Low-latency, high-availability, scalable networking for cloud-native applications with your choice of dataplane: eBPF, Linux, and Windows HNS.
Kubernetes Network Security
High-availability networking and simplified network security for Kubernetes workloads.
Benefits
Enable simplified network security through extensive network policies, rich policy tools, and policy deployment automation using GitOps practices
Highly Available Networking
Simplified Network Security
Network Observability and Troubleshooting
Solution Architecture
Egress Gateway and Universal Firewall Integration
Enable firewalls to identify the source of traffic when it leaves a Kubernetes cluster.
Eliminate the need to change firewall rules and the risk of exposing entire IP CIDR ranges of nodes.
Enable workloads to access resources such as databases and legacy applications residing behind firewalls.
Cluster Mesh
Run applications on cluster mesh with complete visibility, security, and networking across clusters through a centralized management plane.
Extend network policies to workloads in remote clusters using federated endpoint identity and federated service from a local cluster.
Egress Access Controls
Secure egress access from individual pods in Kubernetes clusters to external resources including databases, external applications, 3rd-party cloud APIs, and SaaS applications.
Enforce DNS policies at the source pod to allow access from a pod or set of pods (via label selector) to external resources.
Microsegmentation
Achieve workload isolation and secure lateral communication between pods, namespaces, and services.
Logically divide workloads into distinct security segments and define granular network policies for each segment.
Leverage policy recommendations to deploy network policies based on traffic flows.
Network Policy Management
Author, stage, preview, enforce, and manage network policies at the workload level. Generate policies to automatically isolate namespaces.
Understand policies’ impact on the application’s performance and security posture before going into production.
Implement hierarchical policy tiers to enforce higher-precedence policies from the enterprise security organization and platform teams that cannot be circumvented by the DevOps team and application developers.
Observability and Troubleshooting
Get a purpose-built live view of workload activities within the Kubernetes cluster, including workload communication, upstream and downstream dependencies, and network policies.
Built-in troubleshooting capabilities to identify and resolve network security and compliance gaps, performance issues, connectivity breakdowns, anomalous behavior, and network policy violations.
Deploy mitigating network security controls in the event of a breach.
Compliance
Observe, maintain, and enforce continuous compliance to adhere to regulatory and custom frameworks such as PCI, SOC 2, GDPR, and HIPAA.
Use templated compliance reports on demand as evidence for audit reporting, or set a pre-determined schedule.
Available on Microsoft Azure, AWS, and Google Marketplace
Get started right away on Azure, AWS, or Google Cloud—every Calico component you need to get up and running is ready to go.
Customer Testimonial
Here’s what our customers are saying about us
Using Calico Enterprise, Aldagi achieved EU GDPR compliance and brought our online services to retail and corporate customers.
Calico is an excellent, lightweight solution that helps Playtech’s developers manage, automate, and troubleshoot security policy and networking operations. Calico’s Policy Lifecycle Management capabilities include visualized graphs and dashboards that are intuitive, user-friendly, and great for daily use.
Featured Resources
Developer-created resources to help you secure your Kubernetes deployment

Container Networking and Network Security
Ready to Get Started?
Get started for free or request a demo to see Calico in action


