Skip to content

Calico

Summary

Calico is Tigera's open-source (Apache 2.0) CNI and network policy engine for Kubernetes, VMs and bare metal. It routes pod traffic with BGP, VXLAN or IP-in-IP and enforces policy through a choice of data planes: iptables, nftables, eBPF, Windows HNS and the userspace VPP data plane. The current line is Calico Open Source 3.32 (latest patch v3.32.2, 2026-08-29). Recent releases added open-source flow logs (Goldmane + the Whisker UI), a Gateway API ingress built on Envoy Gateway, a GA nftables data plane, upstream ClusterNetworkPolicy, and a move from the aggregated API server to native CRDs.

Overview

Calico is a mature, pluggable networking and network security project. It offers more data plane choices than most CNIs, one of the most complete network policy models in Kubernetes (ordered tiers, deny/pass actions, global and host policy, staged policies), and the same policy model for workloads outside Kubernetes. Tigera sells two commercial editions on top of it: Calico Enterprise (self-managed) and Calico Cloud (SaaS), plus a free single-cluster Calico Cloud Free Tier.

Key Facts

Attribute Detail
Repository github.com/projectcalico/calico (monorepo; the Tigera Operator now lives here too)
Latest Version v3.32.2 (2026-08-29); v3.31.7 (2026-08-20) also supported
Release cadence Minor release about every 6 months; the two newest minors get patches
Kubernetes tested 1.34, 1.35, 1.36 (Calico 3.32)
Operator Tigera Operator v1.42.6 (ships with v3.32.2)
Language Go (Felix, Typha, CNI, operator), C (BIRD, eBPF programs), JavaScript web app (Whisker UI)
License Apache 2.0 (Open Source); proprietary (Enterprise and Cloud)
Company Tigera, Inc.; not a CNCF project
Data Planes iptables (default), nftables (GA 3.31), eBPF, Windows HNS, VPP
Minimum kernel Linux 5.10 (eBPF also runs on RHEL 8.4 kernel 4.18.0-305+); nftables needs 5.13+
Images quay.io/calico/*, operator quay.io/tigera/operator
Adoption Project README cites 8M+ nodes daily across 166 countries and 200+ contributors
Stars ~6k+ (as of 2026-07)

Editions

Edition Summary
Calico Open Source Free, Apache 2.0. Networking, IPAM, BGP, all data planes, Kubernetes and Calico policy with tiers, staged policies, WireGuard, Goldmane/Whisker flow logs (tech preview), Calico Ingress Gateway, Istio ambient (tech preview in 3.32)
Calico Cloud Free Tier Free hosted console for one cluster; observability and policy management fed by Goldmane
Calico Cloud Managed SaaS; adds multi-cluster management, DNS policy, egress gateways, dashboards, WAF, AI Assistant
Calico Enterprise Self-managed commercial edition; latest GA 3.23.2 (2026-08-27), 3.24 in early preview

Details and feature status are in Reference: Editions.

What's New (3.30 to 3.32)

Release Highlights
3.32 (2026-04-30) Native projectcalico.org/v3 CRDs (tech preview) and deprecation of the aggregated API server; upstream ClusterNetworkPolicy (AdminNetworkPolicy removed); bundled Istio ambient mode (tech preview); KubeVirt VM live migration over BGP; Maglev load balancing in eBPF; Whisker filtering; Kubernetes 1.36
3.31 (2025-10-22) nftables data plane GA; Calico Ingress Gateway GA; operator-driven eBPF install that disables kube-proxy; DSCP marking and eBPF QoS; eBPF LRU conntrack; per-peer BGP local AS
3.30 (2025-05-05) Whisker UI and Goldmane flow-logs API (tech preview); staged network policies; Calico Ingress Gateway (tech preview); LoadBalancer IPAM; QoS controls; host endpoint templates; FIPS mode deprecated

Enterprise and Cloud only

Tigera's "Winter 2026" and "Spring 2026" announcements (AI Assistant, Calico Load Balancer, L2 networking for VM migration, Ingress Gateway dashboard, "last evaluated" policy view) are Calico Enterprise and Calico Cloud features, not Calico Open Source. Some related building blocks, such as Maglev and KubeVirt live migration, did land in Open Source 3.32.

Evaluation

Pros Cons
Five data planes, more choice than any other major CNI Advanced features (DNS policy, egress gateway, federation, UI) need a paid edition
Rich policy model: tiers, Deny/Pass, global, host and staged policies, ClusterNetworkPolicy Complex configuration for BGP and large clusters
Extends policy to VMs, bare metal and OpenStack eBPF mode has limits (no IP-in-IP, no GKE, no mixed nodes); ecosystem smaller than Cilium's
Native BGP for routable pod IPs on-prem Whisker/Goldmane flow logs are still tech preview and less deep than Hubble
Open-source Gateway API ingress (Envoy Gateway) and Istio ambient bundle API migration (aggregated server to native CRDs) adds upgrade steps
Tests three Kubernetes minors per release; Windows support Community smaller than Cilium's

Good fit: on-prem or hybrid clusters that peer with the data center over BGP, mixed Linux/Windows clusters, teams that want ordered policy tiers, and environments that also need to protect VMs or hosts. Consider alternatives when you want eBPF-native L7 observability and service mesh in one open-source project (see Cilium) or only need a simple overlay (Flannel).

Architecture

The compact diagram shows how state flows from the Kubernetes API to each node. The full component diagram is in Explanation: How It Works.

flowchart LR
    subgraph CP["Control plane (calico-system)"]
        OP["Tigera Operator"]
        APISRV["kube-apiserver<br/>+ Calico CRDs"]
        TYPHA["Typha<br/>(fan-out)"]
        GM["Goldmane"]
        WH["Whisker UI"]
    end

    subgraph Node["Each node: calico-node"]
        FELIX["Felix"]
        CONFD["confd"]
        BIRD["BIRD (BGP)"]
        DP["iptables / nftables / eBPF"]
    end

    OP -->|"reconciles"| TYPHA
    APISRV -->|"watch"| TYPHA
    TYPHA -->|"updates"| FELIX
    TYPHA -->|"BGP config"| CONFD
    CONFD --> BIRD
    FELIX -->|"programs"| DP
    FELIX -->|"flows"| GM
    GM --> WH
    BIRD -->|"routes"| FABRIC["Other nodes / ToR routers"]

Topic Map

  • How-to Guides: install (manifests, Helm, native v3 CRDs), switch to eBPF or nftables, enable Whisker, set up the ingress gateway, WireGuard, BGP, policies, upgrades, troubleshooting, Commands & Recipes
  • Reference: release and support matrix, editions, feature status, data plane matrix, ports, Felix keys, operator resources, sizing, Benchmarks
  • Explanation: How It Works, data planes, policy tiers, Goldmane/Whisker pipeline, ingress gateway, encryption, threat model

Sources

Questions

Open

  • What is the performance delta between Calico eBPF and Cilium eBPF at scale? No independent, reproducible benchmark on current versions (3.32 vs Cilium 1.19) was found.
  • When will Whisker and Goldmane reach GA in Calico Open Source? Still tech preview in 3.32.
  • When will the aggregated API server be removed? Deprecated in 3.32; the next release only changes the default for new installs.
  • What is the VPP data plane's support status? Calico docs present it as an install option, but the upstream README still says "incubation".

Answered

  • Q: Can Calico run without kube-proxy? Yes. The eBPF and VPP data planes replace kube-proxy; since 3.31 the operator can disable kube-proxy automatically (kubeProxyManagement: Enabled).
  • Q: Does Calico support Windows? Yes, via the Windows Host Networking Service (HNS) data plane, installable by the operator.
  • Q: Does Calico Open Source have flow logs? Yes, since 3.30: Goldmane aggregates flows and Whisker displays them (tech preview).
  • Q: Does Calico support the Gateway API? Yes. Calico Ingress Gateway (Envoy Gateway based) is GA since 3.31.
  • Q: How does Calico's AI Assistant compare to manual policy authoring? The AI Assistant (Winter 2026) and policy recommendations are Calico Enterprise and Cloud features. Policy recommendations analyze observed traffic and suggest policies, which helps bootstrap zero-trust isolation. Manual authoring with kubectl or calicoctl still gives full control over selectors, tiers and ordering, which complex multi-tenant setups need. Related: Explanation: Policy Tiers.