Calico Cloud: SaaS networking and network security for Kubernetes
Zero-trust policies have secured Kubernetes traffic and now support faster incident resolution
What is our primary use case?
Our primary use case for Calico Cloud is securing and monitoring Kubernetes workloads across multiple clusters, where we use it to enforce network policies, control pod-to-pod communication, gain visibility into network traffic, and detect security issues. It also helps with micro-segmentation, compliance, and troubleshooting connectivity problems in our containerized applications, which maintains a zero-trust networking model.
We use Calico Cloud to implement micro-segmentation across our Kubernetes clusters by defining fine-grained network policies for different namespaces and workloads. Instead of allowing unrestricted pod-to-pod communication, we enforce least privilege access so that only approved services can communicate with each other. This has helped us isolate applications, reduce the attack surface, and meet our internal security requirements. From a connectivity perspective, Calico Cloud has been particularly useful for troubleshooting network policy issues. When an application cannot reach another service, we use flow logs and policy visualization to quickly determine whether traffic is being allowed or denied, identify which policy is responsible, and resolve the issue without spending hours manually tracing Kubernetes networking.
What is most valuable?
The best features for us with Calico Cloud are a combination of Kubernetes network policy management with deep traffic visibility. Other features include real-time flow visualization for troubleshooting connectivity issues, policy recommendations and previews before enhancements, and rich flow logs that help quickly identify blocked or unexpected traffic.
Real-time flow visualization has been one of the most valuable features for our team when dealing with real-time scenarios. During application deployments or network policy changes, we use it to observe live communication between Kubernetes workloads and quickly identify whether traffic is being allowed or blocked. For example, when a newly deployed microservice was unable to communicate with the backend API, the flow visualization immediately showed where the communication was being denied. This allowed us to identify the specific network policy and restore connectivity within minutes instead of spending significant time analyzing logs or packet captures.
Calico Cloud has had a positive impact on our organization by improving both our Kubernetes security posture and operational efficiency. Overall, it has helped our platform and DevOps team deploy changes with greater confidence, respond to incidents more quickly, and maintain a more secure and reliable Kubernetes environment.
What needs improvement?
Calico Cloud is a very good product with well-defined usage. I would appreciate seeing more improvement on real-time analysis capabilities.
For how long have I used the solution?
I have been working as a Senior Systems Engineer for more than five years. I have been using Calico Cloud in my project for more than a year.
What do I think about the stability of the solution?
Calico Cloud is stable.
What do I think about the scalability of the solution?
Calico Cloud has scaled well with our Kubernetes environment and has many capabilities that make it easier to apply consistent security policies across multiple clusters.
How are customer service and support?
Customer support is very good, and they have responded to us whenever we have encountered issues with the product.
How was the initial setup?
I have experience with pricing, setup cost, and licensing.
What about the implementation team?
The company has purchased Calico Cloud from the marketplace, though the implementation was not handled by me personally.
What was our ROI?
We have seen a positive return on investment. While the licensing cost is higher than using basic open-source networking alone, the operational benefits have outweighed the investment. It has reduced the time spent troubleshooting network connectivity issues, improved visibility into Kubernetes traffic, and helped us enforce consistent security policies across clusters. The biggest value has come from faster incident resolution.
What's my experience with pricing, setup cost, and licensing?
The setup cost has been positive overall.
What other advice do I have?
Calico Cloud has been very useful in our project, and I am very positive about it. I would rate Calico Cloud an eight overall because it has more requirements to be fulfilled.
Regarding Calico Cloud's AI capabilities, I have not used them much. When it comes to governance and security, Calico Cloud is useful for strengthening governance and security, particularly when identifying potential policy misconfigurations and unusual network recommendations. Our team validates network policies, detects expected traffic flows, and reduces the likelihood of human error during configuration changes. This serves as a helpful decision support tool rather than replacing manual governance and security controls.
The platform has been accurate and reliable in our experience. Calico Cloud has AI-assisted features, and we treat its recommendations as guidance rather than automatic decisions. We validate suggested changes through our normal review and testing process before applying them to production. This approach has made the insights dependable and has helped reduce troubleshooting time while improving the accuracy of network policy management.
I would suggest using Calico Cloud for the exact use case that I am using it for, as that is the best advice I can give. The benefits I have mentioned are real benefits. I assign a rating of eight to Calico Cloud based on my experience with the product.
Centralized service mesh visibility has strengthened our security and simplified audit readiness
What is our primary use case?
My main use case for Calico Cloud is network and security management in EKS.
I set up a service mesh on EKS while using Calico Cloud, which provides all the observability and graphical interface needed to manage communication between the different services and to the outside.
It greatly facilitates management and allows in the future to connect it with other Kubernetes clusters that are not EKS without having to use proprietary tools from each cloud.
What is most valuable?
I consider the best features offered by Calico Cloud to be portability and its graphical interface.
Since Calico Cloud is a portable tool that can work with different types of Kubernetes clusters, it greatly facilitates deployment in different projects, having people trained on that tool and not having to train them on different tools. In addition, since it has a simple graphical interface, it is very easy for new technicians to learn.
Calico Cloud has positively impacted my organization by improving the security of deployed applications while having greater control and visibility over communication between the different microservices.
I have improved in audits after implementing Calico Cloud, reaching the optimal state in less time.
What needs improvement?
I think Calico Cloud could be improved by being a bit cheaper. The pricing, implementation cost, and licensing of Calico Cloud could be reduced.
For how long have I used the solution?
I have been using Calico Cloud for between one and two years.
What do I think about the stability of the solution?
I consider Calico Cloud to be stable.
What do I think about the scalability of the solution?
I rate the scalability of Calico Cloud as adequate.
How are customer service and support?
Calico Cloud's customer support is adequate, although I have not had to use it.
Which solution did I use previously and why did I switch?
I used several other proxies for service mesh topics before Calico Cloud, and I decided to switch because of the ease and portability between different solutions.
What was our ROI?
I have seen a return on investment from using Calico Cloud, particularly with time savings in achieving audits and passing audits in an optimal way.
Which other solutions did I evaluate?
Before choosing Calico Cloud, I evaluated other options including the specific AWS solutions.
What other advice do I have?
I would advise other professionals who are considering Calico Cloud to evaluate it because it is a very powerful solution. I give this review a rating of 8.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Security posture has become visible and container risks are managed proactively
What is our primary use case?
I have been using Calico Cloud between 2022 to 2024. I worked on a project focused on security and vulnerability scanning within our containers. Calico Cloud was implemented because the company wanted to understand their security architecture within our orchestration environment, as we were using Kubernetes and running on AWS. We were also using AWS Inspector, but Calico Cloud was injected within the system to help with security, particularly within the containers.
My main use case for Calico Cloud is security. Calico Cloud has developed a cloud-native solution for the security of containers. You are able to have insights into your cloud security posture management (CSPM), gaining an understanding of your security posture within your containers and how to design your security system. Within Kubernetes, you have your container security interface (CSI), which Calico Cloud is able to build something native for and is able to secure your containers, ensuring they are well secured within their ecosystem.
When you log in to the console, everything was mostly click-based. You see different options on the console where you can check your posture or scan your containers for vulnerabilities. You can see whether vulnerabilities are high or low, and you are able to apply the best security posture to protect your containers so that no one is open and vulnerable to attack. Everything was connected, and you could see the different policies in place.
What is most valuable?
Calico Cloud is cloud-native. The moment you log in to the console, you have different applications to check for vulnerabilities. You have knowledge of different vulnerabilities from standards such as NIST that you could check against. By setting the policies, you are ensuring that no one has access to your app and that it is well protected. You create policies to prevent someone from logging into a particular container, and since it has its native container security interface, this helps protect against unauthorized access or damage in the cloud.
The best features Calico Cloud offers include the CSI itself and the ease of integration with your CSI. The interface has also improved; when I started using it, I noticed the landing page from the left-hand side of your console was user-friendly. Through Calico Academy, you can learn quickly how to use Calico.
The UI/UX is fantastic, and I believe companies continue improving it.
What needs improvement?
Regarding improvements for Calico Cloud, there is a need to build agentic security systems. I believe Calico Cloud is progressing towards this, and I believe they can enhance their teaching methods to facilitate adoption.
Documentation needs continuous improvement. It is good and easy to read, but it can get better. Having a searchable summary feature, such as a chatbot, could help users quickly resolve issues without having to read extensive documentation.
At the moment, I do not believe there are more improvements needed, but as mentioned earlier, there should be a focus on better documentation, possibly by embedding chatbot features that could respond to user prompts effectively.
For how long have I used the solution?
I have been using Calico Cloud between 2022 to 2024.
What do I think about the stability of the solution?
Calico Cloud is stable.
What do I think about the scalability of the solution?
Calico Cloud is scalable. I do not believe there is a question about that; it has over the years demonstrated its scalability and the adoption of products across the industry.
How are customer service and support?
Customer support is good. I mainly relied on documentation, but I believe the relationship between vendors and our management team was effective, and I did not hear complaints about support.
Which solution did I use previously and why did I switch?
I joined the company and started using Calico Cloud from the beginning, so I cannot comment on previous solutions. The decision for solutions often depends on an organization's needs and industry requirements, leading to a cloud-native approach without dependency on a single vendor.
How was the initial setup?
The integration process of Calico Cloud with existing systems has its challenges. When integrating, especially with AWS, navigating through various providers is necessary. With the rise of generative AI, embedding guidance into the integration process could help users troubleshoot effectively.
What about the implementation team?
In terms of governance and security, my understanding is that it is about protecting users by ensuring their information is not public and thus not exploited. I believe Calico Cloud follows the necessary security and governance standards, which assures users that deploying their agentic systems is secure.
What was our ROI?
The return on investment from using Calico Cloud is evident, as the company has effectively been using it for years. Calico Cloud not only secures our network infrastructure but also assures that we are not incurring costs due to breaches, which is a significant factor in the ROI.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Calico Cloud was determined by management who evaluated the costs related to potential breaches. They decided that the cost of implementing Calico Cloud outweighed the risk of not having it based on our industry needs.
Which other solutions did I evaluate?
I believe they evaluated other options, and it was determined that Calico Cloud is the leader in providing security within the cloud native ecosystem.
What other advice do I have?
The impact of Calico Cloud is that we were able to achieve a more secure understanding of our security posture. We could access our containers, knowing full well that all policies set were followed through. We could see visually how everything was interconnected. That visual representation Calico Cloud has embedded into their design system is wonderful, and it has impacted our business positively.
Having access to vulnerabilities is essential. For example, when the Log4j issue occurred in December 2021, I joined the company in 2022. The company had a lot of internal and external facing applications that needed to be scanned by Calico Cloud. We ensured each application's vulnerabilities were addressed by reaching out to developers to upgrade Java versions. By scanning, we identified vulnerabilities, and we communicated with developers to fix urgent issues, demonstrating how Calico Cloud provided critical insights.
Calico Cloud helps me meet compliance requirements. You set your cloud security posture, and when you scan and see that it is failing, it indicates areas where Calico Cloud delivers security effectively.
My advice to others looking into using Calico Cloud is this: if it fits your needs, go for it without hesitation. Security is a priority in today's world, especially as industries scale globally.
I found the interview to be smooth and thorough, allowing exploration of my knowledge regarding Calico Cloud. Although it took longer than the stated time, the process was engaging. I would be glad if you could summarize my review in a short poem or haiku. My overall review rating for Calico Cloud is 8 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Traffic insights have strengthened zero-trust security but observability reporting still needs work
What is our primary use case?
My main use case for Calico Cloud is traffic management, which is the primary feature that I primarily use in my organization. We appreciate their recommendation system for security, and the service graph they provide gives us accessibility to our service graph, which is what we use it for.
A specific example of how I use Calico Cloud for traffic management and the service graph is that they provide us visibility, which is one of the things I appreciate about Calico Cloud. A similar product is Jaeger when you are using Istio, so they essentially do the same thing. You look at the service graph and you will see how, for example, we have several microservices. For me to communicate with another, normally you would not know how the full communication works. However, with Calico Cloud, you are able to see that this service communicates with these services and how they communicate. You can see the latency that is occurring at a particular junction. You can basically see all your services that make up your application that were developed for different vendors in our company, and you can see how each and every one of them communicates for this product. All the services that make up that microservice are what we use the service graph for. Their micro-segmentation helps to provide functionality similar to AWS Security Hub or a security advisor. You are able to be told that for a particular product and particular communication, these are the communications that occur on a day-to-day basis, and therefore, they recommend that you put in this kind of policy. If you agree with them, then you go and enforce the policy, and they provide a place to test it so that it does not affect your real-life traffic, allowing you to confirm that the feature really helps you.
Regarding my main use case and how Calico Cloud fits into my workflow, they have observability. I am able to combine all the different logs, DNS logs, so that I can see what actually happens from flow logs, DNS logs, and the other logs. That way I can make sense of what is going on in my cluster. For observability, they are doing good work. They provide insights that I have used with Istio, which is another product that also takes care of observability, not necessarily network policies in the way Calico Cloud supports. It is a good job overall.
What is most valuable?
In my opinion, the best features Calico Cloud offers are micro-segmentation, particularly the zero-trust micro-segmentation, which stands out the most for me. Being able for them to look at my traffic and recommend the best network policy for me means I do not have to think about it. That is what I value about Calico Cloud.
Micro-segmentation has helped my team greatly. Some use cases we never thought of with Calico Cloud help increase the security of our application. Micro-segmentation has assisted us with observability as well.
Calico Cloud has positively impacted my organization, especially on the security front, as it helped us anticipate security threats. It aids in making sense of what is happening in the cluster in terms of the logs, the DNS logs, and the other various logs that occur in the system.
What needs improvement?
For the moment, I think they could possibly add AI for human reporting for observability. Rather than just providing data, adding a speech feature on top of it, such as a summarization of what has actually happened, would be useful for troubleshooting faster. They should still allow users to drill down to see the actual issue, but that quick summary can indeed come in handy.
For how long have I used the solution?
I have been using Calico Cloud for over a year and a few months.
What do I think about the stability of the solution?
Calico Cloud is stable.
What do I think about the scalability of the solution?
For the traffic we handle, I consider it quite scalable. We have not had issues with scalability.
How are customer service and support?
I think we have not had time to reach out to customer support as Calico Cloud is quite a usable product.
Which solution did I use previously and why did I switch?
With Calico Cloud, it was our first product; I never used it previously. However, I have tried Cilium and Istio on my private cluster. That is why I can make this informed decision. Calico Cloud are the first ones that work with network policies, so that is the default when trying to work with Kubernetes clusters.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that the pricing is moderate. The setup cost was basic because there are many helpful resources available that I could reference. The licensing was payable with the best pricing based on what they are offering.
What was our ROI?
I have seen a return on investment with time saved and fewer employees needed. We are able to reduce the number of times needed for debugging through the service graph and the recommendations for the micro-segmentation of their security tool, helping us identify necessary network policies. We also observe our traffic with the recommendations provided by Calico Cloud, which results in good savings in return on investment, which includes time saved and fewer troubleshooting and debugging times.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that the pricing is moderate. The setup cost was basic because there are many helpful resources available that I could reference. The licensing was payable with the best pricing based on what they are offering.
Which other solutions did I evaluate?
Before choosing Calico Cloud, I evaluated Cilium, which is their competitor.
What other advice do I have?
My advice to others looking into using Calico Cloud is that it is worth the fee. I give Calico Cloud a rating of seven because there are places for improvement, as I recommended. For what they do, they do it well, especially with zero-trust micro-segmentation and their security plus observability tools. They may not have all the features that their competitor Cilium has, and they are doing a portion of what Cilium does and a portion of what Istio does. For what they do, they do it well, and that is why I give them a seven.
Effortless Kubernetes Networking with Top-Notch Security and Performance
Effortless Network Policy Management with Calico
A powerful Cloud Native Security Solution
Robust Kubernetes Security with Room for Improvement
Evaluating Calico Cloud: Secure, Scalable, and Kubernetes-Ready
> Solution: Calico Cloud allows me to define fine-grained, identity-based network policies that go beyond IP addresses — using labels, namespaces, and service accounts to tightly control traffic between workloads.