---
title: "RKE2"
description: "Install Calico Enterprise on an RKE2 cluster using the standard command-line installer."
product: "Calico Enterprise"
version: "3.23 (latest)"
section: "Install and upgrade"
canonical_url: "https://docs.tigera.io/calico-enterprise/latest/getting-started/install-on-clusters/rke2"
---

# RKE2

## Big picture

Install Calico Enterprise on RKE2 (RKE Government) clusters.

## Before you begin

**CNI support**

Calico CNI for networking with Calico Enterprise network policy:

The geeky details of what you get:

| Policy | IPAM   | CNI    | Overlay | Routing | Datastore  |
| ------ | ------ | ------ | ------- | ------- | ---------- |
| Calico | Calico | Calico | VXLAN   | BGP     | Kubernetes |

?

**Required**

- A [compatible RKE2 cluster](https://docs.tigera.io/calico-enterprise/latest/getting-started/compatibility.md#rke2) with 2.6.5 or later

  For help, see [Rancher Kubernetes Engine cluster](https://rancher.com/docs/rke/latest/en/).

- [Configure cluster with no CNI plugin](https://docs.rke2.io/install/configuration) using any of these methods:

  - RKE2 CLI: `--cni none`
  - Install script: `RKE2_CNI=none`
  - [Configuration file](https://docs.rke2.io/install/configuration#configuration-file): `cni: none`

- Cluster meets [system requirements](https://docs.tigera.io/calico-enterprise/latest/getting-started/install-on-clusters/requirements.md)

- A [Tigera license key and credentials](https://docs.tigera.io/calico-enterprise/latest/getting-started/install-on-clusters/calico-enterprise.md).

- A `kubectl` environment with access to your cluster

  Ensure you have the [kubeconfig file that was generated when you created the cluster](https://docs.rke2.io/cluster_access).

- If using a kubeconfig file locally, [install and set up the Kubectl CLI tool](https://kubernetes.io/docs/tasks/tools/install-kubectl/).

## How to

- [Install Calico Enterprise](#install-calico-enterprise)
- [Install the Calico Enterprise license](#install-the-calico-enterprise-license)

### Install Calico Enterprise

1. [Configure a storage class for Calico Enterprise.](https://docs.tigera.io/calico-enterprise/latest/operations/logstorage/create-storage.md).

2. Install the Tigera Operator and custom resource definitions.

   ```bash
   kubectl create -f https://downloads.tigera.io/ee/v3.23.2/manifests/operator-crds.yaml
   kubectl create -f https://downloads.tigera.io/ee/v3.23.2/manifests/tigera-operator.yaml
   ```

3. Install the Prometheus operator and related custom resource definitions. The Prometheus operator is used to deploy Prometheus server and Alertmanager to monitor Calico Enterprise metrics.

   > **SECONDARY:** If you have an existing Prometheus operator in your cluster that you want to use, skip this step. To work with Calico Enterprise, your Prometheus operator must be v0.40.0 or higher.

   ```bash
   kubectl create -f https://downloads.tigera.io/ee/v3.23.2/manifests/tigera-prometheus-operator.yaml
   ```

4. Install your pull secret.

   If pulling images directly from `quay.io/tigera`, you can use the credentials provided to you by your Tigera support representative. If using a private registry, use your private registry credentials instead.

   ```bash
   kubectl create secret generic tigera-pull-secret \
       --type=kubernetes.io/dockerconfigjson -n tigera-operator \
       --from-file=.dockerconfigjson=<path/to/pull/secret>
   ```

5. Install any extra [Calico resources](https://docs.tigera.io/calico-enterprise/latest/reference/resources.md) needed at cluster start using [calicoctl](https://docs.tigera.io/calico-enterprise/latest/reference/clis/calicoctl/overview.md).

6. Install the Tigera custom resources. For more information on configuration options available, see [the installation reference](https://docs.tigera.io/calico-enterprise/latest/reference/installation/api.md).

   ```bash
   kubectl create -f https://downloads.tigera.io/ee/v3.23.2/manifests/rancher/custom-resources-rke2.yaml
   ```

   Monitor progress with the following command:

   ```bash
   watch kubectl get tigerastatus
   ```

   Wait until the `apiserver` shows a status of `Available`, then proceed to the next section.

### Install the Calico Enterprise license

```bash
kubectl create -f </path/to/license.yaml>
```

Monitor progress with the following command:

```bash
watch kubectl get tigerastatus
```

## Next steps

**Recommended**

- [Configure access to the Calico Enterprise web console](https://docs.tigera.io/calico-enterprise/latest/operations/cnx/access-the-manager.md)
- [Authentication quickstart](https://docs.tigera.io/calico-enterprise/latest/operations/cnx/authentication-quickstart.md)
- [Configure your own identity provider](https://docs.tigera.io/calico-enterprise/latest/operations/cnx/configure-identity-provider.md)

**Recommended - Networking**

- The default networking uses VXLAN encapsulation with BGP routing. For all networking options, see [Determine best networking option](https://docs.tigera.io/calico-enterprise/latest/networking/determine-best-networking.md).

**Recommended - Security**

- [Get started with Calico Enterprise tiered network policy](https://docs.tigera.io/calico-enterprise/latest/network-policy/policy-tiers/tiered-policy.md)
