---
title: "Operations"
description: "Post-installation tasks for managing Calico including upgrading and troubleshooting."
product: "Calico Enterprise"
version: "3.21"
section: "Operations"
canonical_url: "https://docs.tigera.io/calico-enterprise/3.21/operations/"
---

# Operations

Post-installation tasks for managing Calico Enterprise.

## Configuring the web console

##### [Configure access to the web console](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/access-the-manager.md)

[Configure access to the web console.](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/access-the-manager.md)

##### [Authentication quickstart](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/authentication-quickstart.md)

[Use default token authentication to log in to the web console and Kibana.](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/authentication-quickstart.md)

##### [Configure an external identity provider](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/configure-identity-provider.md)

[Configure an external identity provider for user access to Calico Enterprise Manager and Kibana.](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/configure-identity-provider.md)

##### [Configure user roles and permissions](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/roles-and-permissions.md)

[Configure roles and permissions for Calico Enterprise features and functions.](https://docs.tigera.io/calico-enterprise/3.21/operations/cnx/roles-and-permissions.md)

## calicoctl and calicoq

##### [Install calicoctl](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoctl/install.md)

[Install the CLI for Calico.](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoctl/install.md)

##### [Configure calicoctl](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoctl/configure/overview.md)

[Configure calicoctl for datastore access.](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoctl/configure/overview.md)

##### [Configure calicoctl to connect to the datastore](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoctl/configure/datastore.md)

[Sample configuration files for the Kubernetes API datastore.](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoctl/configure/datastore.md)

##### [Install calicoq](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoq/installing.md)

[Install the CLI for Calico Enterprise.](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoq/installing.md)

##### [Configure calicoq](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoq/configure/overview.md)

[Configure the CLI to connect to the Kubernetes API datastore.](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoq/configure/overview.md)

##### [Configure calicoq to connect to the datastore](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoq/configure/datastore.md)

[Configure CLI to connect to the Kubernetes API datastore.](https://docs.tigera.io/calico-enterprise/3.21/operations/clis/calicoq/configure/datastore.md)

## Securing component communications

##### [Configure encryption and authentication to secure Calico Enterprise components](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/crypto-auth.md)

[Enable TLS authentication and encryption for various Calico Enterprise components.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/crypto-auth.md)

##### [Secure Calico Enterprise Prometheus endpoints](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/secure-metrics.md)

[Limit access to Calico Enterprise metric endpoints using network policy.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/secure-metrics.md)

##### [Secure BGP sessions](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/secure-bgp.md)

[Configure BGP passwords to prevent attackers from injecting false routing information.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/secure-bgp.md)

##### [Provide TLS certificates for Calico Enterprise Manager](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/manager-tls.md)

[Add TLS certificates to secure access to Calico Enterprise Manager user interface.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/manager-tls.md)

##### [Provide TLS certificates for log storage](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/log-storage-tls.md)

[Add TLS certificate to secure access to log storage.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/log-storage-tls.md)

##### [Provide TLS certificates for Linseed APIs](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/linseed-tls.md)

[Add TLS certificate to secure access to Linseed APIs.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/linseed-tls.md)

##### [Provide TLS certificates for the API server](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/apiserver-tls.md)

[Add TLS certificates to secure access to the Calico Enterprise API server.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/apiserver-tls.md)

##### [Provide TLS certificates for Typha and Node](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/typha-node-tls.md)

[Add TLS certificates to secure communications between if you are using Typha to scale your deployment.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/typha-node-tls.md)

##### [Provide TLS certificates for compliance](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/compliance-tls.md)

[Add TLS certificate to secure access to compliance.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/compliance-tls.md)

##### [Provide TLS certificates for PacketCapture APIs](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/packetcapture-tls.md)

[Add TLS certificate to secure access to PacketCapture APIs.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/packetcapture-tls.md)

##### [Manage TLS certificates used by Calico Enterprise](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/certificate-management.md)

[Control the issuer of certificates used by Calico Enterprise.](https://docs.tigera.io/calico-enterprise/3.21/operations/comms/certificate-management.md)

## Storage

##### [Log storage recommendations](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/log-storage-recommendations.md)

[Guidelines for setting up your log storage.](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/log-storage-recommendations.md)

##### [Configure storage for logs and reports](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/create-storage.md)

[Configure persistent storage for flow logs, DNS logs, audit logs, and compliance reports.](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/create-storage.md)

##### [Adjust log storage size](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/adjust-log-storage-size.md)

[Adjust the log storage size during or after installation.](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/adjust-log-storage-size.md)

##### [Advanced Node Scheduling](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/advanced-node-scheduling.md)

[Control where Elasticsearch pods and replicas are scheduled.](https://docs.tigera.io/calico-enterprise/3.21/operations/logstorage/advanced-node-scheduling.md)

## Monitoring

##### [Prometheus support](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/support.md)

[Prometheus support in Calico Enterprise.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/support.md)

##### [Bring your own Prometheus](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/byo-prometheus.md)

[Steps to get Calico Enterprise metrics using your own Prometheus.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/byo-prometheus.md)

##### [Configure Prometheus](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/configure-prometheus.md)

[Configure rules for alerts and denied packets, for persistent storage.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/configure-prometheus.md)

##### [Configure Alertmanager](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/alertmanager.md)

[Configure Alertmanager, a Prometheus feature that routes alerts.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/prometheus/alertmanager.md)

##### [Recommended Prometheus metrics](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/recommended-metrics.md)

[Recommended Prometheus metrics for monitoring Calico Enterprise components.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/recommended-metrics.md)

##### [BGP metrics](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/bgp-metrics.md)

[Monitor BGP peering and route exchange in your cluster and get alerts by defining rules and thresholds.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/bgp-metrics.md)

##### [License metrics](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/license-agent.md)

[Monitor Calico Enterprise license metrics such as nodes used, nodes available, and days until license expires.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/license-agent.md)

##### [Policy metrics](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/policy-metrics.md)

[Monitor the effects of policy in your cluster and received alerts by defining rules and thresholds.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/policy-metrics.md)

##### [Elasticsearch and Fluentd metrics](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/elasticsearch-and-fluentd-metrics.md)

[Monitor Elasticsearch and Fluentd metrics, and get alerts on log storage or collection issues.](https://docs.tigera.io/calico-enterprise/3.21/operations/monitor/metrics/elasticsearch-and-fluentd-metrics.md)

## eBPF

##### [eBPF use cases](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/use-cases-ebpf.md)

[Learn when to use eBPF, and when not to.](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/use-cases-ebpf.md)

##### [Enable eBPF on an existing cluster](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/enabling-ebpf.md)

[Steps to enable the eBPF data plane on an existing cluster.](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/enabling-ebpf.md)

##### [Install in eBPF mode](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/install.md)

[Install Calico Enterprise in eBPF mode.](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/install.md)

##### [Troubleshoot eBPF mode](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/troubleshoot-ebpf.md)

[How to troubleshoot when running in eBPF mode.](https://docs.tigera.io/calico-enterprise/3.21/operations/ebpf/troubleshoot-ebpf.md)

## Troubleshooting

##### [Troubleshooting and diagnostics](https://docs.tigera.io/calico-enterprise/3.21/operations/troubleshoot/troubleshooting.md)

[View logs and diagnostics, common issues, and where to report issues in github.](https://docs.tigera.io/calico-enterprise/3.21/operations/troubleshoot/troubleshooting.md)

##### [Troubleshooting commands](https://docs.tigera.io/calico-enterprise/3.21/operations/troubleshoot/commands.md)

[Learn basic commands to verify cluster and components are working.](https://docs.tigera.io/calico-enterprise/3.21/operations/troubleshoot/commands.md)

##### [Component logs](https://docs.tigera.io/calico-enterprise/3.21/operations/troubleshoot/component-logs.md)

[Where to find component logs.](https://docs.tigera.io/calico-enterprise/3.21/operations/troubleshoot/component-logs.md)

## Other operations tasks

##### [Decommission a node](https://docs.tigera.io/calico-enterprise/3.21/operations/decommissioning-a-node.md)

[Manually remove a node from a cluster that is installed with Calico.](https://docs.tigera.io/calico-enterprise/3.21/operations/decommissioning-a-node.md)

##### [License expiration and renewal](https://docs.tigera.io/calico-enterprise/3.21/operations/license-options.md)

[Review options to track your Calico Enterprise license expiration.](https://docs.tigera.io/calico-enterprise/3.21/operations/license-options.md)
