Skip to main content
Calico Open Source 3.31 (latest) documentation

Calico product editions

Calico Open Source icon
Calico Open Source

Open-source networking and security for containers and Kubernetes

Calico Cloud Free Tier icon
Calico Cloud Free Tier

Observability & policy management for a single cluster

Calico Cloud icon
Calico Cloud

SaaS platform for Kubernetes networking and security

Calico Enterprise icon
Calico Enterprise

Self-managed platform for Kubernetes networking and security

Which product edition is right for me?​

My needsCalico product edition
I want open source, best-in-class networking, network security, and observability capabilities that can work across any Kubernetes distribution, for free.Calico Open Source
Get Started
I’m a Calico Open Source user who wants to leverage some of the improved observability and policy management capabilities that are available in Calico Cloud, for free.Calico Cloud Free Tier
Sign up
My organization wants a fully managed SaaS platform for network security and observability.Calico Cloud
Get Started
My organization wants a self-managed platform for network security and observability.Calico Enterprise
Get Started

Feature comparison matrix​

Calico Open SourceCalico Cloud Free Tier*Calico CloudCalico Enterprise
Management and Support
Mutli-cluster security controls management
Data retentionIn-memory24 hours7 daysUnlimited
Number of clustersUnlimitedOneUnlimitedUnlimited
Number of usersN/AOneUnlimitedUnlimited
Support and maintenanceCommunity-drivenCommunity-drivenStandard/BusinessStandard/Business
Networking
High performance, scalable pod networking
Advanced IP address management
Direct infrastructure peering without the overlay
eBPF data plane
Windows data plane
nftables data plane
iptables data plane
VPP data plane
Multiple Calico networks on a pod
Dual ToR peering
Ingress gateway
Egress gateway
Cluster mesh
Network Security
Seamless support for Kubernetes network policy
Label-based policies for K8s and non-K8s workloads
Namespace and cluster-wide scope
Global default deny policy design
Application layer policy
Policy for services
Policy boardView only
DNS/FQDN-based policy
Hierarchical tiered network policy
Policy recommendationsManual workflow
Staged network policy
Preview staged policies
Network sets to limit IP ranges for egress and ingress traffic to workloads
Data-in-transit encryption
Universal firewall integration
Workload-based IDS/IPS
Deep packet inspection
DDoS protection
Workload-centric WAF
Compliance reporting and alerts
SIEM integrations
Network Security for VMs and Bare Metal
Restrict traffic to/from hosts and VMs using network policy
Automatic host endpoints
Apply policy to host-forwarded traffic
Observability
Flow logs API
Calico Whisker web console
Dynamic service and threat graph
Application level observability
Dynamic packet capture
Flow visualizer
Logs (flow)
Logs (http traffic, audit, bgp, dns, events)
Dashboards**
Alerts

* Calico Cloud Free Tier requires a cluster with Calico Open Source 3.30 or higher.

** Calico Cloud Free Tier includes some of the dashboards that are available in Calico Cloud and Calico Enterprise.

How to get started with Calico​

Calico powers 100M+ containers across 8M+ nodes in 166 countries, and is supported across all major cloud providers and Kubernetes distributions.

Ready to get started?​

Start a free trial or request a demo to see Calico in action.

Installation guides​

How to engage​

Learning resources​

Get involved​

Get in touch​