---
title: "Calico for Windows on a Rancher Kubernetes Engine cluster"
description: "Install Calico Open Source for Windows on a Rancher RKE cluster with Windows worker nodes."
product: "Calico Open Source"
version: "3.32 (latest)"
section: "Installing and upgrading"
canonical_url: "https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/rancher"
---

# Calico for Windows on a Rancher Kubernetes Engine cluster

## Big picture

Install Calico for Windows on a Rancher Kubernetes Engine (RKE) cluster.

## Value

Run Linux and Windows workloads on a RKE cluster with Calico.

## Before you begin

**Supported**

- RKE Kubernetes 1.20, 1.19, or 1.18

**Supported networking**

- BGP with no encapsulation
- VXLAN

**Required**

- An RKE cluster provisioned with [no network plugin](https://rancher.com/docs/rke/latest/en/config-options/add-ons/network-plugins#disabling-deployment-of-a-network-plug-in) but which otherwise meets the Calico for Windows Kubernetes [cluster requirements](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/requirements.md). This guide was tested with RKE v1.18.9.
- One or more Windows nodes that meet the [requirements](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/requirements.md).

## How to

The following steps will outline the installation of Calico networking on the RKE cluster, then the installation of Calico for Windows on the Windows nodes.

1. Install the Tigera Operator and custom resource definitions.

   ```text
   kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.32.1/manifests/v1_crd_projectcalico_org.yaml
   kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.32.1/manifests/tigera-operator.yaml
   ```

   > **SECONDARY:** Due to the large size of the CRD bundle, `kubectl apply` might exceed request limits. Instead, use `kubectl create` or `kubectl replace`.

2. Download the necessary Installation custom resources.

   ```bash
   wget https://raw.githubusercontent.com/projectcalico/calico/v3.32.1/manifests/custom-resources.yaml
   ```

3. Update the `calicoNetwork` options, ensuring that the correct pod CIDR is set. (Rancher uses `10.42.0.0/16` by default.) Below are sample installations for VXLAN and BGP networking using the default Rancher pod CIDR:

   **VXLAN**

   ```yaml
   apiVersion: operator.tigera.io/v1
   kind: Installation
   metadata:
     name: default
   spec:
      # Configures Calico networking.
     calicoNetwork:
       bgp: Disabled
       ipPools:
       - blockSize: 26
         cidr: 10.42.0.0/16
         encapsulation: VXLAN
         natOutgoing: Enabled
         nodeSelector: all()
   ```

   **BGP**

   ```yaml
   apiVersion: operator.tigera.io/v1
   kind: Installation
   metadata:
     name: default
   spec:
      # Configures Calico networking.
     calicoNetwork:
       ipPools:
       - blockSize: 26
         cidr: 10.42.0.0/16
         encapsulation: None
         natOutgoing: Enabled
         nodeSelector: all()
   ```

   > **SECONDARY:** For more information on configuration options available in this manifest, see [the installation reference](https://docs.tigera.io/calico/latest/reference/installation/api.md).

4. Apply the updated custom resources:

   ```bash
   kubectl create -f custom-resources.yaml
   ```

5. Configure strict affinity:

   ```bash
   kubectl patch ipamconfigurations default --type merge --patch='{"spec": {"strictAffinity": true}}'
   ```

6. Finally, install Calico for Windows. For an operator installation, follow the [operator guide](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/operator.md). For VXLAN clusters, follow the instructions under the "Kubernetes VXLAN" tab. For BGP clusters, follow the instructions under the "Kubernetes BGP" tab.

   > **SECONDARY:** For Rancher default values for service CIDR and DNS cluster IP, see the [Rancher kube-api service options](https://rancher.com/docs/rke/latest/en/config-options/services/#kubernetes-api-server-options).

7. Check the status of the nodes with `kubectl get nodes`. If you see that the Windows node has the status `Ready`, then you have a Calico for Windows on RKE cluster ready for Linux and Windows workloads!

## Next steps

- [Try the basic policy demo](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/demo.md)
- [Secure pods with Calico network policy](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-network-policy.md)
