Calico¶
Summary
Calico is Tigera's open-source (Apache 2.0) CNI and network policy engine for Kubernetes, VMs and bare metal. It routes pod traffic with BGP, VXLAN or IP-in-IP and enforces policy through a choice of data planes: iptables, nftables, eBPF, Windows HNS and the userspace VPP data plane. The current line is Calico Open Source 3.32 (latest patch v3.32.2, 2026-08-29). Recent releases added open-source flow logs (Goldmane + the Whisker UI), a Gateway API ingress built on Envoy Gateway, a GA nftables data plane, upstream ClusterNetworkPolicy, and a move from the aggregated API server to native CRDs.
Overview¶
Calico is a mature, pluggable networking and network security project. It offers more data plane choices than most CNIs, one of the most complete network policy models in Kubernetes (ordered tiers, deny/pass actions, global and host policy, staged policies), and the same policy model for workloads outside Kubernetes. Tigera sells two commercial editions on top of it: Calico Enterprise (self-managed) and Calico Cloud (SaaS), plus a free single-cluster Calico Cloud Free Tier.
Key Facts¶
| Attribute | Detail |
|---|---|
| Repository | github.com/projectcalico/calico (monorepo; the Tigera Operator now lives here too) |
| Latest Version | v3.32.2 (2026-08-29); v3.31.7 (2026-08-20) also supported |
| Release cadence | Minor release about every 6 months; the two newest minors get patches |
| Kubernetes tested | 1.34, 1.35, 1.36 (Calico 3.32) |
| Operator | Tigera Operator v1.42.6 (ships with v3.32.2) |
| Language | Go (Felix, Typha, CNI, operator), C (BIRD, eBPF programs), JavaScript web app (Whisker UI) |
| License | Apache 2.0 (Open Source); proprietary (Enterprise and Cloud) |
| Company | Tigera, Inc.; not a CNCF project |
| Data Planes | iptables (default), nftables (GA 3.31), eBPF, Windows HNS, VPP |
| Minimum kernel | Linux 5.10 (eBPF also runs on RHEL 8.4 kernel 4.18.0-305+); nftables needs 5.13+ |
| Images | quay.io/calico/*, operator quay.io/tigera/operator |
| Adoption | Project README cites 8M+ nodes daily across 166 countries and 200+ contributors |
| Stars | ~6k+ (as of 2026-07) |
Editions¶
| Edition | Summary |
|---|---|
| Calico Open Source | Free, Apache 2.0. Networking, IPAM, BGP, all data planes, Kubernetes and Calico policy with tiers, staged policies, WireGuard, Goldmane/Whisker flow logs (tech preview), Calico Ingress Gateway, Istio ambient (tech preview in 3.32) |
| Calico Cloud Free Tier | Free hosted console for one cluster; observability and policy management fed by Goldmane |
| Calico Cloud | Managed SaaS; adds multi-cluster management, DNS policy, egress gateways, dashboards, WAF, AI Assistant |
| Calico Enterprise | Self-managed commercial edition; latest GA 3.23.2 (2026-08-27), 3.24 in early preview |
Details and feature status are in Reference: Editions.
What's New (3.30 to 3.32)¶
| Release | Highlights |
|---|---|
| 3.32 (2026-04-30) | Native projectcalico.org/v3 CRDs (tech preview) and deprecation of the aggregated API server; upstream ClusterNetworkPolicy (AdminNetworkPolicy removed); bundled Istio ambient mode (tech preview); KubeVirt VM live migration over BGP; Maglev load balancing in eBPF; Whisker filtering; Kubernetes 1.36 |
| 3.31 (2025-10-22) | nftables data plane GA; Calico Ingress Gateway GA; operator-driven eBPF install that disables kube-proxy; DSCP marking and eBPF QoS; eBPF LRU conntrack; per-peer BGP local AS |
| 3.30 (2025-05-05) | Whisker UI and Goldmane flow-logs API (tech preview); staged network policies; Calico Ingress Gateway (tech preview); LoadBalancer IPAM; QoS controls; host endpoint templates; FIPS mode deprecated |
Enterprise and Cloud only
Tigera's "Winter 2026" and "Spring 2026" announcements (AI Assistant, Calico Load Balancer, L2 networking for VM migration, Ingress Gateway dashboard, "last evaluated" policy view) are Calico Enterprise and Calico Cloud features, not Calico Open Source. Some related building blocks, such as Maglev and KubeVirt live migration, did land in Open Source 3.32.
Evaluation¶
| Pros | Cons |
|---|---|
| Five data planes, more choice than any other major CNI | Advanced features (DNS policy, egress gateway, federation, UI) need a paid edition |
| Rich policy model: tiers, Deny/Pass, global, host and staged policies, ClusterNetworkPolicy | Complex configuration for BGP and large clusters |
| Extends policy to VMs, bare metal and OpenStack | eBPF mode has limits (no IP-in-IP, no GKE, no mixed nodes); ecosystem smaller than Cilium's |
| Native BGP for routable pod IPs on-prem | Whisker/Goldmane flow logs are still tech preview and less deep than Hubble |
| Open-source Gateway API ingress (Envoy Gateway) and Istio ambient bundle | API migration (aggregated server to native CRDs) adds upgrade steps |
| Tests three Kubernetes minors per release; Windows support | Community smaller than Cilium's |
Good fit: on-prem or hybrid clusters that peer with the data center over BGP, mixed Linux/Windows clusters, teams that want ordered policy tiers, and environments that also need to protect VMs or hosts. Consider alternatives when you want eBPF-native L7 observability and service mesh in one open-source project (see Cilium) or only need a simple overlay (Flannel).
Architecture¶
The compact diagram shows how state flows from the Kubernetes API to each node. The full component diagram is in Explanation: How It Works.
flowchart LR
subgraph CP["Control plane (calico-system)"]
OP["Tigera Operator"]
APISRV["kube-apiserver<br/>+ Calico CRDs"]
TYPHA["Typha<br/>(fan-out)"]
GM["Goldmane"]
WH["Whisker UI"]
end
subgraph Node["Each node: calico-node"]
FELIX["Felix"]
CONFD["confd"]
BIRD["BIRD (BGP)"]
DP["iptables / nftables / eBPF"]
end
OP -->|"reconciles"| TYPHA
APISRV -->|"watch"| TYPHA
TYPHA -->|"updates"| FELIX
TYPHA -->|"BGP config"| CONFD
CONFD --> BIRD
FELIX -->|"programs"| DP
FELIX -->|"flows"| GM
GM --> WH
BIRD -->|"routes"| FABRIC["Other nodes / ToR routers"]
Topic Map¶
- How-to Guides: install (manifests, Helm, native v3 CRDs), switch to eBPF or nftables, enable Whisker, set up the ingress gateway, WireGuard, BGP, policies, upgrades, troubleshooting, Commands & Recipes
- Reference: release and support matrix, editions, feature status, data plane matrix, ports, Felix keys, operator resources, sizing, Benchmarks
- Explanation: How It Works, data planes, policy tiers, Goldmane/Whisker pipeline, ingress gateway, encryption, threat model
Related Topics¶
- CNI Comparison: Cilium vs Calico vs Flannel
- Networking comparisons index
- Sibling CNIs: Cilium, Flannel
- Kubernetes: where the CNI fits in the cluster
- Envoy Gateway: upstream of Calico Ingress Gateway
- Istio: ambient mode bundled with Calico 3.32 and Dikastes application layer policy
- OpenStack: Calico's Neutron driver and VM live migration support
- eBPF developer tutorial: background for the eBPF data plane
Sources¶
- Calico Open Source documentation
- Calico Open Source release notes
- Component architecture
- System requirements
- eBPF data plane
- Calico Ingress Gateway
- Whisker flow logs
- GitHub: projectcalico/calico and releases
- Tigera docs source (release notes, feature status)
- endoflife.date: Calico
- What's New in Calico v3.32 (Tigera blog)
- Calico Winter 2026 release (Tigera blog)
- Calico Spring 2026 release (Tigera blog)
- Calico Enterprise release notes
- Tigera Blog: product announcements
Questions¶
Open¶
- What is the performance delta between Calico eBPF and Cilium eBPF at scale? No independent, reproducible benchmark on current versions (3.32 vs Cilium 1.19) was found.
- When will Whisker and Goldmane reach GA in Calico Open Source? Still tech preview in 3.32.
- When will the aggregated API server be removed? Deprecated in 3.32; the next release only changes the default for new installs.
- What is the VPP data plane's support status? Calico docs present it as an install option, but the upstream README still says "incubation".
Answered¶
- Q: Can Calico run without kube-proxy? Yes. The eBPF and VPP data planes replace kube-proxy; since 3.31 the operator can disable kube-proxy automatically (
kubeProxyManagement: Enabled). - Q: Does Calico support Windows? Yes, via the Windows Host Networking Service (HNS) data plane, installable by the operator.
- Q: Does Calico Open Source have flow logs? Yes, since 3.30: Goldmane aggregates flows and Whisker displays them (tech preview).
- Q: Does Calico support the Gateway API? Yes. Calico Ingress Gateway (Envoy Gateway based) is GA since 3.31.
- Q: How does Calico's AI Assistant compare to manual policy authoring? The AI Assistant (Winter 2026) and policy recommendations are Calico Enterprise and Cloud features. Policy recommendations analyze observed traffic and suggest policies, which helps bootstrap zero-trust isolation. Manual authoring with
kubectlorcalicoctlstill gives full control over selectors, tiers and ordering, which complex multi-tenant setups need. Related: Explanation: Policy Tiers.