# Calico Open Source > Open source networking and network security for containers and Kubernetes. ## About Calico - [About Calico](https://docs.tigera.io/calico/latest/about.md): Overview of Calico Open Source, the upstream Calico project for Kubernetes networking, network security, and observability across any cluster. - [Calico product editions](https://docs.tigera.io/calico/latest/about/calico-product-editions.md): Compare Calico Open Source with Calico Cloud and Calico Enterprise across networking, security, and observability capabilities to pick the right edition. - [Training and resources](https://docs.tigera.io/calico/latest/about/training-resources.md): Onboarding and training resources for Calico Open Source, including quickstart guides, certified operator courses, workshops, videos, and community channels. - [Kubernetes networking and policy](https://docs.tigera.io/calico/latest/about/kubernetes-training.md): Introductory Kubernetes networking and network policy training for users new to Calico Open Source, covering services, ingress, egress, eBPF, and more. - [About Kubernetes Networking](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-k8s-networking.md): Background on the Kubernetes network model, services, DNS, NAT outgoing, and dual-stack networking concepts that underpin Calico Open Source deployments. - [About networking](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-networking.md): Background on networking fundamentals such as OSI layers, IP addressing, subnets, routing, overlays, DNS, and NAT for newcomers to Calico Open Source. - [What is network policy?](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-network-policy.md): Background on Kubernetes and Calico Open Source network policy, comparing API capabilities and offering best practices for securing cluster workloads. - [Kubernetes ingress](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-kubernetes-ingress.md): Background on Kubernetes ingress implementations, load balancing at L5-7, and how ingress controllers interact with network policy in Calico Open Source. - [Kubernetes egress](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-kubernetes-egress.md): Background on Kubernetes egress traffic, including outgoing NAT, restricting outbound connections, and egress gateways for Calico Open Source clusters. - [Kubernetes services](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-kubernetes-services.md): Background on Kubernetes service types (ClusterIP, NodePort, LoadBalancer) and how services interact with network policy in Calico Open Source clusters. - [About Calico eBPF](https://docs.tigera.io/calico/latest/about/kubernetes-training/about-ebpf.md): Background on eBPF and how the Calico Open Source eBPF data plane improves throughput, latency, and source IP preservation versus the standard Linux data plane. ## Installing and upgrading - [Install Calico](https://docs.tigera.io/calico/latest/getting-started.md): Install Calico Open Source on Kubernetes, OpenShift, OpenStack, or bare-metal hosts. Includes guidance on installing the calicoctl command-line tool. - [Calico quickstart guide](https://docs.tigera.io/calico/latest/getting-started/kubernetes/quickstart.md): Install Calico Open Source on a single-host Kubernetes cluster in roughly 15 minutes — the standard starter path for trying Calico networking and network policy on a development machine. - [System requirements for Kubernetes](https://docs.tigera.io/calico/latest/getting-started/kubernetes/requirements.md): Cluster, kernel, and platform requirements you must meet before installing Calico Open Source on Kubernetes. - [Community-tested Kubernetes versions](https://docs.tigera.io/calico/latest/getting-started/kubernetes/community-tested.md): Community-reported compatibility data for Calico Open Source across Kubernetes versions, distributions, and host platforms. - [Amazon Elastic Kubernetes Service (EKS)](https://docs.tigera.io/calico/latest/getting-started/kubernetes/managed-public-cloud/eks.md): Add Calico Open Source network policy to an Amazon EKS cluster running the AWS VPC CNI, without replacing the cluster's networking data plane. - [Install Calico network policy on a Google Kubernetes Engine cluster](https://docs.tigera.io/calico/latest/getting-started/kubernetes/managed-public-cloud/gke.md): Add Calico Open Source network policy to a Google Kubernetes Engine (GKE) cluster on top of the built-in GKE networking. - [IBM Cloud Kubernetes Service (IKS)](https://docs.tigera.io/calico/latest/getting-started/kubernetes/managed-public-cloud/iks.md): IBM Cloud Kubernetes Service (IKS) ships with Calico Open Source as the built-in networking and policy engine — what is included and how to use it. - [Microsoft Azure Kubernetes Service (AKS)](https://docs.tigera.io/calico/latest/getting-started/kubernetes/managed-public-cloud/aks.md): Add Calico Open Source network policy to an Azure Kubernetes Service (AKS) cluster running the Azure CNI. - [Migrate from Azure-managed Calico to self-managed Calico](https://docs.tigera.io/calico/latest/getting-started/kubernetes/managed-public-cloud/aks-migrate.md): Switch an AKS cluster between the Azure-managed Calico add-on and a self-managed Calico Open Source installation. - [Self-managed Kubernetes in Amazon Web Services (AWS)](https://docs.tigera.io/calico/latest/getting-started/kubernetes/self-managed-public-cloud/aws.md): Run Calico Open Source on a self-managed Kubernetes cluster in Amazon Web Services (AWS) — what to know about VPC sizing, MTU, and source/dest checks. - [Self-managed Kubernetes in Google Compute Engine (GCE)](https://docs.tigera.io/calico/latest/getting-started/kubernetes/self-managed-public-cloud/gce.md): Run Calico Open Source on a self-managed Kubernetes cluster in Google Compute Engine (GCE) — what to know about IP forwarding, MTU, and route limits. - [Self-managed Kubernetes in Microsoft Azure](https://docs.tigera.io/calico/latest/getting-started/kubernetes/self-managed-public-cloud/azure.md): Run Calico Open Source on a self-managed Kubernetes cluster in Microsoft Azure — what to know about VNet routing, UDR limits, and IPAM choices. - [Self-managed Kubernetes in DigitalOcean (DO)](https://docs.tigera.io/calico/latest/getting-started/kubernetes/self-managed-public-cloud/do.md): Run Calico Open Source on a self-managed Kubernetes cluster in DigitalOcean — what to know about MTU, droplet networking, and floating IPs. - [Install Calico networking and network policy for on-premises deployments](https://docs.tigera.io/calico/latest/getting-started/kubernetes/self-managed-onprem/onpremises.md): Install Calico Open Source networking and network policy on a self-managed Kubernetes cluster running on-premises hardware. - [Customize Calico configuration](https://docs.tigera.io/calico/latest/getting-started/kubernetes/self-managed-onprem/config-options.md): Customize a Calico Open Source on-premises installation before applying it — IP pools, BGP, MTU, and other Installation resource fields. - [Non-cluster hosts](https://docs.tigera.io/calico/latest/getting-started/bare-metal.md): Install Calico Open Source on bare-metal hosts outside a Kubernetes cluster — choose between policy-only, networking-only, or full installation paths. - [About non-cluster hosts](https://docs.tigera.io/calico/latest/getting-started/bare-metal/about.md): Install Calico Open Source on non-cluster hosts and VMs — pick between policy-only and networking-and-policy modes for protecting hosts outside Kubernetes. - [System requirements for Kubernetes](https://docs.tigera.io/calico/latest/getting-started/bare-metal/requirements.md): Operating system, kernel, and connectivity requirements for installing Calico Open Source on a non-cluster host. - [Install on non-cluster hosts](https://docs.tigera.io/calico/latest/getting-started/bare-metal/installation.md): Choose an installation method for Calico Open Source on a bare-metal host — package manager, raw binary, or Docker container. - [Docker container install](https://docs.tigera.io/calico/latest/getting-started/bare-metal/installation/container.md): Run the Calico Open Source agent on a non-cluster host inside a Docker container. - [Binary install with package manager](https://docs.tigera.io/calico/latest/getting-started/bare-metal/installation/binary-mgr.md): Install the Calico Open Source binary on a non-cluster host using a Linux package manager such as apt or yum. - [Binary install without package manager](https://docs.tigera.io/calico/latest/getting-started/bare-metal/installation/binary.md): Install the Calico Open Source binary directly on a non-cluster host without using a package manager. - [OpenShift](https://docs.tigera.io/calico/latest/getting-started/kubernetes/openshift.md): Install Calico Open Source on OpenShift 4 for cluster networking and network policy, replacing the default OVN-Kubernetes data plane. - [System requirements for OpenShift](https://docs.tigera.io/calico/latest/getting-started/kubernetes/openshift/requirements.md): Cluster, OpenShift, and host OS requirements you must meet before installing Calico Open Source on an OpenShift 4 cluster. - [Install an OpenShift 4 cluster with Calico](https://docs.tigera.io/calico/latest/getting-started/kubernetes/openshift/installation.md): Install Calico Open Source on a self-managed OpenShift 4 cluster using the operator-based installation flow. - [Install Calico on an OpenShift HCP cluster](https://docs.tigera.io/calico/latest/getting-started/kubernetes/openshift/hostedcontrolplanes.md): Install Calico Open Source on an OpenShift Hosted Control Planes (HCP) cluster, where the control plane is managed and the data plane runs on user-owned nodes. - [Migrate from OVN-Kubernetes CNI to Calico](https://docs.tigera.io/calico/latest/getting-started/kubernetes/openshift/ovn-to-calico.md): Migrate an OpenShift 4 cluster from the OVN-Kubernetes CNI to Calico Open Source as the cluster networking provider. - [Rancher Kubernetes Engine (RKE)](https://docs.tigera.io/calico/latest/getting-started/kubernetes/rancher.md): Install Calico Open Source on a Rancher Kubernetes Engine cluster. - [Flannel](https://docs.tigera.io/calico/latest/getting-started/kubernetes/flannel.md): Run Calico Open Source policy enforcement on a cluster that uses Flannel for the networking data plane. - [Install Calico for policy and flannel (aka Canal) for networking](https://docs.tigera.io/calico/latest/getting-started/kubernetes/flannel/install-for-flannel.md): Install Calico Open Source network policy on an existing Flannel-networked cluster without replacing the data plane. - [Migrate a Kubernetes cluster from flannel/Canal to Calico](https://docs.tigera.io/calico/latest/getting-started/kubernetes/flannel/migration-from-flannel.md): Migrate from Flannel to Calico Open Source while preserving the existing VXLAN data plane, gaining Calico IPAM and advanced policy. - [Calico for Windows](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico.md): Install and configure Calico Open Source for Windows — covers requirements, supported platforms, and the install paths for Windows nodes. - [Limitations and known issues](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/limitations.md): Known limitations of Calico Open Source for Windows that you should review before planning an installation. - [Requirements](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/requirements.md): Cluster and Windows host requirements you must meet before installing Calico Open Source for Windows. - [Install using Operator](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/operator.md): Install Calico Open Source for Windows on a Kubernetes cluster using the operator, for testing or development. - [Calico for Windows on a Rancher Kubernetes Engine cluster](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/rancher.md): Install Calico Open Source for Windows on a Rancher RKE cluster with Windows worker nodes. - [Basic policy demo](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/demo.md): Interactive demo that applies basic Calico Open Source network policy to pods running on a Windows node. - [Troubleshoot Calico for Windows](https://docs.tigera.io/calico/latest/getting-started/kubernetes/windows-calico/troubleshoot.md): Troubleshooting guide for Calico Open Source for Windows clusters — common issues, diagnostic steps, and where to look for logs. - [K3s](https://docs.tigera.io/calico/latest/getting-started/kubernetes/k3s.md): Install Calico Open Source on a K3s cluster — covers single-node and multi-node configurations. - [Quickstart for Calico on K3s](https://docs.tigera.io/calico/latest/getting-started/kubernetes/k3s/quickstart.md): Quickstart that installs Calico Open Source on a single-node K3s cluster in roughly 5 minutes for testing or development. - [K3s multi-node install](https://docs.tigera.io/calico/latest/getting-started/kubernetes/k3s/multi-node-install.md): Install Calico Open Source on a multi-node K3s cluster for testing or development workloads. - [Install using Helm](https://docs.tigera.io/calico/latest/getting-started/kubernetes/helm.md): Install Calico Open Source on a Kubernetes cluster using a Helm 3 chart. - [Install Calico on a single-host Kubernetes cluster](https://docs.tigera.io/calico/latest/getting-started/kubernetes/k8s-single-node.md): Install Calico Open Source on a single-host Kubernetes cluster for testing or development in roughly 15 minutes. - [Quickstart for Calico on MicroK8s](https://docs.tigera.io/calico/latest/getting-started/kubernetes/microk8s.md): Install Calico Open Source on a single-host MicroK8s cluster for testing or development in roughly 5 minutes. - [Quickstart for Calico on minikube](https://docs.tigera.io/calico/latest/getting-started/kubernetes/minikube.md): Install Calico Open Source on a single- or multi-node minikube cluster for testing or development in roughly 1 minute. - [Kind multi-node install](https://docs.tigera.io/calico/latest/getting-started/kubernetes/kind.md): Install Calico Open Source on a single- or multi-node Kind cluster for testing or development in roughly 10 minutes. - [Calico the hard way](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway.md): Calico the hard way — install every Calico Open Source component manually to understand how the pieces fit together end to end. - [Calico the hard way](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/overview.md): Step-by-step tutorial intro for Calico the hard way — the cluster you build with Calico Open Source, the components installed by hand, and prerequisites. - [Stand up Kubernetes](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/standing-up-kubernetes.md): Calico the hard way — stand up a minimal Kubernetes cluster ready to receive a manual Calico Open Source installation. - [The Calico datastore](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/the-calico-datastore.md): Calico the hard way — choose between the Kubernetes API datastore and etcd for the Calico Open Source operational and configuration store. - [Configure IP pools](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/configure-ip-pools.md): Calico the hard way — define IP pools that govern which address ranges Calico Open Source assigns to pods and services. - [Install CNI plugin](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/install-cni-plugin.md): Calico the hard way — install the Calico Open Source CNI plugin on each node and wire it into kubelet. - [Install Typha](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/install-typha.md): Calico the hard way — install Typha to fan out datastore reads so Calico Open Source can scale to large clusters. - [Install calico/node](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/install-node.md): Calico the hard way — deploy calico/node as a DaemonSet so the Calico Open Source agent runs on every cluster node. - [Configure BGP peering](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/configure-bgp-peering.md): Calico the hard way — configure BGP peering between Calico Open Source nodes and review the available peering topologies. - [Test networking](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/test-networking.md): Calico the hard way — verify pod-to-pod connectivity and routing on a cluster after the manual Calico Open Source build-out. - [Test network policy](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/test-network-policy.md): Calico the hard way — verify that Calico Open Source network policy enforcement is working after the manual install. - [End user RBAC](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/end-user-rbac.md): Calico the hard way — RBAC roles and access controls that govern who can edit Calico Open Source resources in a production cluster. - [Istio integration](https://docs.tigera.io/calico/latest/getting-started/kubernetes/hardway/istio-integration.md): Calico the hard way — extend Calico Open Source policy enforcement into Istio service-mesh sidecars for layer-7 traffic. - [Upgrade](https://docs.tigera.io/calico/latest/operations/upgrading.md): Upgrade options for Calico Open Source clusters covering Kubernetes, OpenShift, and OpenStack platforms with manifest, Helm, and operator install methods. - [Upgrade Calico on Kubernetes](https://docs.tigera.io/calico/latest/operations/upgrading/kubernetes-upgrade.md): Upgrade Calico Open Source on Kubernetes from v3.15 or later for Helm, operator-managed, and manifest-based installs on both Kubernetes API and etcd datastores. - [Upgrade Calico on OpenShift 4](https://docs.tigera.io/calico/latest/operations/upgrading/openshift-upgrade.md): Upgrade Calico Open Source on OpenShift 4 by reapplying manifests and updating OwnerReferences for projectcalico.org/v3 resources. - [Upgrade Calico on OpenStack](https://docs.tigera.io/calico/latest/operations/upgrading/openstack-upgrade.md): Upgrade Calico Open Source on OpenStack from v3.0 or later by updating system packages on CentOS or Ubuntu compute and control nodes. - [eBPF data plane mode](https://docs.tigera.io/calico/latest/operations/ebpf.md): Reference index for the Calico Open Source eBPF data plane covering installation, runtime switching, troubleshooting, and use-case selection. - [eBPF use cases](https://docs.tigera.io/calico/latest/operations/ebpf/use-cases-ebpf.md): Guidance on when the Calico Open Source eBPF data plane fits a workload compared to the standard iptables data plane, with trade-offs and feature comparisons. - [Enabling the eBPF data plane](https://docs.tigera.io/calico/latest/operations/ebpf/enabling-ebpf.md): Switch a running Calico Open Source cluster to the eBPF data plane through automatic Tigera Operator detection on kubeadm clusters or a manual configuration path. - [Install in eBPF mode](https://docs.tigera.io/calico/latest/operations/ebpf/install.md): Install Calico Open Source with the eBPF data plane during initial cluster setup as an alternative to the iptables data plane. - [Troubleshoot eBPF mode](https://docs.tigera.io/calico/latest/operations/ebpf/troubleshoot-ebpf.md): Troubleshooting guide for the Calico Open Source eBPF data plane covering verification logs, service connectivity, BPF map inspection, and common failure modes. - [Calico nftables data plane](https://docs.tigera.io/calico/latest/getting-started/kubernetes/nftables.md): Install Calico Open Source with the nftables data plane instead of the default iptables back end. - [VPP data plane](https://docs.tigera.io/calico/latest/getting-started/kubernetes/vpp.md): Install Calico Open Source with the VPP data plane — high-throughput userspace networking for clusters that need more than iptables or eBPF. - [Get started with VPP networking](https://docs.tigera.io/calico/latest/getting-started/kubernetes/vpp/getting-started.md): Install Calico Open Source with the VPP userspace data plane on a Kubernetes cluster. - [IPsec configuration with VPP](https://docs.tigera.io/calico/latest/getting-started/kubernetes/vpp/ipsec.md): Configure IPsec encryption between nodes for Calico Open Source clusters running the VPP data plane. - [Details of VPP implementation & known-issues](https://docs.tigera.io/calico/latest/getting-started/kubernetes/vpp/specifics.md): Behavioral differences to expect when running Calico Open Source with the VPP data plane instead of iptables or eBPF. - [Install an OpenShift 4 cluster with Calico VPP](https://docs.tigera.io/calico/latest/getting-started/kubernetes/vpp/openshift.md): Install Calico Open Source with the VPP data plane on an OpenShift 4 cluster. - [OpenStack](https://docs.tigera.io/calico/latest/getting-started/openstack.md): Install Calico Open Source networking and network policy for OpenStack — covers Neutron integration, supported distributions, and the OpenStack-specific install path. - [Calico for OpenStack](https://docs.tigera.io/calico/latest/getting-started/openstack/overview.md): Components and topology used when running Calico Open Source as the networking and policy layer for an OpenStack deployment. - [System requirements for OpenStack](https://docs.tigera.io/calico/latest/getting-started/openstack/requirements.md): Hypervisor, OS, and OpenStack requirements you must meet before installing Calico Open Source on OpenStack nodes. - [Install Calico on OpenStack](https://docs.tigera.io/calico/latest/getting-started/openstack/installation.md): Install Calico Open Source on an OpenStack deployment — choose a supported Linux distribution and follow the per-distribution path. - [Calico on OpenStack](https://docs.tigera.io/calico/latest/getting-started/openstack/installation/overview.md): Pick an installation method for Calico Open Source on OpenStack — DevStack for evaluation, or a per-distribution path for production. - [Ubuntu](https://docs.tigera.io/calico/latest/getting-started/openstack/installation/ubuntu.md): Install Calico Open Source on an OpenStack deployment running Ubuntu compute nodes. - [Red Hat Enterprise Linux](https://docs.tigera.io/calico/latest/getting-started/openstack/installation/redhat.md): Install Calico Open Source on an OpenStack deployment running Red Hat Enterprise Linux compute nodes. - [DevStack](https://docs.tigera.io/calico/latest/getting-started/openstack/installation/devstack.md): Quickstart that wires Calico Open Source into a DevStack OpenStack environment to verify connectivity and policy. - [Verify your deployment](https://docs.tigera.io/calico/latest/getting-started/openstack/installation/verification.md): Verification steps that confirm a Calico Open Source OpenStack deployment is forwarding traffic and applying policy correctly. ## Networking - [Networking](https://docs.tigera.io/calico/latest/networking.md): Calico Open Source networking spans overlay and non-overlay data planes, BGP, IPAM, MTU tuning, and Kubernetes Gateway API ingress for flexible cluster connectivity. - [Determine best networking option](https://docs.tigera.io/calico/latest/networking/determine-best-networking.md): Compare networking options in Calico Open Source — overlay versus non-overlay, BGP routing, CNI choices, and IPAM modes — to pick the right combination for your environment. - [Calico Ingress Gateway](https://docs.tigera.io/calico/latest/networking/ingress-gateway/about-calico-ingress-gateway.md): Overview of Calico Ingress Gateway in Calico Open Source — a hardened Envoy Gateway distribution that uses the Kubernetes Gateway API for cluster ingress. - [Create an ingress gateway](https://docs.tigera.io/calico/latest/networking/ingress-gateway/create-ingress-gateway.md): Deploy a Calico Ingress Gateway on Calico Open Source by applying a GatewayAPI resource and a Gateway that references the Tigera-managed gateway class. - [Customizing your ingress gateway](https://docs.tigera.io/calico/latest/networking/ingress-gateway/customize-ingress-gateway.md): Customize a Calico Ingress Gateway in Calico Open Source through the GatewayAPI resource — node selectors, multiple gateway classes, pod metadata, and load balancer service options. - [Tutorial: Launch a canary deployment with Calico Ingress Gateway](https://docs.tigera.io/calico/latest/networking/ingress-gateway/tutorial-ingress-gateway-canary.md): Step-by-step tutorial for shipping a canary deployment with Calico Ingress Gateway on Calico Open Source by splitting HTTPRoute traffic between stable and new versions. - [Migrating from NGINX Ingress](https://docs.tigera.io/calico/latest/networking/ingress-gateway/migrate-from-nginx.md): Migrate from NGINX Ingress to Calico Ingress Gateway on Calico Open Source, covering the Gateway API mental model, an annotation conversion tool, and a step-by-step workflow. - [Configure Networking](https://docs.tigera.io/calico/latest/networking/configuring.md): Networking configuration tasks for Calico Open Source — BGP, overlay encapsulation, service advertisement, MTU, NAT, IPVS kube-proxy, and QoS controls. - [Configure BGP peering](https://docs.tigera.io/calico/latest/networking/configuring/bgp.md): Configure BGP peering for Calico Open Source — full mesh, node-specific peers, top-of-rack switches, and Calico route reflectors — using BGPPeer and BGPConfiguration resources. - [Configure BGP peering with nested clusters running on KubeVirt VMs](https://docs.tigera.io/calico/latest/networking/configuring/bgp-to-workload.md): Peer Calico Open Source nodes with BGP speakers running inside KubeVirt VMs to support nested clusters and route announcements from workloads. - [Overlay networking](https://docs.tigera.io/calico/latest/networking/configuring/vxlan-ipip.md): Pick between VXLAN and IP-in-IP overlay modes in Calico Open Source so pod traffic crosses underlay networks that don't route pod CIDRs natively. - [Advertise Kubernetes service IP addresses](https://docs.tigera.io/calico/latest/networking/configuring/advertise-service-ips.md): Advertise Kubernetes service cluster IPs and external IPs out of the cluster over BGP with Calico Open Source so external clients can route to them directly. - [Configure MTU to maximize network performance](https://docs.tigera.io/calico/latest/networking/configuring/mtu.md): Tune the Calico Open Source MTU on the FelixConfiguration resource so pod traffic matches the underlying network, including VXLAN, IP-in-IP, and WireGuard overheads. - [Configure outgoing NAT](https://docs.tigera.io/calico/latest/networking/configuring/workloads-outside-cluster.md): Set NAT outgoing on Calico Open Source IP pools so pod traffic to destinations outside the cluster is source-NATed to the node's IP. - [Use IPVS kube-proxy](https://docs.tigera.io/calico/latest/networking/configuring/use-ipvs.md): Run kube-proxy in IPVS mode with Calico Open Source for constant-time service load balancing on clusters with thousands of services. - [Accelerate Istio network performance](https://docs.tigera.io/calico/latest/networking/configuring/sidecar-acceleration.md): Accelerate Istio Envoy sidecar traffic on Calico Open Source by using eBPF SOCKMAP to bypass kernel networking layers between the sidecar and the application. - [Use a specific MAC address for a pod](https://docs.tigera.io/calico/latest/networking/configuring/pod-mac-address.md): Set a chosen MAC address on a Kubernetes pod interface with the Calico Open Source CNI plugin, useful for software licensing tied to MAC. - [Use NodeLocal DNSCache in your cluster](https://docs.tigera.io/calico/latest/networking/configuring/node-local-dns-cache.md): Install NodeLocal DNSCache alongside Calico Open Source and configure network policy that lets pod DNS traffic reach the local cache. - [Configure QoS Controls](https://docs.tigera.io/calico/latest/networking/configuring/qos-controls.md): Cap pod ingress and egress bandwidth, packet rate, and connection counts with Calico Open Source QoS controls, plus DiffServ marking on egress traffic. - [Add Maglev load balancing to a service](https://docs.tigera.io/calico/latest/networking/configuring/add-maglev-load-balancing.md): Switch a Kubernetes service to Maglev consistent-hash load balancing on the Calico Open Source eBPF data plane for resilient backend selection. - [IP address management](https://docs.tigera.io/calico/latest/networking/ipam.md): IP address management with Calico Open Source — IPPools, block sizes, dual-stack IPv6, service load balancer IPAM, topology-aware assignment, and pool migration. - [Get started with IP address management](https://docs.tigera.io/calico/latest/networking/ipam/get-started-ip-addresses.md): Decide between Calico Open Source IPAM and host-local IPAM, then configure IP pool allocation, NAT outgoing, and per-namespace assignment. - [Create multiple IP pools](https://docs.tigera.io/calico/latest/networking/ipam/ippools.md): Create additional Calico Open Source IPPool resources at install time or on a running cluster to serve disjoint ranges, IPv6, or per-topology pod address assignment. - [Configure IP autodetection](https://docs.tigera.io/calico/latest/networking/ipam/ip-autodetection.md): Choose how Calico Open Source detects each node's primary IP address, with options for first-found, Kubernetes internal, interface regex, CIDR, and skip-interface. - [Configure dual stack or IPv6 only](https://docs.tigera.io/calico/latest/networking/ipam/ipv6.md): Set up dual-stack or IPv6-only pod networking on Calico Open Source by configuring IP pools, node IP autodetection, and the CNI plugin. - [Configure Kubernetes control plane to operate over IPv6](https://docs.tigera.io/calico/latest/networking/ipam/ipv6-control-plane.md): Run the Kubernetes control plane over IPv6 with Calico Open Source for dual-stack or IPv6-only clusters, including kubeadm flags and node configuration. - [Add a floating IP to a pod](https://docs.tigera.io/calico/latest/networking/ipam/add-floating-ip.md): Attach one or more floating IPs to a Kubernetes pod with Calico Open Source IPAM so external clients can reach the workload over any IP protocol. - [Use a specific IP address with a pod](https://docs.tigera.io/calico/latest/networking/ipam/use-specific-ip.md): Pin a Kubernetes pod to a chosen IP address with Calico Open Source IPAM by setting a pod annotation that supplies the requested address. - [Assign IP addresses based on topology](https://docs.tigera.io/calico/latest/networking/ipam/assign-ip-addresses-topology.md): Bind Calico Open Source IP pools to specific zones, racks, or regions with node selectors so pods receive addresses that match the cluster topology. - [Migrate from one IP pool to another](https://docs.tigera.io/calico/latest/networking/ipam/migrate-pools.md): Migrate workloads from one Calico Open Source IPPool to another on a running cluster without disrupting existing pod connectivity. - [Change IP pool block size](https://docs.tigera.io/calico/latest/networking/ipam/change-block-size.md): Resize an IPPool block in Calico Open Source — by creating a replacement pool and migrating workloads — to use IP space more efficiently. - [Restrict a pod to use an IP address in a specific range](https://docs.tigera.io/calico/latest/networking/ipam/legacy-firewalls.md): Restrict pods to a defined IP address range with Calico Open Source so legacy firewalls and security appliances can recognize cluster workloads. - [LoadBalancer IP address management](https://docs.tigera.io/calico/latest/networking/ipam/service-loadbalancer.md): Use the Calico Open Source LoadBalancer controller to allocate addresses to Kubernetes Service type LoadBalancer from configured IP pools. - [Calico networking for OpenStack](https://docs.tigera.io/calico/latest/networking/openstack.md): Run Calico Open Source as the networking layer for an OpenStack cloud, covering Neutron integration, IP address ranges, floating IPs, and live migration. - [Set up a development machine](https://docs.tigera.io/calico/latest/networking/openstack/dev-machine-setup.md): Walk-through example of provisioning a developer VM on a Calico Open Source OpenStack cloud, with security groups, an external network attachment, and SSH access. - [Prepare a VM guest OS for IPv6](https://docs.tigera.io/calico/latest/networking/openstack/ipv6.md): Prepare a guest OS image for IPv6 connectivity on Calico Open Source OpenStack VMs by configuring DHCPv6 client behavior and accepting router advertisements. - [IP addressing and connectivity](https://docs.tigera.io/calico/latest/networking/openstack/connectivity.md): Plan IPv4 and IPv6 address ranges, gateway routing, and Neutron network setup to connect Calico Open Source OpenStack VMs with the data center fabric. - [Endpoint labels and operator policy](https://docs.tigera.io/calico/latest/networking/openstack/labels.md): Reference for the project, network, security-group, and namespace labels that Calico Open Source places on WorkloadEndpoints for OpenStack VMs, plus how to use them in policy. - [Configure systems for use with Calico](https://docs.tigera.io/calico/latest/networking/openstack/configuration.md): Configure Nova, Neutron, and DHCP agent settings on OpenStack compute hosts to run Calico Open Source as either a core plugin or an ML2 mechanism driver. - [Detailed semantics](https://docs.tigera.io/calico/latest/networking/openstack/semantics.md): Reference for the IP-only connectivity model Calico Open Source provides between OpenStack instances, and how it differs from traditional Neutron L2 semantics. - [Floating IPs](https://docs.tigera.io/calico/latest/networking/openstack/floating-ips.md): Allocate Neutron floating IPs against a Calico Open Source OpenStack tenant network, including router gateways, provider subnets, and core-plugin requirements. - [Service IPs](https://docs.tigera.io/calico/latest/networking/openstack/service-ips.md): Assign a service IP to a Calico Open Source OpenStack VM by attaching either a Neutron floating IP or an additional fixed IP on the VM port. - [Host routes](https://docs.tigera.io/calico/latest/networking/openstack/host-routes.md): Configure Neutron subnet host routes so the next-hop IP points at the local hypervisor in Calico Open Source OpenStack deployments and traffic flows correctly. - [Multiple regions](https://docs.tigera.io/calico/latest/networking/openstack/multiple-regions.md): Deploy Calico Open Source across multiple OpenStack regions sharing one etcd datastore, with per-region namespaces for inter-region policy. - [Live migration for OpenStack VMs](https://docs.tigera.io/calico/latest/networking/openstack/live-migration.md): Tune route priority and BGP propagation so Calico Open Source converges OpenStack VM traffic to the destination host quickly during live migration. - [Kuryr](https://docs.tigera.io/calico/latest/networking/openstack/kuryr.md): Use Kuryr together with the Calico ML2 driver in Calico Open Source so Neutron provides networking for container workloads. - [Calico's interpretation of Neutron API calls](https://docs.tigera.io/calico/latest/networking/openstack/neutron-api.md): Reference for how Calico Open Source interprets each Neutron API call — networks, subnets, ports, security groups, and Horizon actions — in an OpenStack deployment. - [Calico networking for KubeVirt](https://docs.tigera.io/calico/latest/networking/kubevirt.md): Run Calico Open Source as the network for KubeVirt virtual machines on Kubernetes, with persistent IPs, BGP routing, and live migration support. - [KubeVirt networking](https://docs.tigera.io/calico/latest/networking/kubevirt/kubevirt-networking.md): Configure Calico Open Source bridge-mode networking for KubeVirt VMs so each VM keeps the same IP across reboots, evictions, and live migrations. - [BGP routing for KubeVirt live migration](https://docs.tigera.io/calico/latest/networking/kubevirt/live-migration-bgp.md): Configure BGPFilter resources in Calico Open Source so elevated route priorities propagate across racks and AS boundaries during KubeVirt live migration. ## Network policy - [Network policy](https://docs.tigera.io/calico/latest/network-policy.md): Secure Kubernetes workloads and hosts with Calico Open Source network policy — Calico NetworkPolicy and GlobalNetworkPolicy resources for adopting a zero-trust model. - [Adopt a zero trust network model for security](https://docs.tigera.io/calico/latest/network-policy/adopt-zero-trust.md): Adopt a zero-trust network model for Kubernetes workloads and hosts using Calico Open Source — five requirements for controlling network access in cloud-native environments. - [Get started with policy](https://docs.tigera.io/calico/latest/network-policy/get-started.md): Pick a path for getting started with Calico Open Source policy — Kubernetes-native NetworkPolicy basics, or the richer Calico-specific resources that work alongside it. - [Calico policy](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy.md): Use Calico Open Source policy resources to secure both workloads and hosts beyond what Kubernetes NetworkPolicy alone supports. - [Get started with Calico network policy](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-network-policy.md): Write your first Calico Open Source NetworkPolicy — sample policies that exercise the rich rule features that extend Kubernetes NetworkPolicy. - [Calico automatic labels](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-labels.md): Reference list of automatic labels Calico Open Source attaches to resources, useful as selectors in policy rules. - [Get started with Calico network policy for OpenStack](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/network-policy-openstack.md): Extend OpenStack security groups with Calico Open Source network policy and label-based rules for VMs running on OpenStack. - [Calico policy tutorial](https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-policy-tutorial.md): Step-by-step tutorial for advanced Calico Open Source policy patterns — namespace scoping, allow-all, deny-all, and ingress and egress controls. - [Kubernetes policy](https://docs.tigera.io/calico/latest/network-policy/get-started/kubernetes-policy.md): Manage Kubernetes NetworkPolicy resources alongside the more powerful Calico Open Source policy resources in the same cluster. - [Get started with Kubernetes network policy](https://docs.tigera.io/calico/latest/network-policy/get-started/kubernetes-policy/kubernetes-network-policy.md): Reference for Kubernetes NetworkPolicy syntax, rules, and features when used with the Calico Open Source enforcement engine. - [Kubernetes policy, demo](https://docs.tigera.io/calico/latest/network-policy/get-started/kubernetes-policy/kubernetes-demo.md): Interactive demo for a Calico Open Source cluster that visualizes how Kubernetes NetworkPolicy allows and denies connections between pods. - [Kubernetes policy, basic tutorial](https://docs.tigera.io/calico/latest/network-policy/get-started/kubernetes-policy/kubernetes-policy-basic.md): Apply your first Kubernetes NetworkPolicy in a Calico Open Source cluster to restrict ingress and egress traffic to and from pods. - [Kubernetes policy, advanced tutorial](https://docs.tigera.io/calico/latest/network-policy/get-started/kubernetes-policy/kubernetes-policy-advanced.md): Write more advanced Kubernetes NetworkPolicy resources in a Calico Open Source cluster — namespace scoping, allow-all, and deny-all variants. - [Enable a default deny policy for Kubernetes pods](https://docs.tigera.io/calico/latest/network-policy/get-started/kubernetes-default-deny.md): Apply a default-deny network policy in a Calico Open Source cluster so unprotected pods are denied traffic until explicit policy is written. - [Policy tiers](https://docs.tigera.io/calico/latest/network-policy/policy-tiers.md): Use Calico Open Source policy tiers so platform, security, and app teams can author and order policy independently within a single Kubernetes cluster. - [Get started with policy tiers](https://docs.tigera.io/calico/latest/network-policy/policy-tiers/tiered-policy.md): How tiered policy works in Calico Open Source — evaluation order, pass actions, and using tiers to support microsegmentation. - [Configure RBAC for tiered policies](https://docs.tigera.io/calico/latest/network-policy/policy-tiers/rbac-tiered-policies.md): Set up Kubernetes RBAC to control which users can edit Calico Open Source policies and tiers in a multi-team cluster. - [Stage, preview impacts, and enforce policy](https://docs.tigera.io/calico/latest/network-policy/staged-network-policies.md): Stage and preview Calico Open Source network policies to observe traffic implications before enforcing them in production. - [Policy rules](https://docs.tigera.io/calico/latest/network-policy/policy-rules.md): Control traffic to and from endpoints using Calico Open Source network policy rules — selectors, actions, and egress/ingress directions. - [Basic rules](https://docs.tigera.io/calico/latest/network-policy/policy-rules/policy-rules-overview.md): How to write policy rules in Calico Open Source — label selectors, source and destination match criteria, and rule actions. - [Use namespace rules in policy](https://docs.tigera.io/calico/latest/network-policy/policy-rules/namespace-policy.md): Group or separate workloads in Calico Open Source policy using namespaces and namespace selectors so policies apply only to specified namespaces. - [Use service rules in policy](https://docs.tigera.io/calico/latest/network-policy/policy-rules/service-policy.md): Match on Kubernetes Service names in Calico Open Source policy rules instead of specific pod selectors. - [Use service accounts rules in policy](https://docs.tigera.io/calico/latest/network-policy/policy-rules/service-accounts.md): Match on Kubernetes service accounts in Calico Open Source policy rules to validate workload identity and apply RBAC-controlled rules. - [Use external IPs or networks rules in policy](https://docs.tigera.io/calico/latest/network-policy/policy-rules/external-ips-policy.md): Restrict egress and ingress to specific IP ranges in Calico Open Source policy, either inline or via reusable network sets. - [Use ICMP/ping rules in policy](https://docs.tigera.io/calico/latest/network-policy/policy-rules/icmp-ping.md): Allow or deny ICMP and ping traffic for Calico Open Source workloads and host endpoints using policy rules. - [Use log rules to test network policy](https://docs.tigera.io/calico/latest/network-policy/policy-rules/log-rules.md): Add Log actions to Calico Open Source policy rules to debug which rules are matching traffic at runtime. - [Policy for hosts and VMs](https://docs.tigera.io/calico/latest/network-policy/hosts.md): Apply Calico Open Source network policy to host interfaces — extending the same selector-based policy model from pods to bare-metal hosts and VMs. - [Protect hosts and VMs](https://docs.tigera.io/calico/latest/network-policy/hosts/protect-hosts.md): Protect Kubernetes hosts and bare-metal nodes with Calico Open Source policy by writing rules that target host endpoints. - [Protect Kubernetes nodes](https://docs.tigera.io/calico/latest/network-policy/hosts/kubernetes-nodes.md): Protect Kubernetes node interfaces with Calico Open Source host endpoints to extend network policy to the node itself. - [Protect hosts tutorial](https://docs.tigera.io/calico/latest/network-policy/hosts/protect-hosts-tutorial.md): Tutorial for protecting hosts in a Calico Open Source cluster — register host endpoints, write rules, and allow controlled access to specific Kubernetes services. - [Apply policy to forwarded traffic](https://docs.tigera.io/calico/latest/network-policy/hosts/host-forwarded-traffic.md): Apply Calico Open Source network policy to traffic forwarded through hosts acting as routers or NAT gateways. - [Policy for Kubernetes services](https://docs.tigera.io/calico/latest/network-policy/services.md): Apply Calico Open Source policy to Kubernetes Services — node ports, ClusterIPs, and externally exposed services. - [Apply Calico policy to Kubernetes node ports](https://docs.tigera.io/calico/latest/network-policy/services/kubernetes-node-ports.md): Restrict access to Kubernetes NodePort services using Calico Open Source GlobalNetworkPolicy at the host endpoint. - [Apply Calico policy to services exposed externally as cluster IPs](https://docs.tigera.io/calico/latest/network-policy/services/services-cluster-ips.md): Expose Kubernetes Service ClusterIPs over BGP using Calico Open Source and restrict who can reach them with network policy. - [Policy for Istio](https://docs.tigera.io/calico/latest/network-policy/istio.md): Configure Calico Open Source application-layer policy to apply Istio service mesh attributes (HTTP methods, paths) to Kubernetes traffic. - [Enforce Calico network policy for Istio service mesh](https://docs.tigera.io/calico/latest/network-policy/istio/app-layer-policy.md): Apply Calico Open Source network policy to Istio service-mesh traffic, including matching on HTTP methods and paths. - [Use HTTP methods and paths in policy rules](https://docs.tigera.io/calico/latest/network-policy/istio/http-methods.md): Restrict ingress traffic to Istio-enabled apps by matching HTTP methods or paths in a Calico Open Source network policy. - [Enforce Calico network policy using Istio (tutorial)](https://docs.tigera.io/calico/latest/network-policy/istio/enforce-policy-istio.md): Use Calico Open Source with Istio to apply fine-grained access control at both the network layer and inside the service mesh. - [Policy for extreme traffic](https://docs.tigera.io/calico/latest/network-policy/extreme-traffic.md): Apply Calico Open Source network policy early in the Linux packet-processing pipeline to handle DoS, high-connection, and other extreme traffic scenarios. - [Enable extreme high-connection workloads](https://docs.tigera.io/calico/latest/network-policy/extreme-traffic/high-connection-workloads.md): Bypass Linux conntrack with a Calico Open Source policy rule for workloads that handle an extreme number of concurrent connections. - [Defend against DoS attacks](https://docs.tigera.io/calico/latest/network-policy/extreme-traffic/defend-dos-attack.md): Define DoS mitigation rules in Calico Open Source policy that drop connections at the eBPF or XDP layer, with hardware offload when available. - [Encrypt in-cluster pod traffic](https://docs.tigera.io/calico/latest/network-policy/encrypt-cluster-pod-traffic.md): Turn on WireGuard encryption between pods on a Calico Open Source cluster for state-of-the-art cryptographic protection of in-cluster traffic. - [Secure Calico component communications](https://docs.tigera.io/calico/latest/network-policy/comms.md): Secure communications between Calico Open Source components — TLS, BGP authentication, and metric-endpoint access control. - [Configure encryption and authentication to secure Calico components](https://docs.tigera.io/calico/latest/network-policy/comms/crypto-auth.md): Turn on TLS authentication and encryption between Calico Open Source components using a custom certificate authority. - [Schedule Typha for scaling to well-known nodes](https://docs.tigera.io/calico/latest/network-policy/comms/reduce-nodes.md): Configure the TCP port used by Typha in a Calico Open Source cluster to reduce datastore load on large clusters. - [Secure Calico Prometheus endpoints](https://docs.tigera.io/calico/latest/network-policy/comms/secure-metrics.md): Restrict access to Calico Open Source metric endpoints using network policy. - [Secure BGP sessions](https://docs.tigera.io/calico/latest/network-policy/comms/secure-bgp.md): Configure BGP authentication passwords for Calico Open Source so attackers cannot inject false routing information. ## Observability - [Observability](https://docs.tigera.io/calico/latest/observability.md): Observe Kubernetes network traffic in Calico Open Source with the Goldmane flow logs API and the Calico Whisker in-cluster web console. - [View flow logs in the Calico Whisker web console](https://docs.tigera.io/calico/latest/observability/view-flow-logs.md): Inspect aggregated network flow logs in the Calico Whisker in-cluster web console for Calico Open Source. Filter by source, destination, and policy verdicts. - [Enable the flow logs API and Calico Whisker](https://docs.tigera.io/calico/latest/observability/enable-whisker.md): Activate the Goldmane flow logs API and the Calico Whisker web console in Calico Open Source clusters that were upgraded from earlier versions. - [Flow logs API](https://docs.tigera.io/calico/latest/observability/flow-logs-api.md): Reference for the Goldmane flow logs API in Calico Open Source. Retrieve aggregated traffic data, policy hits, and packet and byte counts over gRPC. ## Operations - [Operations](https://docs.tigera.io/calico/latest/operations.md): Day-2 operations for Calico Open Source clusters covering upgrades, calicoctl, certificate management, monitoring, image registries, eBPF, and troubleshooting. - [Istio Ambient Mode](https://docs.tigera.io/calico/latest/operations/istio/about-istio-ambient.md): Overview of the Istio ambient mode service mesh bundled with Calico Open Source, covering mTLS without sidecars and integration with Calico network policy. - [Deploy Istio Ambient Mode on your cluster](https://docs.tigera.io/calico/latest/operations/istio/deploy-istio-ambient.md): Deploy the Calico Open Source bundled Istio ambient mesh on an existing cluster to add mTLS to workloads without sidecars or Waypoint. - [calicoctl](https://docs.tigera.io/calico/latest/operations/calicoctl.md): Install and configure calicoctl, the command-line tool for managing Calico Open Source resources in Kubernetes API and etcdv3 datastores. - [Install calicoctl](https://docs.tigera.io/calico/latest/operations/calicoctl/install.md): Install the calicoctl command-line tool as a binary or container so administrators can manage Calico Open Source resources from any workstation. - [Configure calicoctl](https://docs.tigera.io/calico/latest/operations/calicoctl/configure.md): Configure calicoctl to reach the datastore backing a Calico Open Source cluster through config files, environment variables, or kubeconfig credentials. - [Configure calicoctl](https://docs.tigera.io/calico/latest/operations/calicoctl/configure/overview.md): Overview reference for configuring calicoctl datastore access in Calico Open Source, comparing config-file, environment-variable, and kubeconfig credential methods. - [Configure calicoctl to connect to an etcd datastore](https://docs.tigera.io/calico/latest/operations/calicoctl/configure/etcd.md): Sample calicoctl configuration files for connecting to an etcdv3 datastore in a Calico Open Source cluster, with TLS, endpoints, and authentication settings. - [Configure calicoctl to connect to the Kubernetes API datastore](https://docs.tigera.io/calico/latest/operations/calicoctl/configure/kdd.md): Sample calicoctl configuration files for connecting to the Kubernetes API datastore in a Calico Open Source cluster using kubeconfig credentials. - [Install using an alternate registry](https://docs.tigera.io/calico/latest/operations/image-options.md): Install Calico Open Source from a public or private container registry, or pin operator-managed components to specific image digests. - [Install images by registry digest](https://docs.tigera.io/calico/latest/operations/image-options/imageset.md): Pin Calico Open Source operator deployments to immutable image digests with an ImageSet resource so security teams can review and verify each image. - [Configure use of your image registry](https://docs.tigera.io/calico/latest/operations/image-options/alternate-registry.md): Configure Calico Open Source to pull operator and component images from a public or private container registry, including air-gapped and constrained networks. - [Migrate from API server to native CRDs](https://docs.tigera.io/calico/latest/operations/crd-migration.md): Migrate Calico Open Source resources from the aggregated API server backing storage to native projectcalico.org/v3 CRDs so the API server component can be removed. - [Migrate Calico data from an etcdv3 datastore to a Kubernetes datastore](https://docs.tigera.io/calico/latest/operations/datastore-migration.md): Migrate a Calico Open Source cluster from the etcdv3 datastore to the Kubernetes API datastore with calicoctl, preserving network and policy state on a live cluster. - [Migrate Calico to an operator-managed installation](https://docs.tigera.io/calico/latest/operations/operator-migration.md): Migrate a Calico Open Source installation from manifest-based resources to an operator-managed install for automatic platform detection, simpler upgrades, and lifecycle management. - [Enable kubectl to manage Calico APIs](https://docs.tigera.io/calico/latest/operations/install-apiserver.md): Install the Calico Open Source aggregated API server on an existing cluster so kubectl can manage projectcalico.org/v3 resources without calicoctl. - [Enable native v3 CRDs](https://docs.tigera.io/calico/latest/operations/native-v3-crds.md): Switch Calico Open Source to native projectcalico.org/v3 CRDs so resources are stored directly as CRDs without the aggregated API server component. - [Monitor](https://docs.tigera.io/calico/latest/operations/monitor.md): Reference index for scraping and visualizing Calico Open Source component metrics with the open-source Prometheus and Grafana stack. - [Monitor Calico component metrics](https://docs.tigera.io/calico/latest/operations/monitor/monitor-component-metrics.md): Scrape Calico Open Source Felix, Typha, and kube-controllers metrics with open-source Prometheus and configure alerting rules from time-series data. - [Visualizing metrics via Grafana](https://docs.tigera.io/calico/latest/operations/monitor/monitor-component-visual.md): Visualize Calico Open Source component metrics scraped by Prometheus on Grafana dashboards to spot anomalies in Felix, Typha, and node performance. - [Decommission a node](https://docs.tigera.io/calico/latest/operations/decommissioning-a-node.md): Manually decommission a node in a self-managed Calico Open Source cluster with calicoctl, releasing IP allocations and BGP peers from the datastore cleanly. - [FIPS mode](https://docs.tigera.io/calico/latest/operations/fips.md): Run Calico Open Source in FIPS 140-2 compliant mode using NIST-validated cryptographic modules and FIPS-approved algorithms across all data plane components. - [Troubleshoot](https://docs.tigera.io/calico/latest/operations/troubleshoot.md): Troubleshooting guide for Calico Open Source clusters covering diagnostic commands, component logs, and known issues for self-managed installations. - [Troubleshooting and diagnostics](https://docs.tigera.io/calico/latest/operations/troubleshoot/troubleshooting.md): Troubleshooting guide for Calico Open Source clusters covering diagnostics, common failure patterns, log severity tuning, and where to file upstream issues. - [Troubleshooting commands](https://docs.tigera.io/calico/latest/operations/troubleshoot/commands.md): Reference of command-line tools and kubectl invocations for verifying cluster, routing, and component health in a Calico Open Source installation. - [Component logs](https://docs.tigera.io/calico/latest/operations/troubleshoot/component-logs.md): Reference for locating and collecting Calico Open Source component logs including calico/node, Felix, Typha, kube-controllers, and CNI plugin output. - [VPP data plane troubleshooting](https://docs.tigera.io/calico/latest/operations/troubleshoot/vpp.md): Troubleshooting guide for the Calico Open Source VPP data plane covering log collection, diagnostic helpers, and recovery from common VPP failure modes. - [Manage TLS certificates used by Calico](https://docs.tigera.io/calico/latest/operations/certificate-management.md): Manage TLS certificates for Calico Open Source components by controlling the certificate issuer through the Kubernetes Certificates API and operator configuration. ## Reference - [Reference](https://docs.tigera.io/calico/latest/reference.md): Reference content for Calico Open Source including APIs, calicoctl, architecture and design, host endpoints, Felix, Typha, and FAQ. - [Calico Client library](https://docs.tigera.io/calico/latest/reference/api.md): Calico Open Source Go client library reference for working with resources such as network policies programmatically against the Calico Open Source API. - [Installation reference](https://docs.tigera.io/calico/latest/reference/installation/api.md): Installation API reference for Calico Open Source listing the operator-managed custom resources used to configure cluster installation. - [Helm installation reference](https://docs.tigera.io/calico/latest/reference/installation/helm_customization.md): Helm chart values reference for installing Calico Open Source covering supported overrides and operator configuration knobs. - [calicoctl](https://docs.tigera.io/calico/latest/reference/calicoctl.md): Calico Open Source calicoctl command-line tool reference for managing Calico API resources, IP address management, BGP, and node operations. - [calicoctl user reference](https://docs.tigera.io/calico/latest/reference/calicoctl/overview.md): Reference overview of the calicoctl command-line tool for managing Calico Open Source network policy, BGP, IP address management, and node operations. - [calicoctl create](https://docs.tigera.io/calico/latest/reference/calicoctl/create.md): Reference for the calicoctl create command in Calico Open Source, used to create resources from a manifest file. - [calicoctl replace](https://docs.tigera.io/calico/latest/reference/calicoctl/replace.md): Reference for the calicoctl replace command in Calico Open Source, used to replace an existing resource with one defined in a manifest. - [calicoctl apply](https://docs.tigera.io/calico/latest/reference/calicoctl/apply.md): Reference for the calicoctl apply command in Calico Open Source, used to create or update resources from a manifest file. - [calicoctl delete](https://docs.tigera.io/calico/latest/reference/calicoctl/delete.md): Reference for the calicoctl delete command in Calico Open Source, used to remove resources by name or from a manifest file. - [calicoctl get](https://docs.tigera.io/calico/latest/reference/calicoctl/get.md): Reference for the calicoctl get command in Calico Open Source, used to list resources in plain, YAML, JSON, or wide output formats. - [calicoctl patch](https://docs.tigera.io/calico/latest/reference/calicoctl/patch.md): Reference for the calicoctl patch command in Calico Open Source, used to apply a partial update to a resource. - [calicoctl label](https://docs.tigera.io/calico/latest/reference/calicoctl/label.md): Reference for the calicoctl label command in Calico Open Source, used to add, change, or remove labels on workload endpoints and nodes. - [calicoctl validate](https://docs.tigera.io/calico/latest/reference/calicoctl/validate.md): Reference for the calicoctl validate command in Calico Open Source, used to check resource manifests for syntax and schema errors. - [cluster](https://docs.tigera.io/calico/latest/reference/calicoctl/cluster.md): Reference index for the calicoctl cluster subcommands in Calico Open Source. - [calicoctl cluster](https://docs.tigera.io/calico/latest/reference/calicoctl/cluster/overview.md): Reference overview of the calicoctl cluster subcommands in Calico Open Source for cluster-wide operations such as diagnostics collection. - [calicoctl cluster diags](https://docs.tigera.io/calico/latest/reference/calicoctl/cluster/diags.md): Reference for the calicoctl cluster diags command in Calico Open Source, used to collect diagnostics from all nodes in a cluster. - [ipam](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam.md): Reference index for the calicoctl IPAM subcommands in Calico Open Source for managing Calico-assigned IP addresses. - [calicoctl ipam](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/overview.md): Reference overview of the calicoctl IPAM subcommands in Calico Open Source for IP address management operations. - [calicoctl ipam check](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/check.md): Reference for the calicoctl IPAM check command in Calico Open Source, used to audit IP address allocation consistency across the cluster. - [calicoctl ipam release](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/release.md): Reference for the calicoctl IPAM release command in Calico Open Source, used to release a leaked or stale IP address back to the pool. - [calicoctl ipam show](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/show.md): Reference for the calicoctl IPAM show command in Calico Open Source, used to display the owner and details of an allocated IP address. - [calicoctl ipam configure](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/configure.md): Reference for the calicoctl IPAM configure command in Calico Open Source, used to set IP address management options such as strict affinity. - [calicoctl ipam split](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/split.md): Reference for the calicoctl IPAM split command in Calico Open Source, used to split an existing IP pool into smaller pools. - [node](https://docs.tigera.io/calico/latest/reference/calicoctl/node.md): Reference index for the calicoctl node subcommands in Calico Open Source. - [calicoctl node](https://docs.tigera.io/calico/latest/reference/calicoctl/node/overview.md): Reference overview of the calicoctl node subcommands in Calico Open Source for managing the calico/node container. - [calicoctl node run](https://docs.tigera.io/calico/latest/reference/calicoctl/node/run.md): Reference for the calicoctl node run command in Calico Open Source, used to start a calico/node instance with the supplied options. - [calicoctl node status](https://docs.tigera.io/calico/latest/reference/calicoctl/node/status.md): Reference for the calicoctl node status command in Calico Open Source, used to display BGP peer state and node liveness. - [calicoctl node diags](https://docs.tigera.io/calico/latest/reference/calicoctl/node/diags.md): Reference for the calicoctl node diags command in Calico Open Source, used to collect diagnostics from a single Calico node. - [calicoctl node checksystem](https://docs.tigera.io/calico/latest/reference/calicoctl/node/checksystem.md): Reference for the calicoctl node check-system command in Calico Open Source, used to verify host kernel support for Calico features. - [datastore](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore.md): Reference index for the calicoctl datastore subcommands in Calico Open Source covering migration between etcdv3 and Kubernetes datastores. - [calicoctl datastore](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/overview.md): Reference overview of the calicoctl datastore subcommands in Calico Open Source for migrating between etcdv3 and Kubernetes datastores. - [Migrate](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/migrate.md): Reference index for the calicoctl datastore migrate subcommands in Calico Open Source. - [calicoctl datastore migrate](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/migrate/overview.md): Reference overview of the calicoctl datastore migrate subcommands in Calico Open Source for performing safe datastore migrations. - [calicoctl datastore migrate export](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/migrate/export.md): Reference for the calicoctl datastore migrate export command in Calico Open Source, used to export resources from an etcdv3 datastore. - [calicoctl datastore migrate import](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/migrate/import.md): Reference for the calicoctl datastore migrate import command in Calico Open Source, used to import resources into a Kubernetes datastore. - [calicoctl datastore migrate lock](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/migrate/lock.md): Reference for the calicoctl datastore migrate lock command in Calico Open Source, used to lock a datastore during migration. - [calicoctl datastore migrate unlock](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/migrate/unlock.md): Reference for the calicoctl datastore migrate unlock command in Calico Open Source, used to unlock a datastore after migration completes. - [calicoctl datastore migrate-policy-names](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore/migrate-policy-names.md): Reference for the calicoctl datastore migrate-policy-names command in Calico Open Source, used to fix pre-v3.32 policy names on an upgraded etcdv3 datastore. - [calicoctl version](https://docs.tigera.io/calico/latest/reference/calicoctl/version.md): Reference for the calicoctl version command in Calico Open Source, used to display client and cluster version information. - [Resource definitions](https://docs.tigera.io/calico/latest/reference/resources.md): Reference index of the Calico Open Source API resources covering networking, IP address management, BGP, and policy custom resources. - [Resource definitions](https://docs.tigera.io/calico/latest/reference/resources/overview.md): Reference overview of the Calico Open Source API resources, including the manifest format and how calicoctl manages them. - [BGP configuration](https://docs.tigera.io/calico/latest/reference/resources/bgpconfig.md): Reference for the BGPConfiguration resource in Calico Open Source that sets cluster-wide BGP options including the autonomous system number and route reflectors. - [BGP peer](https://docs.tigera.io/calico/latest/reference/resources/bgppeer.md): Reference for the BGPPeer resource in Calico Open Source that defines a BGP neighbor relationship between Calico nodes and external routers. - [BGP filter](https://docs.tigera.io/calico/latest/reference/resources/bgpfilter.md): Reference for the BGPFilter resource in Calico Open Source that filters routes imported from or exported to BGP peers. - [Block affinity](https://docs.tigera.io/calico/latest/reference/resources/blockaffinity.md): Reference for the BlockAffinity resource in Calico Open Source that records which node owns each IP address management block. - [Calico node status](https://docs.tigera.io/calico/latest/reference/resources/caliconodestatus.md): Reference for the CalicoNodeStatus resource in Calico Open Source that exposes per-node agent, BGP, and routing state. - [Felix configuration](https://docs.tigera.io/calico/latest/reference/resources/felixconfig.md): Reference for the FelixConfiguration resource in Calico Open Source that controls Felix data plane behavior across the cluster. - [Global network policy](https://docs.tigera.io/calico/latest/reference/resources/globalnetworkpolicy.md): Reference for the GlobalNetworkPolicy resource in Calico Open Source, a cluster-scoped policy that selects endpoints across all namespaces. - [Global network set](https://docs.tigera.io/calico/latest/reference/resources/globalnetworkset.md): Reference for the GlobalNetworkSet resource in Calico Open Source that defines a cluster-scoped set of CIDRs referenced by network policy. - [Host endpoint](https://docs.tigera.io/calico/latest/reference/resources/hostendpoint.md): Reference for the HostEndpoint resource in Calico Open Source that represents a host network interface for policy enforcement. - [IP pool](https://docs.tigera.io/calico/latest/reference/resources/ippool.md): Reference for the IPPool resource in Calico Open Source that defines CIDRs available for pod IP address allocation. - [IP reservation](https://docs.tigera.io/calico/latest/reference/resources/ipreservation.md): Reference for the IPReservation resource in Calico Open Source that excludes specific addresses or ranges from automatic allocation. - [IPAM configuration](https://docs.tigera.io/calico/latest/reference/resources/ipamconfig.md): Reference for the IP address management configuration resource in Calico Open Source that sets cluster-wide options such as strict affinity. - [Kubernetes controllers configuration](https://docs.tigera.io/calico/latest/reference/resources/kubecontrollersconfig.md): Reference for the KubeControllersConfiguration resource in Calico Open Source that controls behavior of the kube-controllers component. - [Network policy](https://docs.tigera.io/calico/latest/reference/resources/networkpolicy.md): Reference for the NetworkPolicy resource in Calico Open Source, a namespaced policy that selects pods within a single namespace. - [Network set](https://docs.tigera.io/calico/latest/reference/resources/networkset.md): Reference for the NetworkSet resource in Calico Open Source that defines a namespaced set of CIDRs referenced by network policy. - [Node](https://docs.tigera.io/calico/latest/reference/resources/node.md): Reference for the Node resource in Calico Open Source that represents a host running the calico/node agent. - [Profile](https://docs.tigera.io/calico/latest/reference/resources/profile.md): Reference for the Profile resource in Calico Open Source that groups labels and rules applied to endpoints. - [Staged global network policy](https://docs.tigera.io/calico/latest/reference/resources/stagedglobalnetworkpolicy.md): Reference for the StagedGlobalNetworkPolicy resource in Calico Open Source that previews cluster-scoped policy without enforcing it. - [Staged Kubernetes network policy](https://docs.tigera.io/calico/latest/reference/resources/stagedkubernetesnetworkpolicy.md): Reference for the StagedKubernetesNetworkPolicy resource in Calico Open Source that previews Kubernetes network policy without enforcing it. - [Staged network policy](https://docs.tigera.io/calico/latest/reference/resources/stagednetworkpolicy.md): Reference for the StagedNetworkPolicy resource in Calico Open Source that previews namespaced policy without enforcing it. - [Tier](https://docs.tigera.io/calico/latest/reference/resources/tier.md): Reference for the Tier resource in Calico Open Source that groups policies into ordered evaluation buckets. - [Workload endpoint](https://docs.tigera.io/calico/latest/reference/resources/workloadendpoint.md): Reference for the WorkloadEndpoint resource in Calico Open Source that represents a pod or VM interface for policy and IPAM. - [Configuring etcd RBAC](https://docs.tigera.io/calico/latest/reference/etcd-rbac.md): Reference content for protecting the etcdv3 datastore used by Calico Open Source through role-based access control and TLS authentication. - [Setting up etcd certificates for RBAC](https://docs.tigera.io/calico/latest/reference/etcd-rbac/overview.md): Reference overview of role-based access control for the etcdv3 datastore used by Calico Open Source covering users, roles, and permission scopes. - [Generating certificates](https://docs.tigera.io/calico/latest/reference/etcd-rbac/certificate-generation.md): Reference for generating Certificate Authority and client certificates that authenticate Calico Open Source components against the etcdv3 datastore. - [Creating users and roles](https://docs.tigera.io/calico/latest/reference/etcd-rbac/users-and-roles.md): Reference for defining etcdv3 users and roles that grant scoped access to Calico Open Source components. - [Segmenting etcd on Kubernetes (basic)](https://docs.tigera.io/calico/latest/reference/etcd-rbac/kubernetes.md): Reference for restricting user access to Kubernetes and Calico Open Source resources using role-based access control. - [Segmenting etcd on Kubernetes (advanced)](https://docs.tigera.io/calico/latest/reference/etcd-rbac/kubernetes-advanced.md): Advanced reference for restricting user access to Calico Open Source components and calicoctl through Kubernetes role-based access control. - [Calico key and path prefixes](https://docs.tigera.io/calico/latest/reference/etcd-rbac/calico-etcdv3-paths.md): Reference listing the etcdv3 key prefixes used by each Calico Open Source component for role-based access control configuration. - [Configuring calico/node](https://docs.tigera.io/calico/latest/reference/configure-calico-node.md): Reference for configuring the calico/node container in Calico Open Source through environment variables that control Felix, BIRD, and confd. - [Configure resource requests and limits](https://docs.tigera.io/calico/latest/reference/configure-resources.md): Reference for setting Kubernetes resource requests and limits on Calico Open Source components managed by the Tigera Operator. - [Felix](https://docs.tigera.io/calico/latest/reference/felix.md): Reference content for Felix in Calico Open Source, the per-node daemon that programs routes and policy rules into the Linux data plane. - [Configuring Felix](https://docs.tigera.io/calico/latest/reference/felix/configuration.md): Reference for Felix configuration parameters in Calico Open Source covering environment variables, FelixConfiguration fields, and per-node overrides. - [Monitoring Felix with Prometheus](https://docs.tigera.io/calico/latest/reference/felix/prometheus.md): Prometheus metrics reference for Felix in Calico Open Source covering counters and gauges exposed for data plane health and policy evaluation. - [Typha](https://docs.tigera.io/calico/latest/reference/typha.md): Reference content for Typha in Calico Open Source, the fan-out daemon that scales Felix connections to the Kubernetes API datastore. - [Typha overview](https://docs.tigera.io/calico/latest/reference/typha/overview.md): Reference overview of the Typha daemon in Calico Open Source explaining how it reduces datastore load and scales Felix to large clusters. - [Configuring Typha](https://docs.tigera.io/calico/latest/reference/typha/configuration.md): Reference for Typha configuration parameters in Calico Open Source covering environment variables and config file options for scaling the Kubernetes datastore. - [Monitoring Typha with Prometheus](https://docs.tigera.io/calico/latest/reference/typha/prometheus.md): Prometheus metrics reference for Typha in Calico Open Source covering connection counts, cache health, and fan-out metrics. - [Configure the Calico CNI plugins](https://docs.tigera.io/calico/latest/reference/configure-cni-plugins.md): Reference for configuring the Calico Open Source CNI plugin and IPAM plugin through CNI network configuration files. - [kube-controllers](https://docs.tigera.io/calico/latest/reference/kube-controllers.md): Reference content for the kube-controllers component in Calico Open Source that watches Kubernetes API events and reconciles cluster state. - [Configuring the Calico Kubernetes controllers](https://docs.tigera.io/calico/latest/reference/kube-controllers/configuration.md): Reference for kube-controllers configuration in Calico Open Source covering environment variables and KubeControllersConfiguration options. - [Monitoring kube-controllers with Prometheus](https://docs.tigera.io/calico/latest/reference/kube-controllers/prometheus.md): Prometheus metrics reference for the kube-controllers component in Calico Open Source covering reconcile latency and queue depth. - [Configuration on public clouds](https://docs.tigera.io/calico/latest/reference/public-cloud.md): Public cloud reference for Calico Open Source covering platform-specific networking notes for AWS, Azure, GCE, and IBM Cloud deployments. - [Amazon Web Services](https://docs.tigera.io/calico/latest/reference/public-cloud/aws.md): Reference for running Calico Open Source on Amazon Web Services covering supported networking modes, source/destination check requirements, and AWS-specific notes. - [Azure](https://docs.tigera.io/calico/latest/reference/public-cloud/azure.md): Reference for running Calico Open Source on Microsoft Azure covering supported networking modes, user-defined routes, and Azure platform notes. - [Google Compute Engine](https://docs.tigera.io/calico/latest/reference/public-cloud/gce.md): Reference for running Calico Open Source on Google Compute Engine covering supported networking modes and platform-specific routing requirements. - [IBM Cloud](https://docs.tigera.io/calico/latest/reference/public-cloud/ibm.md): Reference for running Calico Open Source on IBM Cloud covering supported networking modes and platform integration notes. - [Host endpoints](https://docs.tigera.io/calico/latest/reference/host-endpoints.md): Reference content for protecting host endpoints with Calico Open Source network policy including failsafe ports, applyOnForward, pre-DNAT, and connectivity behavior. - [Host endpoints](https://docs.tigera.io/calico/latest/reference/host-endpoints/overview.md): Reference overview of host endpoint protection in Calico Open Source covering the model for securing host network interfaces with policy. - [Creating policy for basic connectivity](https://docs.tigera.io/calico/latest/reference/host-endpoints/connectivity.md): Reference for the Calico Open Source failsafe policy that protects host endpoints from being cut off when host network policy is misconfigured. - [Creating host endpoint objects](https://docs.tigera.io/calico/latest/reference/host-endpoints/objects.md): Reference for the HostEndpoint object in Calico Open Source describing how to represent a host network interface so policy can select it. - [Selector-based policies](https://docs.tigera.io/calico/latest/reference/host-endpoints/selector.md): Reference for ordered host endpoint policies in Calico Open Source that match interfaces using label selectors. - [Failsafe rules](https://docs.tigera.io/calico/latest/reference/host-endpoints/failsafe.md): Reference for the Calico Open Source failsafe inbound and outbound port lists that prevent host network policy from cutting off control-plane connectivity. - [Pre-DNAT policy](https://docs.tigera.io/calico/latest/reference/host-endpoints/pre-dnat.md): Reference for pre-DNAT host endpoint policy in Calico Open Source that applies rules to ingress traffic before destination NAT rewrites the address. - [Apply on forwarded traffic](https://docs.tigera.io/calico/latest/reference/host-endpoints/forwarded.md): Reference for the applyOnForward field on Calico Open Source host endpoint policy that determines how rules apply to forwarded traffic versus local processes. - [Summary of host endpoint policies](https://docs.tigera.io/calico/latest/reference/host-endpoints/summary.md): Reference summary describing how the different Calico Open Source host endpoint policy types interact and affect packet flows. - [Connection tracking](https://docs.tigera.io/calico/latest/reference/host-endpoints/conntrack.md): Reference covering Linux conntrack workarounds for Calico Open Source host endpoint policy when stateful tracking interferes with expected packet flow. - [Architecture](https://docs.tigera.io/calico/latest/reference/architecture.md): Reference content for Calico Open Source architecture covering components, network design, and data path between workloads. - [Component architecture](https://docs.tigera.io/calico/latest/reference/architecture/overview.md): Architectural overview reference of the Calico Open Source components including Felix, BIRD, confd, Typha, and the kube-controllers. - ['The Calico data path: IP routing and iptables'](https://docs.tigera.io/calico/latest/reference/architecture/data-path.md): Reference covering the Calico Open Source data path explaining how packets flow between workloads and to external destinations across networking modes. - [Network design](https://docs.tigera.io/calico/latest/reference/architecture/design.md): Network design reference for Calico Open Source covering layer-2 and layer-3 interconnect fabric options for the underlay network. - [Calico over Ethernet fabrics](https://docs.tigera.io/calico/latest/reference/architecture/design/l2-interconnect-fabric.md): Reference for using Calico Open Source over a layer-2 Ethernet interconnect fabric covering BGP peering and broadcast domain considerations. - [Calico over IP fabrics](https://docs.tigera.io/calico/latest/reference/architecture/design/l3-interconnect-fabric.md): Reference for using Calico Open Source over a layer-3 IP interconnect fabric covering BGP topology choices and route propagation. - [VPP data plane](https://docs.tigera.io/calico/latest/reference/vpp.md): Reference content for the Calico Open Source VPP data plane including configuration settings, host network setup, and architecture details. - [Primary interface configuration](https://docs.tigera.io/calico/latest/reference/vpp/uplink-configuration.md): Reference for primary interface configuration parameters in the Calico Open Source VPP data plane. - [VPP data plane implementation details](https://docs.tigera.io/calico/latest/reference/vpp/technical-details.md): Technical reference for the Calico Open Source VPP data plane integration covering packet processing, kernel offload, and graph nodes. - [Host network configuration](https://docs.tigera.io/calico/latest/reference/vpp/host-network.md): Reference covering the host network configuration applied by the Calico Open Source VPP data plane during initialization. - [Component versions](https://docs.tigera.io/calico/latest/reference/component-versions.md): Component version reference listing the upstream container images and binaries shipped with each Calico Open Source release. - [Frequently asked questions](https://docs.tigera.io/calico/latest/reference/faq.md): Frequently asked questions about Calico Open Source covering networking modes, IP address management, BGP, policy behavior, and platform support. - [Getting involved](https://docs.tigera.io/calico/latest/reference/involved.md): Reference for getting involved with the Calico Open Source upstream project including source repositories, mailing lists, Slack, and contribution channels. ## Support and feedback - [Support and feedback](https://docs.tigera.io/calico/latest/get-help/support.md): Community support and feedback channels for Calico Open Source, including the Calico Users Slack, GitHub project, contribution guide, and docs repository. ## Optional - [Calico Open Source 3.32 release notes](https://docs.tigera.io/calico/latest/release-notes.md): Release notes for the current Calico Open Source release — new features, enhancements, technology previews, deprecations, bug fixes, and known issues.