Project reference ↗

Calico provides the network that lets Kubernetes workloads communicate and the rules that limit which connections are allowed. Teams use it to connect applications across machines and prevent services from reaching systems they should not access. Depending on the cluster, it can supply the networking implementation or a compatible policy-enforcement layer. Because application traffic depends on that choice, installing or changing Calico is a cluster networking decision, not just adding another application.

Chart ownership

Calico's official documentation installs the Tigera operator using the tigera-operator chart from https://docs.tigera.io/calico/charts. The operator then manages Calico components. Consult the selected release's instructions for CRDs instead of assuming the controller chart upgrades every schema.

Before adoption

A CNI change can interrupt the entire cluster. Follow the distribution-specific prerequisites, address-pool and routing configuration, and check whether an existing CNI permits policy-only installation. Preserve access that does not depend on the workload network. Plan migrations and recovery on a representative non-production cluster, including node replacement and policy enforcement. Do not install a second network implementation as an ordinary application chart.

Read the Helm installation guide and upgrade guidance.

Sources & further reading

  1. Calico Helm installation
  2. Calico Kubernetes upgrade guidance

Spotted something that needs another look?

Help improve this page →