integration - architecture diagram
Service mesh dashboard view showing policies, traffic, endpoints, and DNS latency, illustrating observability features

High-Availability Networking

Low-latency, high-availability, scalable networking for cloud-native applications with your choice of dataplane: eBPF, Linux, and Windows HNS.

Learn More
Universal Firewall Integration diagram

Egress Gateway and Universal Firewall Integration

Enable firewalls to identify the source of traffic when it leaves a Kubernetes cluster.

Eliminate the need to change firewall rules and the risk of exposing entire IP CIDR ranges of nodes.

Enable workloads to access resources such as databases and legacy applications residing behind firewalls.

Learn More
Cluster Management Connected Screen

Cluster Mesh

Run applications on cluster mesh with complete visibility, security, and networking across clusters through a centralized management plane.

Extend network policies to workloads in remote clusters using federated endpoint identity and federated service from a local cluster.

Learn More
Edit Policy - DNS Policy Screenshot

Egress Access Controls

Secure egress access from individual pods in Kubernetes clusters to external resources including databases, external applications, 3rd-party cloud APIs, and SaaS applications.

Enforce DNS policies at the source pod to allow access from a pod or set of pods (via label selector) to external resources.

Learn More
Policies Board Screenshot

Microsegmentation

Achieve workload isolation and secure lateral communication between pods, namespaces, and services.

Logically divide workloads into distinct security segments and define granular network policies for each segment.

Leverage policy recommendations to deploy network policies based on traffic flows.

Learn More
Recommend Policy Screenshot

Network Policy Management

Author, stage, preview, enforce, and manage network policies at the workload level. Generate policies to automatically isolate namespaces.

Understand policies’ impact on the application’s performance and security posture before going into production.

Implement hierarchical policy tiers to enforce higher-precedence policies from the enterprise security organization and platform teams that cannot be circumvented by the DevOps team and application developers.

Learn More
Service Graph Screenshot

Observability and Troubleshooting

Get a purpose-built live view of workload activities within the Kubernetes cluster, including workload communication, upstream and downstream dependencies, and network policies.

Built-in troubleshooting capabilities to identify and resolve network security and compliance gaps, performance issues, connectivity breakdowns, anomalous behavior, and network policy violations.

Deploy mitigating network security controls in the event of a breach.

Learn More
Compliance report dashboard showing inventory and policy audit results. 100% protected ingress/egress endpoints and

Compliance

Observe, maintain, and enforce continuous compliance to adhere to regulatory and custom frameworks such as PCI, SOC 2, GDPR, and HIPAA.

Use templated compliance reports on demand as evidence for audit reporting, or set a pre-determined schedule.

Learn More

Available on Microsoft Azure, AWS, and Google Marketplace

Get started right away on Azure, AWS, or Google Cloud—every Calico component you need to get up and running is ready to go.

Microsoft Azure, AWS, and Google Cloud logos.

Customer Testimonial

Here’s what our customers are saying about us

Quotation marks
Using Calico Enterprise, Aldagi achieved EU GDPR compliance and brought our online services to retail and corporate customers.
Vasili Grigolaia
Vice President of Engineering,
Aldagi
Aldagi Logo
Read More
Quotation marks
Calico is an excellent, lightweight solution that helps Playtech’s developers manage, automate, and troubleshoot security policy and networking operations. Calico’s Policy Lifecycle Management capabilities include visualized graphs and dashboards that are intuitive, user-friendly, and great for daily use.
DevOps Team Leader,
Playtech
Playtech Logo
Read More

Featured Resources

Developer-created resources to help you secure your Kubernetes deployment

Container Networking and Network Security
Datasheet

Container Networking and Network Security

Kubernetes deployments face unique security challenges. See how Calico can help in this solution datasheet.
Read More
Access Controls for Containerized Workload Protection
White Paper

Access Controls for Containerized Workload Protection

Read our white paper on access controls best practices to secure your containerized workloads.
Read More
Securing Kubernetes Workloads at Discover Financial Services
Video

Securing Kubernetes Workloads at Discover Financial Services

Learn how Discover secured its global, multi-cluster, hybrid cloud deployment with Calico.
Watch the Video
Calico Logo

Ready to Get Started?

Get started for free or request a demo to see Calico in action

X