---
title: "About Calico"
description: "Overview of Calico Open Source, the upstream Calico project for Kubernetes networking, network security, and observability across any cluster."
product: "Calico Open Source"
version: "3.32 (latest)"
section: "About Calico"
canonical_url: "https://docs.tigera.io/calico/latest/about/"
---

# About Calico

## What is Calico?

Calico is a single platform for networking, network security, and observability for any Kubernetes distribution in the cloud, on-premises, or at the edge. Whether you're just starting with Kubernetes or operating at scale, Calico's open source, enterprise, and cloud editions provide the networking, security, and observability you need.

The key advantages of Calico are:

- A single platform to address all networking, network security, and observability needs for Kubernetes environments
- Consistent networking and network security controls for any Kubernetes distribution, ensuring workload portability
- Ability to scale networking and network security to multi-cluster applications, VMs, and bare metal servers without additional software

The Calico portfolio of products includes Calico Open Source, Calico Enterprise (self-managed), and Calico Cloud (fully-managed SaaS). Calico Cloud Free Tier is a free version of Calico Cloud that focuses on observability and policy management for a single cluster. All of this is built on Calico Open Source, the most widely used container networking and security solution.

## Calico overview

### Networking

##### [Determine best networking option](https://docs.tigera.io/calico/latest/networking/determine-best-networking.md)

[Compare networking options in Calico Open Source — overlay versus non-overlay, BGP routing, CNI choices, and IPAM modes — to pick the right combination for your environment.](https://docs.tigera.io/calico/latest/networking/determine-best-networking.md)

##### [Ingress Gateway](https://docs.tigera.io/calico/latest/networking/ingress-gateway/about-calico-ingress-gateway.md)

[Enterprise-grade traffic control based on K8s Gateway API](https://docs.tigera.io/calico/latest/networking/ingress-gateway/about-calico-ingress-gateway.md)

##### [Egress Gateway](https://docs.tigera.io/calico-cloud/networking/egress/egress-gateway-on-prem.md)

[Secure outbound traffic with fixed, routable IP assignment](https://docs.tigera.io/calico-cloud/networking/egress/egress-gateway-on-prem.md)

[Cloud](https://docs.tigera.io/calico-cloud/networking/egress/egress-gateway-on-prem.md)

##### [Cluster Mesh](https://docs.tigera.io/calico-cloud/multicluster.md)

[Resilient and secure networking between clusters at scale](https://docs.tigera.io/calico-cloud/multicluster.md)

[Cloud](https://docs.tigera.io/calico-cloud/multicluster.md)

### Network security

##### [Calico Network Policies](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-network-policy.md)

[Control network and application level traffic with network policies](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-network-policy.md)

##### [DNS Policies](https://docs.tigera.io/calico-cloud/network-policy/domain-based-policy.md)

[Simplify policy creation using DNS namess](https://docs.tigera.io/calico-cloud/network-policy/domain-based-policy.md)

[Cloud](https://docs.tigera.io/calico-cloud/network-policy/domain-based-policy.md)

##### [Staged Policies](https://docs.tigera.io/calico/latest/network-policy/staged-network-policies.md)

[Preview and test policies prior to deployment](https://docs.tigera.io/calico/latest/network-policy/staged-network-policies.md)

##### [Policy Tiers](https://docs.tigera.io/calico/latest/network-policy/policy-tiers/tiered-policy.md)

[Enforce consistent, network policies with defined precedence](https://docs.tigera.io/calico/latest/network-policy/policy-tiers/tiered-policy.md)

##### [Encryption](https://docs.tigera.io/calico/latest/network-policy/encrypt-cluster-pod-traffic.md)

[High-performance encryption with WireGuard for data in transit](https://docs.tigera.io/calico/latest/network-policy/encrypt-cluster-pod-traffic.md)

### Threat detection, observability, and incident response

##### [View flow logs with Calico Whisker](https://docs.tigera.io/calico/latest/observability/view-flow-logs.md)

[View flow logs in the Calico Whisker web console.](https://docs.tigera.io/calico/latest/observability/view-flow-logs.md)

##### [Web Application Firewall](https://docs.tigera.io/calico-cloud/threat/web-application-firewall.md)

[Detects malicious traffic targeting web applications, defending against exploits like SQL injection and cross-site scripting.](https://docs.tigera.io/calico-cloud/threat/web-application-firewall.md)

[Cloud](https://docs.tigera.io/calico-cloud/threat/web-application-firewall.md)

##### [Dynamic Service Graph](https://docs.tigera.io/calico-cloud/tutorials/calico-cloud-features/service-graph.md)

[Monitor, visualize, log, and quickly troubleshoot Kubernetes traffic](https://docs.tigera.io/calico-cloud/tutorials/calico-cloud-features/service-graph.md)

[Cloud](https://docs.tigera.io/calico-cloud/tutorials/calico-cloud-features/service-graph.md)

##### [Packet Capture](https://docs.tigera.io/calico-cloud/observability/packetcapture.md)

[Self-service packet capture for troubleshooting and forensics](https://docs.tigera.io/calico-cloud/observability/packetcapture.md)

[Cloud](https://docs.tigera.io/calico-cloud/observability/packetcapture.md)

##### [Analytics](https://docs.tigera.io/calico-cloud/free/overview.md)

[Dashboards to analyze security and networking data](https://docs.tigera.io/calico-cloud/free/overview.md)

[Cloud](https://docs.tigera.io/calico-cloud/free/overview.md)

##### [Alerts & Incident Response](https://docs.tigera.io/calico-cloud/observability/alerts.md)

[Alert on security events and deploy mitigating policies](https://docs.tigera.io/calico-cloud/observability/alerts.md)

[Cloud](https://docs.tigera.io/calico-cloud/observability/alerts.md)

### CI/CD automation and tools

##### [Policy Board](https://docs.tigera.io/calico-cloud/tutorials/calico-cloud-features/tour.md#policies)

[Author, view and manage Kubernetes network policies](https://docs.tigera.io/calico-cloud/tutorials/calico-cloud-features/tour.md#policies)

[Cloud](https://docs.tigera.io/calico-cloud/tutorials/calico-cloud-features/tour.md#policies)

##### [Policy recommendations](https://docs.tigera.io/calico-cloud/network-policy/recommendations/learn-about-policy-recommendations.md)

[Automatically generate policies to isolate namespaces](https://docs.tigera.io/calico-cloud/network-policy/recommendations/learn-about-policy-recommendations.md)

[Cloud](https://docs.tigera.io/calico-cloud/network-policy/recommendations/learn-about-policy-recommendations.md)

##### [Multi-Cluster Controls](https://docs.tigera.io/calico-enterprise/latest/multicluster.md)

[Manage network security and observability for multiple clusters](https://docs.tigera.io/calico-enterprise/latest/multicluster.md)

[Enterprise](https://docs.tigera.io/calico-enterprise/latest/multicluster.md)

## Calico product editions

##### Calico Open Source

Open-source networking and security for containers and Kubernetes

##### Calico Cloud Free Tier

Observability & policy management for a single cluster

##### Calico Cloud

SaaS platform for Kubernetes networking and security

##### Calico Enterprise

Self-managed platform for Kubernetes networking and security

### Calico Open Source

Calico Open Source is a networking and security solution for containers, virtual machines, and native host-based workloads. Calico supports a broad range of platforms including Kubernetes, OpenShift, OpenStack, and bare metal services.

### Calico Cloud Free Tier

Calico Cloud Free Tier is a free-tier, single-cluster, single-user version of Calico Cloud that provides additional enhanced Kubernetes observability and network security capabilities for Calico Open Source users. To connect a cluster to Calico Cloud Free Tier, your cluster must have Calico Open Source 3.30 or higher.

Calico can be deployed as a self-managed platform (Calico Enterprise) or a fully-managed SaaS platform (Calico Cloud). Either way, Calico provides a unified network security and observability platform to prevent, detect and mitigate security breaches in Kubernetes clusters.

### Calico commercial editions

#### Calico Cloud and Calico Enterprise

Calico can be deployed as a self-managed platform (Calico Enterprise) or a fully-managed SaaS platform (Calico Cloud). Either way, Calico provides a unified network security and observability platform to prevent, detect, and mitigate security breaches in Kubernetes clusters.

## Which product edition is right for me?

| My needs                                                                                                                                                                | Calico product edition                                                                                                                                                                                                                                                  |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| I want open source, best-in-class networking, network security, and observability capabilities that can work across any Kubernetes distribution, for free.              | Calico Open Source [Get Started](https://docs.tigera.io/calico/latest/getting-started.md)                                                                                                                                                                                 |
| I’m a Calico Open Source user who wants to leverage some of the improved observability and policy management capabilities that are available in Calico Cloud, for free. | Calico Cloud Free Tier [Sign up](https://auth.calicocloud.io/u/signup/identifier?state=hKFo2SBoMWV0M1RBUDlvWU83V2pGOS1ybVpCdmJGcDJRXzRSdaFur3VuaXZlcnNhbC1sb2dpbqN0aWTZIEJMclZBR2NmZzFacHRMclRIOFBzVEdNdVozOFlOSkpio2NpZNkgcTZ4MVM2dHdxZ0pHOVZLSEQzRGR0S0tEQTB2MlNuYkU) |
| My organization wants a **fully managed SaaS** platform for network security and observability.                                                                         | Calico Cloud [Get Started](https://docs.tigera.io/calico-cloud/get-started.md)                                                                                                                                                                                             |
| My organization wants a **self-managed platform** for network security and observability.                                                                               | Calico Enterprise [Get Started](https://docs.tigera.io/calico-enterprise/latest/getting-started.md)                                                                                                                                                                       |

## Feature comparison matrix

|                                                                             | Calico Open Source | Calico Cloud Free Tier\* | Calico Cloud      | Calico Enterprise |
| --------------------------------------------------------------------------- | ------------------ | ------------------------ | ----------------- | ----------------- |
| **Management and Support**                                                  |                    |                          |                   |                   |
| Mutli-cluster security controls management                                  |                    |                          |                   |                   |
| Data retention                                                              | In-memory          | 24 hours                 | 7 days            | Unlimited         |
| Number of clusters                                                          | Unlimited          | One                      | Unlimited         | Unlimited         |
| Number of users                                                             | N/A                | One                      | Unlimited         | Unlimited         |
| Support and maintenance                                                     | Community-driven   | Community-driven         | Standard/Business | Standard/Business |
| **Networking**                                                              |                    |                          |                   |                   |
| High performance, scalable pod networking                                   |                    |                          |                   |                   |
| Advanced IP address management                                              |                    |                          |                   |                   |
| Direct infrastructure peering without the overlay                           |                    |                          |                   |                   |
| eBPF data plane                                                             |                    |                          |                   |                   |
| Windows data plane                                                          |                    |                          |                   |                   |
| nftables data plane                                                         |                    |                          |                   |                   |
| iptables data plane                                                         |                    |                          |                   |                   |
| VPP data plane                                                              |                    |                          |                   |                   |
| Multiple Calico networks on a pod                                           |                    |                          |                   |                   |
| Dual ToR peering                                                            |                    |                          |                   |                   |
| Ingress gateway                                                             |                    |                          |                   |                   |
| Egress gateway                                                              |                    |                          |                   |                   |
| Cluster mesh                                                                |                    |                          |                   |                   |
| **Network Security**                                                        |                    |                          |                   |                   |
| Seamless support for Kubernetes network policy                              |                    |                          |                   |                   |
| Label-based policies for K8s and non-K8s workloads                          |                    |                          |                   |                   |
| Namespace and cluster-wide scope                                            |                    |                          |                   |                   |
| Global default deny policy design                                           |                    |                          |                   |                   |
| Application layer policy                                                    |                    |                          |                   |                   |
| Policy for services                                                         |                    |                          |                   |                   |
| Policy board                                                                |                    | View only                |                   |                   |
| DNS/FQDN-based policy                                                       |                    |                          |                   |                   |
| Hierarchical tiered network policy                                          |                    |                          |                   |                   |
| Policy recommendations                                                      |                    | Manual workflow          |                   |                   |
| Staged network policy                                                       |                    |                          |                   |                   |
| Preview staged policies                                                     |                    |                          |                   |                   |
| Network sets to limit IP ranges for egress and ingress traffic to workloads |                    |                          |                   |                   |
| Data-in-transit encryption                                                  |                    |                          |                   |                   |
| Universal firewall integration                                              |                    |                          |                   |                   |
| Workload-based IDS/IPS                                                      |                    |                          |                   |                   |
| Deep packet inspection                                                      |                    |                          |                   |                   |
| DDoS protection                                                             |                    |                          |                   |                   |
| Workload-centric WAF                                                        |                    |                          |                   |                   |
| Compliance reporting and alerts                                             |                    |                          |                   |                   |
| SIEM integrations                                                           |                    |                          |                   |                   |
| **Network Security for VMs and Bare Metal**                                 |                    |                          |                   |                   |
| Restrict traffic to/from hosts and VMs using network policy                 |                    |                          |                   |                   |
| Automatic host endpoints                                                    |                    |                          |                   |                   |
| Apply policy to host-forwarded traffic                                      |                    |                          |                   |                   |
| **Observability**                                                           |                    |                          |                   |                   |
| Flow logs API                                                               |                    |                          |                   |                   |
| Calico Whisker web console                                                  |                    |                          |                   |                   |
| Dynamic service and threat graph                                            |                    |                          |                   |                   |
| Application level observability                                             |                    |                          |                   |                   |
| Dynamic packet capture                                                      |                    |                          |                   |                   |
| Flow visualizer                                                             |                    |                          |                   |                   |
| Logs (flow)                                                                 |                    |                          |                   |                   |
| Logs (http traffic, audit, bgp, dns, events)                                |                    |                          |                   |                   |
| Dashboards                                                                  |                    | \*\*                     |                   |                   |
| Alerts                                                                      |                    |                          |                   |                   |

\* Calico Cloud Free Tier requires a cluster with Calico Open Source 3.30 or higher.

\*\* Calico Cloud Free Tier includes some of the dashboards that are available in Calico Cloud and Calico Enterprise.

## How to get started with Calico

Calico powers 100M+ containers across 8M+ nodes in 166 countries, and is supported across all major cloud providers and Kubernetes distributions.

### Ready to get started?

Start a free trial or request a demo to see Calico in action.

- [Sign up for a Calico Cloud Free Tier account](https://www.calicocloud.io/?code=free)
- [Schedule a 30-minute demo with our experts](https://www.tigera.io/demo/)

### Installation guides

- [Install Calico Open Source](https://docs.tigera.io/calico/latest/getting-started.md)
- [Install Calico Cloud Free Tier](https://docs.tigera.io/calico-cloud/free/connect-cluster-free.md)
- [Install Calico Cloud](https://docs.tigera.io/calico-cloud/get-started/install-cluster.md)
- [Install Calico Enterprise](https://docs.tigera.io/calico-enterprise/latest/getting-started.md)

## How to engage

### Learning resources

- [Blog](https://www.tigera.io/blog/)
- [Certifications](https://www.tigera.io/lp/calico-certification/) (self-paced)
- [Product tutorials](https://www.tigera.io/tutorials/) (self-paced)
- [Learn guides](https://www.tigera.io/learn/guides/kubernetes-networking/)
- [Webinars and workshops](https://www.tigera.io/events/) (live and on demand)
- [Resources](https://www.tigera.io/resources/)

### Get involved

- [Calico Open Source Community](https://www.tigera.io/project-calico/community/)

- GitHub

  - [Project Calico](https://github.com/projectcalico/calico)
  - [Tigera](https://github.com/tigera)

### Get in touch

- [Slack](https://calicousers.slack.com/) (Calico Open Source users)

- [YouTube](https://www.youtube.com/channel/UCFpTnXDNcBoXI4gqCDmegFA) (@ProjectCalico)

- LinkedIn

  - [Tigera](https://www.linkedin.com/company/tigera/)
  - [Project Calico](https://www.linkedin.com/company/project-calico/)

- X

  - [Tigera](https://x.com/tigeraio)
  - [Project Calico](https://x.com/projectcalico)

- [Contact us](https://www.tigera.io/contact/)
