Calico Cloud provides network security, observability, and traffic controls for Kubernetes clusters in cloud, on-premises, and edge environments. Its network views map topology, workload connections, dependencies, and traffic to help investigate issues. Security capabilities include IDS/IPS, WAF, DDoS protection, forensic tools, and policy-based quarantine for infected workloads. Teams can use policy recommendations, tiered enforcement, or manage policies as code in CI/CD pipelines. Networking options include eBPF, nftables, iptables, Windows data planes, Envoy Gateway, Egress Gateways, and cluster mesh. Compliance reports cover PCI, SOC 2, HIPAA, and GDPR, with scheduled or on-demand generation and exportable data. Tigera operates Calico Cloud as a managed SaaS service. Listed supported Kubernetes environments include self-provisioned clusters, Amazon EKS, Azure AKS, Google GKE, and Rancher Kubernetes Engine 2. Clusters need a CNI before connection; Calico Open Source is required when the service provides both networking and network policy. The Free plan costs 0.00 USD per free and is limited to one user, one cluster, view-only policy editing, and 24-hour log retention. A free trial is also available without a credit card.
Who it is for
It suits teams that need Kubernetes network visibility, security controls, or compliance reporting across supported cloud and self-provisioned environments. The Free plan is limited to one user and one cluster.
What is good
- Network views show topology, connections, dependencies, and traffic.
- Includes IDS/IPS, WAF, and DDoS protection.
- Reports cover PCI, SOC 2, HIPAA, and GDPR.
- Supports Linux and Windows nodes on x86-64 and ARM64.
- Free trial is available without a credit card.
What to know first
- Free plan allows one user and one cluster.
- Free plan retains logs for 24 hours.
- Free plan policy editing is view-only.
- A CNI must be installed before cluster connection.
Freedom251 review
Calico Cloud: the full review
Calico Cloud combines Kubernetes traffic visibility, policy controls, threat protection, and compliance reporting in a managed service. Check cluster prerequisites and the Free plan’s user, cluster, and log limits before choosing it.
Overview
Calico Cloud is a managed Kubernetes networking and security service for teams operating clusters across cloud, on-premises, or edge environments. It is strongest for operators who want traffic insight and policy controls in the same service; its narrow Free plan and cluster prerequisites make it a less natural fit for a quick, standalone security deployment.
Tigera runs Calico Cloud as SaaS, but connecting a cluster is not entirely plug-and-play: a CNI must already be installed. If Calico Cloud is to provide both networking and network policy, Calico Open Source is required. That makes the product more compelling for teams prepared to manage Kubernetes networking than for those looking for general-purpose protection across unrelated workloads.
Key features
Traffic visibility and policy
Topology, workload connections, dependencies, and traffic data give operators context for troubleshooting how services communicate. Policy recommendations, tiered enforcement, and policy as code in CI/CD pipelines help teams move from visibility to controlled changes. The breadth is useful, but teams should distinguish the view-only Policy Editor on Free from the fuller policy capabilities associated with the product.
Threat protection and networking
Calico Cloud describes integrated IDS/IPS, WAF, and DDoS protection, alongside forensics and network-policy quarantine for infected workloads. Response actions include denying HTTP traffic, blocking traffic to suspicious IPs, and creating a security-event exception. Networking capabilities span eBPF, nftables, iptables, Windows data planes, Envoy Gateway, Egress Gateways, and cluster mesh. This is a substantial Kubernetes-focused toolkit, not a general endpoint-security suite.
Compliance and deployment
Compliance reporting covers PCI, SOC 2, HIPAA, and GDPR, with scheduled or on-demand reports and exportable data. The agent-based service supports Linux and Windows hosts, x86-64 and ARM64 nodes, and hybrid clusters with a Linux control plane and Windows nodes on EKS or AKS. The web console supports the latest two versions of Chrome and Safari.
Pricing
Calico Cloud uses a freemium model, with a free trial that does not require a credit card.
| Plan | Price | What it includes | Best for |
|---|---|---|---|
| Free | 0.00 USD per free | One user, one cluster, Calico 3.30 or greater, 24-hour log retention, and Policy Editor view only. | A solo operator evaluating a single cluster with short-lived log needs. |
| Pay-As-You-Go | Custom pricing | Unlimited users and clusters, 7-day log retention, packet capture, Egress Gateway, Threat Defense, DNS and L7, alerts, and anomaly detection. | Teams needing shared access, multiple clusters, or the additional operational and security features. |
Free is a constrained evaluation or small-scope option: one user, one cluster, a 24-hour log window, and view-only policy editing limit its usefulness for ongoing team operations. Pay-As-You-Go removes the user and cluster caps and extends retention, but its custom pricing means buyers should establish the cost before planning a broader rollout.
Platforms
Tigera tests and supports self-provisioned Kubernetes, Amazon EKS, Azure AKS, Google GKE, and Rancher Kubernetes Engine 2. Other distributions may connect with Calico Open Source installed, with Support available for guidance; they do not have the same stated tested-and-supported status. The service is listed for Linux, self-hosted, web, and Windows, and supports AWS, Microsoft Azure, and Google Cloud.
Who it's for
Calico Cloud suits Kubernetes platform and security teams that need network visibility, policy enforcement, threat protection, and compliance reporting across supported cloud or hybrid environments. It is a weaker match for buyers who need broad endpoint coverage, need to connect a cluster without first installing a CNI, or cannot work within the Free plan's single-user and single-cluster limits.
Pros and cons
Pros
- Combines traffic observability, policy controls, and threat protection, giving Kubernetes teams a connected view of communications and enforcement.
- Compliance reporting spans PCI, SOC 2, HIPAA, and GDPR, with scheduled or on-demand output and exportable data.
- Supports Linux and Windows nodes, ARM64 and x86-64, and several major managed Kubernetes services.
- The free trial requires no credit card, and the Free plan offers a no-cost single-cluster starting point.
Cons
- Connecting requires a preinstalled CNI; Calico Open Source is mandatory when Calico Cloud supplies both networking and policy.
- Free is limited to one user and one cluster, with only 24 hours of logs and view-only Policy Editor access.
- Pay-As-You-Go pricing is custom, so teams cannot compare its cost from a fixed published rate.
- Distributions outside Tigera's tested list may connect, but do not carry the same tested-and-supported status.
Alternatives
For a broader directory of options, see Cloud Workload Protection Platforms.
- Choose Amazon GuardDuty if you want a paid AWS-oriented service with API and web platforms; charges are pay-as-you-go and vary by analyzed data and AWS Region, rather than a fixed price.
- Choose Falco if a free, open-source option for Linux and self-hosted environments is the priority.
- Consider Qualys TotalCloud for its free license with limited API calls for control evaluation, or a Cloud Platform subscription with custom pricing.
- Bitdefender Total Security is another option, with a first-year individual plan at 59.99 USD per year for five devices and one account.
- Consider Sysdig Secure if host-based licensing is a better fit; its licensing is based on hosts, or compute instances for CSPM.
- FortiCNAPP is another paid option, with Standard plans on one- and three-year terms and entitlement per vCPU.
- Palo Alto Networks Cortex Cloud API Security is another paid option.
- Sweet Security is another paid option for Linux, self-hosted, and web platforms.
Verdict
Choose Calico Cloud if your team runs Kubernetes and wants managed traffic visibility, policy controls, threat protection, and compliance reporting together. Its key advantage is that operational networking insight and security actions share the same Kubernetes-focused service. Look elsewhere if the CNI prerequisite, the Free plan's tight caps, or custom pricing for broader use does not fit your deployment or budget.
Calico Cloud plans and pricing
All plansCompared on cloud workload protection platforms
- Free plan
- Yes
- Container protection
- Yes
- Kubernetes protection
- Yes
- Deployment model
- agent-based
- Response actions
- Deny HTTP traffic; block traffic to suspicious IPs; create security-event exceptions; dismiss security events
- Supported host OS
- Linux; Windows
- Cloud platforms
- AWS; Microsoft Azure; Google Cloud




