---
title: "Non-cluster hosts"
description: "Install Calico Enterprise on bare-metal hosts and VMs to extend zero-trust policy enforcement beyond a Kubernetes cluster."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Install and upgrade"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/getting-started/bare-metal/"
---

# Non-cluster hosts

## [📄️Install Calico on non-cluster hosts and VMs](https://docs.tigera.io/calico-enterprise/latest/getting-started/bare-metal/about.md)

[Install Calico Enterprise on non-cluster hosts and VMs to apply Calico network policy and capture flow logs for workloads running outside Kubernetes.](https://docs.tigera.io/calico-enterprise/latest/getting-started/bare-metal/about.md)

## [📄️Use custom certificates for Node and Typha](https://docs.tigera.io/calico-enterprise/latest/getting-started/bare-metal/typha-node-tls.md)

[Configure custom TLS certificates between non-cluster Calico Enterprise nodes and Typha for clusters with strict PKI requirements.](https://docs.tigera.io/calico-enterprise/latest/getting-started/bare-metal/typha-node-tls.md)

## [📄️Troubleshoot non-cluster hosts and VMs setup](https://docs.tigera.io/calico-enterprise/latest/getting-started/bare-metal/troubleshoot.md)

[Troubleshooting guide for Calico Enterprise on non-cluster hosts and VMs — connectivity, agent registration, and policy issues.](https://docs.tigera.io/calico-enterprise/latest/getting-started/bare-metal/troubleshoot.md)
