---
title: "Reference"
description: "Reference content for Calico Cloud including resource definitions, APIs, architecture, host endpoints, and component resources for connected clusters."
product: "Calico Cloud"
version: "v23.0.1"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico-cloud/reference/"
---

# Reference

APIs, CLI, architecture and design, and FAQ.

## API and installation references

##### [Tigera Client library](https://docs.tigera.io/calico-cloud/reference/api.md)

[Calico Cloud Go client library reference for working with cluster resources programmatically against the Calico Cloud API in connected clusters.](https://docs.tigera.io/calico-cloud/reference/api.md)

##### [Installation reference](https://docs.tigera.io/calico-cloud/reference/installation/api.md)

[Installation API reference for Calico Cloud listing the operator-managed custom resources used to configure connected cluster installation.](https://docs.tigera.io/calico-cloud/reference/installation/api.md)

##### [REST API Reference](https://docs.tigera.io/calico-cloud/reference/rest-api-reference)

[REST API reference index for Calico Cloud covering the SaaS management plane endpoints used by the Calico Cloud web console.](https://docs.tigera.io/calico-cloud/reference/rest-api-reference)

## Resource definitions

##### [Resource definitions](https://docs.tigera.io/calico-cloud/reference/resources/overview.md)

[Reference overview of the Calico Cloud API resources, including the manifest format and how kubectl manages them in connected clusters.](https://docs.tigera.io/calico-cloud/reference/resources/overview.md)

##### [BFD configuration](https://docs.tigera.io/calico-cloud/reference/resources/bfdconfig.md)

[Reference for the BFD configuration resource in Calico Cloud connected clusters that tunes Bidirectional Forwarding Detection on BGP-peered nodes.](https://docs.tigera.io/calico-cloud/reference/resources/bfdconfig.md)

##### [BGP configuration](https://docs.tigera.io/calico-cloud/reference/resources/bgpconfig.md)

[Reference for the BGPConfiguration resource in Calico Cloud connected clusters that sets cluster-wide BGP options including route reflectors and AS number.](https://docs.tigera.io/calico-cloud/reference/resources/bgpconfig.md)

##### [BGP peer](https://docs.tigera.io/calico-cloud/reference/resources/bgppeer.md)

[Reference for the BGPPeer resource in Calico Cloud connected clusters that defines BGP neighbor relationships with external routers or other Calico nodes.](https://docs.tigera.io/calico-cloud/reference/resources/bgppeer.md)

##### [BGP Filter](https://docs.tigera.io/calico-cloud/reference/resources/bgpfilter.md)

[Reference for the BGPFilter resource in Calico Cloud connected clusters that filters routes imported from or exported to BGP peers.](https://docs.tigera.io/calico-cloud/reference/resources/bgpfilter.md)

##### [Block affinity](https://docs.tigera.io/calico-cloud/reference/resources/blockaffinity.md)

[Reference for the BlockAffinity resource in Calico Cloud connected clusters that records which node owns each IP address management block.](https://docs.tigera.io/calico-cloud/reference/resources/blockaffinity.md)

##### [Calico node status](https://docs.tigera.io/calico-cloud/reference/resources/caliconodestatus.md)

[Reference for the CalicoNodeStatus resource in Calico Cloud connected clusters that exposes per-node agent, BGP, and routing state.](https://docs.tigera.io/calico-cloud/reference/resources/caliconodestatus.md)

##### [Compliance reports (deprecated)](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/overview.md)

[Reference overview of compliance reporting in Calico Cloud connected clusters covering schedules, report scope, and the GlobalReport resource.](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/overview.md)

##### [Inventory report](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/inventory.md)

[Reference for the inventory compliance report in Calico Cloud connected clusters that catalogs endpoints, namespaces, and policies in scope at report time.](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/inventory.md)

##### [Network Access report](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/network-access.md)

[Reference for the network access compliance report in Calico Cloud connected clusters that summarizes which endpoints could communicate based on policy.](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/network-access.md)

##### [Policy audit report](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/policy-audit.md)

[Reference for the policy audit compliance report in Calico Cloud connected clusters that records changes to network policies during the report period.](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/policy-audit.md)

##### [CIS benchmark report](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/cis-benchmark.md)

[Reference for the CIS benchmark compliance report in Calico Cloud connected clusters that audits Kubernetes nodes against CIS recommendations.](https://docs.tigera.io/calico-cloud/reference/resources/compliance-reports/cis-benchmark.md)

##### [Deep packet inspection](https://docs.tigera.io/calico-cloud/reference/resources/deeppacketinspection.md)

[Reference for the DeepPacketInspection resource in Calico Cloud connected clusters that defines workloads to scan with the Snort-based IDS engine.](https://docs.tigera.io/calico-cloud/reference/resources/deeppacketinspection.md)

##### [Felix configuration](https://docs.tigera.io/calico-cloud/reference/resources/felixconfig.md)

[Reference for the FelixConfiguration resource in Calico Cloud connected clusters that controls Felix data plane behavior cluster-wide.](https://docs.tigera.io/calico-cloud/reference/resources/felixconfig.md)

##### [Egress gateway policy](https://docs.tigera.io/calico-cloud/reference/resources/egressgatewaypolicy.md)

[Reference for the EgressGatewayPolicy resource in Calico Cloud connected clusters that selects which pods route through which egress gateways.](https://docs.tigera.io/calico-cloud/reference/resources/egressgatewaypolicy.md)

##### [Global Alert](https://docs.tigera.io/calico-cloud/reference/resources/globalalert.md)

[Reference for the GlobalAlert resource in Calico Cloud connected clusters that defines an alerting query against flow, audit, or DNS logs.](https://docs.tigera.io/calico-cloud/reference/resources/globalalert.md)

##### [Global network policy](https://docs.tigera.io/calico-cloud/reference/resources/globalnetworkpolicy.md)

[Reference for the GlobalNetworkPolicy resource in Calico Cloud, a cluster-scoped tiered policy that selects endpoints across all namespaces in a connected cluster.](https://docs.tigera.io/calico-cloud/reference/resources/globalnetworkpolicy.md)

##### [Global network set](https://docs.tigera.io/calico-cloud/reference/resources/globalnetworkset.md)

[Reference for the GlobalNetworkSet resource in Calico Cloud connected clusters that defines a cluster-scoped set of CIDRs referenced by tiered network policy.](https://docs.tigera.io/calico-cloud/reference/resources/globalnetworkset.md)

##### [Global report](https://docs.tigera.io/calico-cloud/reference/resources/globalreport.md)

[Reference for the GlobalReport resource in Calico Cloud connected clusters that schedules compliance reports against cluster network and policy state.](https://docs.tigera.io/calico-cloud/reference/resources/globalreport.md)

##### [Global threat feed](https://docs.tigera.io/calico-cloud/reference/resources/globalthreatfeed.md)

[Reference for the GlobalThreatFeed resource in Calico Cloud connected clusters that pulls indicators of compromise into Calico-managed network sets.](https://docs.tigera.io/calico-cloud/reference/resources/globalthreatfeed.md)

##### [Host endpoint](https://docs.tigera.io/calico-cloud/reference/resources/hostendpoint.md)

[Reference for the HostEndpoint resource in Calico Cloud connected clusters that represents a host network interface for tiered policy enforcement.](https://docs.tigera.io/calico-cloud/reference/resources/hostendpoint.md)

##### [IP pool](https://docs.tigera.io/calico-cloud/reference/resources/ippool.md)

[Reference for the IPPool resource in Calico Cloud connected clusters that defines CIDRs available for pod IP address allocation.](https://docs.tigera.io/calico-cloud/reference/resources/ippool.md)

##### [IP reservation](https://docs.tigera.io/calico-cloud/reference/resources/ipreservation.md)

[Reference for the IPReservation resource in Calico Cloud connected clusters that excludes specific addresses or ranges from automatic allocation.](https://docs.tigera.io/calico-cloud/reference/resources/ipreservation.md)

##### [IPAM configuration](https://docs.tigera.io/calico-cloud/reference/resources/ipamconfig.md)

[Reference for the IP address management configuration resource in Calico Cloud connected clusters that sets cluster-wide IPAM options.](https://docs.tigera.io/calico-cloud/reference/resources/ipamconfig.md)

##### [License key](https://docs.tigera.io/calico-cloud/reference/resources/licensekey.md)

[Reference for the LicenseKey resource in Calico Cloud connected clusters that activates entitled features.](https://docs.tigera.io/calico-cloud/reference/resources/licensekey.md)

##### [Kubernetes controllers configuration](https://docs.tigera.io/calico-cloud/reference/resources/kubecontrollersconfig.md)

[Reference for the KubeControllersConfiguration resource in Calico Cloud connected clusters that controls behavior of the kube-controllers component.](https://docs.tigera.io/calico-cloud/reference/resources/kubecontrollersconfig.md)

##### [Managed Cluster](https://docs.tigera.io/calico-cloud/reference/resources/managedcluster.md)

[Reference for the ManagedCluster resource in Calico Cloud that registers a workload cluster with the Calico Cloud management plane.](https://docs.tigera.io/calico-cloud/reference/resources/managedcluster.md)

##### [Network policy](https://docs.tigera.io/calico-cloud/reference/resources/networkpolicy.md)

[Reference for the NetworkPolicy resource in Calico Cloud, a namespaced tiered policy that selects pods within a single namespace in a connected cluster.](https://docs.tigera.io/calico-cloud/reference/resources/networkpolicy.md)

##### [Network set](https://docs.tigera.io/calico-cloud/reference/resources/networkset.md)

[Reference for the NetworkSet resource in Calico Cloud connected clusters that defines a namespaced set of CIDRs referenced by tiered network policy.](https://docs.tigera.io/calico-cloud/reference/resources/networkset.md)

##### [Node](https://docs.tigera.io/calico-cloud/reference/resources/node.md)

[Reference for the Node resource in Calico Cloud connected clusters that represents a host running the cnx-node agent.](https://docs.tigera.io/calico-cloud/reference/resources/node.md)

##### [PacketCapture](https://docs.tigera.io/calico-cloud/reference/resources/packetcapture.md)

[Reference for the PacketCapture resource in Calico Cloud connected clusters that captures pcap files from selected workloads for offline analysis.](https://docs.tigera.io/calico-cloud/reference/resources/packetcapture.md)

##### [Remote cluster configuration](https://docs.tigera.io/calico-cloud/reference/resources/remoteclusterconfiguration.md)

[Reference for the RemoteClusterConfiguration resource in Calico Cloud that federates resources between connected clusters for shared identity.](https://docs.tigera.io/calico-cloud/reference/resources/remoteclusterconfiguration.md)

##### [Security event webhook](https://docs.tigera.io/calico-cloud/reference/resources/securityeventwebhook.md)

[Reference for the SecurityEventWebhook resource in Calico Cloud connected clusters that forwards security events to external systems such as Slack or Jira.](https://docs.tigera.io/calico-cloud/reference/resources/securityeventwebhook.md)

##### [Staged global network policy](https://docs.tigera.io/calico-cloud/reference/resources/stagedglobalnetworkpolicy.md)

[Reference for the StagedGlobalNetworkPolicy resource in Calico Cloud connected clusters that previews cluster-scoped tiered policy without enforcing it.](https://docs.tigera.io/calico-cloud/reference/resources/stagedglobalnetworkpolicy.md)

##### [Staged Kubernetes network policy](https://docs.tigera.io/calico-cloud/reference/resources/stagedkubernetesnetworkpolicy.md)

[Reference for the StagedKubernetesNetworkPolicy resource in Calico Cloud connected clusters that previews Kubernetes network policy without enforcing it.](https://docs.tigera.io/calico-cloud/reference/resources/stagedkubernetesnetworkpolicy.md)

##### [Staged network policy](https://docs.tigera.io/calico-cloud/reference/resources/stagednetworkpolicy.md)

[Reference for the StagedNetworkPolicy resource in Calico Cloud connected clusters that previews namespaced tiered policy without enforcing it.](https://docs.tigera.io/calico-cloud/reference/resources/stagednetworkpolicy.md)

##### [Tier](https://docs.tigera.io/calico-cloud/reference/resources/tier.md)

[Reference for the Tier resource in Calico Cloud connected clusters that groups tiered policies into ordered evaluation buckets.](https://docs.tigera.io/calico-cloud/reference/resources/tier.md)

##### [Workload endpoint](https://docs.tigera.io/calico-cloud/reference/resources/workloadendpoint.md)

[Reference for the WorkloadEndpoint resource in Calico Cloud connected clusters that represents a pod or VM interface for policy and IPAM.](https://docs.tigera.io/calico-cloud/reference/resources/workloadendpoint.md)

## Component resources

##### [Configuring the Calico Cloud CNI plugins](https://docs.tigera.io/calico-cloud/reference/component-resources/configuration.md)

[Reference for configuring the CNI plugin in Calico Cloud connected clusters covering operator-managed and manifest-mode CNI options.](https://docs.tigera.io/calico-cloud/reference/component-resources/configuration.md)

##### [Configure resource requests and limits](https://docs.tigera.io/calico-cloud/reference/component-resources/configure-resources.md)

[Reference for setting Kubernetes resource requests and limits on Calico Cloud components managed by the Tigera Operator in connected clusters.](https://docs.tigera.io/calico-cloud/reference/component-resources/configure-resources.md)

##### [Monitoring kube-controllers with Prometheus](https://docs.tigera.io/calico-cloud/reference/component-resources/kube-controllers/prometheus.md)

[Prometheus metrics reference for the kube-controllers component in Calico Cloud connected clusters covering reconcile latency and queue depth.](https://docs.tigera.io/calico-cloud/reference/component-resources/kube-controllers/prometheus.md)

##### [Configuring cnx-node](https://docs.tigera.io/calico-cloud/reference/component-resources/node/configuration.md)

[Reference for configuring the cnx-node container in Calico Cloud connected clusters through environment variables that control Felix, BIRD, and confd.](https://docs.tigera.io/calico-cloud/reference/component-resources/node/configuration.md)

##### [Configuring Felix](https://docs.tigera.io/calico-cloud/reference/component-resources/node/felix/configuration.md)

[Reference for Felix configuration parameters in Calico Cloud connected clusters covering environment variables, FelixConfiguration fields, and per-node overrides.](https://docs.tigera.io/calico-cloud/reference/component-resources/node/felix/configuration.md)

##### [Monitoring Felix with Prometheus](https://docs.tigera.io/calico-cloud/reference/component-resources/node/felix/prometheus.md)

[Prometheus metrics reference for Felix in Calico Cloud connected clusters covering counters and gauges exposed for data plane health and policy evaluation.](https://docs.tigera.io/calico-cloud/reference/component-resources/node/felix/prometheus.md)

## Configuration on public clouds

##### [Amazon Web Services](https://docs.tigera.io/calico-cloud/reference/public-cloud/aws.md)

[Reference for connecting Calico Cloud clusters running on Amazon Web Services covering supported networking modes and AWS platform notes.](https://docs.tigera.io/calico-cloud/reference/public-cloud/aws.md)

##### [Azure](https://docs.tigera.io/calico-cloud/reference/public-cloud/azure.md)

[Reference for connecting Calico Cloud clusters running on Microsoft Azure covering supported networking modes and Azure platform notes.](https://docs.tigera.io/calico-cloud/reference/public-cloud/azure.md)

##### [Google Compute Engine](https://docs.tigera.io/calico-cloud/reference/public-cloud/gce.md)

[Reference for connecting Calico Cloud clusters running on Google Compute Engine covering supported networking modes and platform-specific routing.](https://docs.tigera.io/calico-cloud/reference/public-cloud/gce.md)

## Host endpoints

##### [Host endpoints](https://docs.tigera.io/calico-cloud/reference/host-endpoints/overview.md)

[Reference overview of host endpoint protection in Calico Cloud covering the model for securing host network interfaces with policy across connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/overview.md)

##### [Creating policy for basic connectivity](https://docs.tigera.io/calico-cloud/reference/host-endpoints/connectivity.md)

[Reference for the Calico Cloud failsafe policy that protects host endpoints in connected clusters from being cut off by misconfigured host policy.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/connectivity.md)

##### [Creating host endpoint objects](https://docs.tigera.io/calico-cloud/reference/host-endpoints/objects.md)

[Reference for the HostEndpoint object in Calico Cloud describing how to model a host network interface in a connected cluster so policy can select it.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/objects.md)

##### [Selector-based policies](https://docs.tigera.io/calico-cloud/reference/host-endpoints/selector.md)

[Reference for ordered host endpoint policies in Calico Cloud connected clusters that match interfaces using label selectors.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/selector.md)

##### [Failsafe rules](https://docs.tigera.io/calico-cloud/reference/host-endpoints/failsafe.md)

[Reference for the Calico Cloud failsafe inbound and outbound port lists that prevent host network policy from cutting off control-plane connectivity.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/failsafe.md)

##### [Pre-DNAT policy](https://docs.tigera.io/calico-cloud/reference/host-endpoints/pre-dnat.md)

[Reference for pre-DNAT host endpoint policy in Calico Cloud connected clusters that applies rules to ingress traffic before destination NAT rewrites the address.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/pre-dnat.md)

##### [Apply on forwarded traffic](https://docs.tigera.io/calico-cloud/reference/host-endpoints/forwarded.md)

[Reference for the applyOnForward field on Calico Cloud host endpoint policy that controls how rules apply to forwarded traffic in connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/forwarded.md)

##### [Summary of host endpoint policies](https://docs.tigera.io/calico-cloud/reference/host-endpoints/summary.md)

[Reference summary describing how the different Calico Cloud host endpoint policy types interact and affect packet flows in connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/summary.md)

##### [Connection tracking](https://docs.tigera.io/calico-cloud/reference/host-endpoints/conntrack.md)

[Reference covering Linux conntrack workarounds for Calico Cloud host endpoint policy when stateful tracking interferes with packet flow in connected clusters.](https://docs.tigera.io/calico-cloud/reference/host-endpoints/conntrack.md)

## Architecture

##### ['The Calico Cloud data path: IP routing and iptables'](https://docs.tigera.io/calico-cloud/reference/architecture/data-path.md)

[Reference covering the Calico Cloud data path explaining how packets flow between workloads and to external destinations in connected clusters.](https://docs.tigera.io/calico-cloud/reference/architecture/data-path.md)

##### [Calico over Ethernet fabrics](https://docs.tigera.io/calico-cloud/reference/architecture/design/l2-interconnect-fabric.md)

[Reference for using Calico Cloud over a layer-2 Ethernet interconnect fabric covering BGP peering and broadcast domain considerations.](https://docs.tigera.io/calico-cloud/reference/architecture/design/l2-interconnect-fabric.md)

##### [Calico over IP fabrics](https://docs.tigera.io/calico-cloud/reference/architecture/design/l3-interconnect-fabric.md)

[Reference for using Calico Cloud over a layer-3 IP interconnect fabric covering BGP topology choices and route propagation.](https://docs.tigera.io/calico-cloud/reference/architecture/design/l3-interconnect-fabric.md)

## Other reference topics

##### [Attribution](https://docs.tigera.io/calico-cloud/reference/attribution.md)

[Third-party license attribution report listing open-source components shipped with Calico Cloud.](https://docs.tigera.io/calico-cloud/reference/attribution.md)

##### [Frequently asked questions](https://docs.tigera.io/calico-cloud/reference/faq.md)

[Frequently asked questions about Calico Cloud covering connected clusters, the web console, observability, and platform support.](https://docs.tigera.io/calico-cloud/reference/faq.md)
