---
title: "About Calico"
description: "A brief description of Calico, deployment options, and features."
product: "Calico Enterprise"
version: "3.21"
section: "About Calico"
canonical_url: "https://docs.tigera.io/calico-enterprise/3.21/about/"
---

# About Calico

## What is Calico?

Calico is a single platform for networking, network security, and observability for any Kubernetes distribution in the cloud, on-premises, or at the edge. Whether you're just starting with Kubernetes or operating at scale, Calico's open source, enterprise, and cloud editions provide the networking, security, and observability you need.

The key advantages of Calico are:

- A single platform to address all networking, network security, and observability needs for Kubernetes environments
- Consistent networking and network security controls for any Kubernetes distribution, ensuring workload portability
- Ability to scale networking and network security to multi-cluster applications, VMs, and bare metal servers without additional software

The Calico portfolio of products includes Calico Open Source, Calico Enterprise (self-managed), and Calico Cloud (fully-managed SaaS). Calico Cloud Free Tier is a free version of Calico Cloud that focuses on observability and policy management for a single cluster. All of this is built on Calico Open Source, the most widely used container networking and security solution.

## Calico overview

### Networking

##### [Determine best networking option](https://docs.tigera.io/calico-enterprise/3.21/networking/determine-best-networking.md)

[Learn about the different networking options Calico Enterprise supports so you can choose the best option for your needs.](https://docs.tigera.io/calico-enterprise/3.21/networking/determine-best-networking.md)

##### [Ingress Gateway](https://docs.tigera.io/calico-enterprise/3.21/networking/gateway-api.md)

[Enterprise-grade traffic control based on K8s Gateway API](https://docs.tigera.io/calico-enterprise/3.21/networking/gateway-api.md)

##### [Egress Gateway](https://docs.tigera.io/calico-enterprise/3.21/networking/egress/egress-gateway-on-prem.md)

[Secure outbound traffic with fixed, routable IP assignment](https://docs.tigera.io/calico-enterprise/3.21/networking/egress/egress-gateway-on-prem.md)

##### [Cluster Mesh](https://docs.tigera.io/calico-enterprise/3.21/multicluster/federation/overview.md)

[Resilient and secure networking between clusters at scale](https://docs.tigera.io/calico-enterprise/3.21/multicluster/federation/overview.md)

### Network security

##### [Calico Network Policies](https://docs.tigera.io/calico-enterprise/3.21/network-policy/beginners/calico-network-policy.md)

[Control network and application level traffic with network policies](https://docs.tigera.io/calico-enterprise/3.21/network-policy/beginners/calico-network-policy.md)

##### [DNS Policies](https://docs.tigera.io/calico-enterprise/3.21/network-policy/domain-based-policy.md)

[Simplify policy creation using DNS namess](https://docs.tigera.io/calico-enterprise/3.21/network-policy/domain-based-policy.md)

##### [Staged Policies](https://docs.tigera.io/calico-enterprise/3.21/network-policy/staged-network-policies.md)

[Preview and test policies prior to deployment](https://docs.tigera.io/calico-enterprise/3.21/network-policy/staged-network-policies.md)

##### [Policy Tiers](https://docs.tigera.io/calico-enterprise/3.21/network-policy/policy-tiers/tiered-policy.md)

[Enforce consistent, network policies with defined precedence](https://docs.tigera.io/calico-enterprise/3.21/network-policy/policy-tiers/tiered-policy.md)

##### [Encryption](https://docs.tigera.io/calico-enterprise/3.21/compliance/encrypt-cluster-pod-traffic.md)

[High-performance encryption with WireGuard for data in transit](https://docs.tigera.io/calico-enterprise/3.21/compliance/encrypt-cluster-pod-traffic.md)

### Threat detection, observability, and incident response

##### [Web Application Firewall](https://docs.tigera.io/calico-enterprise/3.21/threat/web-application-firewall.md)

[Detects malicious traffic targeting web applications, defending against exploits like SQL injection and cross-site scripting.](https://docs.tigera.io/calico-enterprise/3.21/threat/web-application-firewall.md)

##### [Visualize traffic](https://docs.tigera.io/calico-enterprise/3.21/observability/visualize-traffic.md)

[Monitor, visualize, log, and quickly troubleshoot Kubernetes traffic](https://docs.tigera.io/calico-enterprise/3.21/observability/visualize-traffic.md)

##### [Packet Capture](https://docs.tigera.io/calico-enterprise/3.21/observability/packetcapture.md)

[Self-service packet capture for troubleshooting and forensics](https://docs.tigera.io/calico-enterprise/3.21/observability/packetcapture.md)

##### [Alerts & Incident Response](https://docs.tigera.io/calico-enterprise/3.21/observability/alerts.md)

[Alert on security events and deploy mitigating policies](https://docs.tigera.io/calico-enterprise/3.21/observability/alerts.md)

### CI/CD automation and tools

##### [Policy Board](https://docs.tigera.io/calico-enterprise/3.21/observability/get-started-cem.md)

[Author, view and manage Kubernetes network policies](https://docs.tigera.io/calico-enterprise/3.21/observability/get-started-cem.md)

##### [Policy recommendations](https://docs.tigera.io/calico-enterprise/3.21/network-policy/recommendations/learn-about-policy-recommendations.md)

[Automatically generate policies to isolate namespaces](https://docs.tigera.io/calico-enterprise/3.21/network-policy/recommendations/learn-about-policy-recommendations.md)

##### [Multi-Cluster Controls](https://docs.tigera.io/calico-enterprise/3.21/multicluster/set-up-multi-cluster-management/standard-install/create-a-management-cluster.md)

[Manage network security and observability for multiple clusters](https://docs.tigera.io/calico-enterprise/3.21/multicluster/set-up-multi-cluster-management/standard-install/create-a-management-cluster.md)

## Calico product editions

##### Calico Open Source

Open-source networking and security for containers and Kubernetes

##### Calico Cloud Free Tier

Observability & policy management for a single cluster

##### Calico Cloud

SaaS platform for Kubernetes networking and security

##### Calico Enterprise

Self-managed platform for Kubernetes networking and security

## Which product edition is right for me?

| My needs                                                                                                                                                                | Calico product edition                                                                                                                                                                                                                                                  |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| I want open source, best-in-class networking, network security, and observability capabilities that can work across any Kubernetes distribution, for free.              | Calico Open Source [Get Started](https://docs.tigera.io/calico/latest/getting-started.md)                                                                                                                                                                                  |
| I’m a Calico Open Source user who wants to leverage some of the improved observability and policy management capabilities that are available in Calico Cloud, for free. | Calico Cloud Free Tier [Sign up](https://auth.calicocloud.io/u/signup/identifier?state=hKFo2SBoMWV0M1RBUDlvWU83V2pGOS1ybVpCdmJGcDJRXzRSdaFur3VuaXZlcnNhbC1sb2dpbqN0aWTZIEJMclZBR2NmZzFacHRMclRIOFBzVEdNdVozOFlOSkpio2NpZNkgcTZ4MVM2dHdxZ0pHOVZLSEQzRGR0S0tEQTB2MlNuYkU) |
| My organization wants a **fully managed SaaS** platform for network security and observability.                                                                         | Calico Cloud [Get Started](https://docs.tigera.io/calico-cloud/get-started.md)                                                                                                                                                                                             |
| My organization wants a **self-managed platform** for network security and observability.                                                                               | Calico Enterprise [Get Started](https://docs.tigera.io/calico-enterprise/3.21/getting-started.md)                                                                                                                                                                         |

## Feature comparison matrix

|                                                                             | Calico Open Source | Calico Cloud Free Tier\* | Calico Cloud      | Calico Enterprise |
| --------------------------------------------------------------------------- | ------------------ | ------------------------ | ----------------- | ----------------- |
| **Management and Support**                                                  |                    |                          |                   |                   |
| Mutli-cluster security controls management                                  |                    |                          |                   |                   |
| Data retention                                                              | In-memory          | 24 hours                 | 7 days            | Unlimited         |
| Number of clusters                                                          | Unlimited          | One                      | Unlimited         | Unlimited         |
| Number of users                                                             | N/A                | One                      | Unlimited         | Unlimited         |
| Support and maintenance                                                     | Community-driven   | Community-driven         | Standard/Business | Standard/Business |
| **Networking**                                                              |                    |                          |                   |                   |
| High performance, scalable pod networking                                   |                    |                          |                   |                   |
| Advanced IP address management                                              |                    |                          |                   |                   |
| Direct infrastructure peering without the overlay                           |                    |                          |                   |                   |
| eBPF data plane                                                             |                    |                          |                   |                   |
| Windows data plane                                                          |                    |                          |                   |                   |
| nftables data plane                                                         |                    |                          |                   |                   |
| iptables data plane                                                         |                    |                          |                   |                   |
| VPP data plane                                                              |                    |                          |                   |                   |
| Multiple Calico networks on a pod                                           |                    |                          |                   |                   |
| Dual ToR peering                                                            |                    |                          |                   |                   |
| Ingress gateway                                                             |                    |                          |                   |                   |
| Egress gateway                                                              |                    |                          |                   |                   |
| Cluster mesh                                                                |                    |                          |                   |                   |
| **Network Security**                                                        |                    |                          |                   |                   |
| Seamless support for Kubernetes network policy                              |                    |                          |                   |                   |
| Label-based policies for K8s and non-K8s workloads                          |                    |                          |                   |                   |
| Namespace and cluster-wide scope                                            |                    |                          |                   |                   |
| Global default deny policy design                                           |                    |                          |                   |                   |
| Application layer policy                                                    |                    |                          |                   |                   |
| Policy for services                                                         |                    |                          |                   |                   |
| Policy board                                                                |                    | View only                |                   |                   |
| DNS/FQDN-based policy                                                       |                    |                          |                   |                   |
| Hierarchical tiered network policy                                          |                    |                          |                   |                   |
| Policy recommendations                                                      |                    | Manual workflow          |                   |                   |
| Staged network policy                                                       |                    |                          |                   |                   |
| Preview staged policies                                                     |                    |                          |                   |                   |
| Network sets to limit IP ranges for egress and ingress traffic to workloads |                    |                          |                   |                   |
| Data-in-transit encryption                                                  |                    |                          |                   |                   |
| Universal firewall integration                                              |                    |                          |                   |                   |
| Workload-based IDS/IPS                                                      |                    |                          |                   |                   |
| Deep packet inspection                                                      |                    |                          |                   |                   |
| DDoS protection                                                             |                    |                          |                   |                   |
| Workload-centric WAF                                                        |                    |                          |                   |                   |
| Compliance reporting and alerts                                             |                    |                          |                   |                   |
| SIEM integrations                                                           |                    |                          |                   |                   |
| **Network Security for VMs and Bare Metal**                                 |                    |                          |                   |                   |
| Restrict traffic to/from hosts and VMs using network policy                 |                    |                          |                   |                   |
| Automatic host endpoints                                                    |                    |                          |                   |                   |
| Apply policy to host-forwarded traffic                                      |                    |                          |                   |                   |
| **Observability**                                                           |                    |                          |                   |                   |
| Flow logs API                                                               |                    |                          |                   |                   |
| Calico Whisker web console                                                  |                    |                          |                   |                   |
| Dynamic service and threat graph                                            |                    |                          |                   |                   |
| Application level observability                                             |                    |                          |                   |                   |
| Dynamic packet capture                                                      |                    |                          |                   |                   |
| Flow visualizer                                                             |                    |                          |                   |                   |
| Logs (flow)                                                                 |                    |                          |                   |                   |
| Logs (http traffic, audit, bgp, dns, events)                                |                    |                          |                   |                   |
| Dashboards                                                                  |                    | \*\*                     |                   |                   |
| Alerts                                                                      |                    |                          |                   |                   |

\* Calico Cloud Free Tier requires a cluster with Calico Open Source 3.30 or higher.

\*\* Calico Cloud Free Tier includes some of the dashboards that are available in Calico Cloud and Calico Enterprise.

## How to get started with Calico

Calico powers 100M+ containers across 8M+ nodes in 166 countries, and is supported across all major cloud providers and Kubernetes distributions.

### Ready to get started?

Start a free trial or request a demo to see Calico in action.

- [Sign up for a Calico Cloud Free Tier account](https://www.calicocloud.io/?code=free)
- [Schedule a 30-minute demo with our experts](https://www.tigera.io/demo/)

### Installation guides

- [Install Calico Open Source](https://docs.tigera.io/calico-enterprise/3.21/getting-started.md)
- [Install Calico Cloud Free Tier](https://docs.tigera.io/calico-cloud/free/connect-cluster-free.md)
- [Install Calico Cloud](https://docs.tigera.io/calico-cloud/get-started/install-cluster.md)
- [Install Calico Enterprise](https://docs.tigera.io/calico-enterprise/latest/getting-started.md)

## How to engage

### Learning resources

- [Blog](https://www.tigera.io/blog/)
- [Certifications](https://www.tigera.io/lp/calico-certification/) (self-paced)
- [Product tutorials](https://www.tigera.io/tutorials/) (self-paced)
- [Learn guides](https://www.tigera.io/learn/guides/kubernetes-networking/)
- [Webinars and workshops](https://www.tigera.io/events/) (live and on demand)
- [Resources](https://www.tigera.io/resources/)

### Get involved

- [Calico Open Source Community](https://www.tigera.io/project-calico/community/)

- GitHub

  - [Project Calico](https://github.com/projectcalico/calico)
  - [Tigera](https://github.com/tigera)

### Get in touch

- [Slack](https://calicousers.slack.com/) (Calico Open Source users)

- [YouTube](https://www.youtube.com/channel/UCFpTnXDNcBoXI4gqCDmegFA) (@ProjectCalico)

- LinkedIn

  - [Tigera](https://www.linkedin.com/company/tigera/)
  - [Project Calico](https://www.linkedin.com/company/project-calico/)

- X

  - [Tigera](https://x.com/tigeraio)
  - [Project Calico](https://x.com/projectcalico)

- [Contact us](https://www.tigera.io/contact/)
