Unified Network Security & Observability for Kubernetes
Secure, observe, and troubleshoot your Kubernetes environments – in cloud, on-prem, or at the edge – with Calico Cloud.
Calico Cloud provides network security, comprehensive observability, and advanced traffic controls to help your teams protect and scale business-critical applications running on any Kubernetes distribution.
Running Calico OSS v3.30+? Connect seamlessly to the Free Forever version of Calico Cloud & gain instant visibility into your cluster.



Why Calico Cloud?

Pricing
Calico Cloud comes in two fully-managed versions that offer active security for containers and Kubernetes. Our Free Forever option is ideal for one user and one cluster already running open source Calico. For teams who need to secure multiple clusters, use more advanced features, or retain logs beyond 24 hours, we offer a Pay-as-you-go version.
For a completely self-managed option, see Calico Enterprise.
Free ForeverGet the most from your deployment of open source Calico | Pay-As-You-GoMulti-cloud, multi-cluster, or team environments | |
---|---|---|
Requires Calico 3.30 or Greater | Yes | No |
Users | One | Unlimited |
Clusters | One | Unlimited |
Service Graph | ✔ | ✔ |
Policy Dashboard | ✔ | ✔ |
Policy Editor | View Only | ✔ |
Policy Recommendations | ✔ | ✔ |
Logs | 24 hrs | 7 days |
Packet Capture | -- | ✔ |
Egress Gateway | -- | ✔ |
Threat Defense | -- | ✔ |
DNS and L7 | -- | ✔ |
Alerts | -- | ✔ |
Anomaly Detection | -- | ✔ |
Free ForeverStart Free | Starting at $0.025 / vCPU HourSchedule a Price Estimation Call |
How do teams use Calico Cloud?
Automate consistent network security enforcement with embedded network policies security as code in CI/CD pipelines. Use a single management plane to visualize traffic dependencies and manage network policies across any Kubernetes cluster on any distribution. Quickly troubleshoot gnarly Kubernetes network issues with an intuitive service graph and dashboards.

Unify Kubernetes networking, security, and observability in a single, distribution-agnostic platform. Manage ingress, egress, and east-west traffic consistently across any Kubernetes environment—on-prem, cloud, or edge. Eliminate silos and scale seamlessly from single to multi-cluster deployments with a cluster mesh for security and observability. Extend network security and observability to VMs and bare metals.

Strengthen the network security posture of Kubernetes workloads with granular workload access controls for egress and east-west traffic. Prevent attacks with workload-based IDS/IPS, WAF, and granular microsegmentation. Detect threats at runtime and proactively mitigate the risk of exposure with network policies to quarantine infected workloads. Accelerate incident response and ensure compliance through deep observability and forensic capabilities.

Customer Stories
“Thanks to Calico, we are now able to see exactly where things are happening in our environment, which allows us to identify potential security threats, monitor cluster health, and troubleshoot performance, connectivity, and security issues.”
Matthew Riedle
Sr. Staff Security Engineer,
eHealth
“Tigera is our zero trust security partner. Whatever Box does with its Kubernetes clusters, Calico is always a key component.”
Apas Mohapatra
Sr. Manager, Site Reliability Engineering, Cloud & Kubernetes,
Box
“Calico played a crucial role in our journey towards containerization and Kubernetes. It provided the network security and compliance capabilities we needed, allowing us to modernize our applications and streamline our development processes.”
Vimal Nair
CTO,
Nowcom
“Calico Cloud made the lives of the platform, security, finance, and legal teams easier due to its one-stop solution approach. Calico’s comprehensive and consolidated security solution, including a WAF, security policies, active monitoring, image assurance, CIS benchmarking, and threat feeds, saved us from having to implement 5 different standalone solutions.”
Romil Khanna
Data Security Officer & Platform Engineering Team Lead,
Nuralogix
“Rafay recommends Calico as the default networking and security solution for customers using the Rafay Kubernetes Operations Platform. No one should run Kubernetes without Calico networking and security.”
Mohan Atreya
Senior VP of Product and Solutions,
Rafay
“Tigera helped Upwork migrate to Kubernetes on Amazon EKS and meet our InfoSec team’s mandate for zero-trust security. We were able to deploy Calico in two weeks and secure our EKS cluster in just six months.”
Angelos Lenis
Sr. Manager, Platform Engineering,
Upwork