Tigera Launches eBPF-powered Calico for VMs on Kubernetes: VM Migration That Doesn't Require Rebuilding the Network
Canada NewsWire
SAN JOSE, Calif., July 23, 2026
Organizations who have decided to migrate their VMs from VMware require an alternative to NSX for network automation and simplicity of operations for virtual machines and containers running on Kubernetes
SAN JOSE, Calif., July 23, 2026 /CNW/ -- Tigera, Inc., the inventor and maintainer of Calico Open Source and the company behind Calico and Lynx, today launched Calico for VMs on Kubernetes: the industry's first and only eBPF-powered platform to deliver networking and network security for both virtual machines and containers on a single Kubernetes-native control plane. With it, enterprises that have already decided to migrate from VMware can move their VM estates onto Kubernetes and keep every networking and security outcome they had under NSX, without re-designing their network, making the migration process seamless.
Enterprises that have decided to migrate their VMs from VMware to Kubernetes platforms such as OpenShift, VKS, SUSE, Mirantis, Canonical, etc., are discovering that migrating compute and storage are the easy parts. The hard part is the network: The VM's network identity is hardcoded into surrounding infrastructure, business rules, and processes. Any changes to the network identity will break all these things. Teams that are used to managing VM networking with NSX are discovering that the native Kubernetes network capabilities are complex, and lack the functionality that VM admins rely on for efficient operations.
VMware users who are migrating to Kubernetes have four broad objectives:
- Migrate a VM as-is (lift & shift) to minimize disruption to operations and meet tight timelines for migration
- Modernize their network architecture to eliminate hard-coded dependencies on their legacy networking stack (VLANs, Firewalls, DNS, DHCP) to reduce costs and simplify operations. In phase 2, teams would like to transition from an L2 network design to an L3 network design, on their own timeline.
- Ensure that the new architecture doesn't lock them into a new Kubernetes platform and that they keep their platform options open for the future as they plan for AI workloads.
- Build a converged platform that can house both containers and VMs to prepare for AI workloads and agents. To control token costs and keep models physically close to the proprietary data that lives in their own data centers, organizations are increasingly self-hosting open large language models. That pulls high-value, data-adjacent AI workloads back on-prem and onto the same converged platform that already runs everything else.
One operating model across any workload, any environment
Because the same policy, routing, egress, QoS, and observability patterns apply to VMs and containers alike, platform teams operate a single operating model instead of two. That model extends consistently across clusters, Kubernetes distributions, and on-premises, cloud, and edge deployments, eliminating platform-specific configuration and the vendor lock-in that defined the previous era. Organizations can migrate first and modernize later: preserve existing IPs, VLANs, and firewall rules on day one, then consolidate to Kubernetes-native patterns on their own timeline, without fragmenting operations along the way.
Calico for VMs on Kubernetes ends complexity and delivers the network automation and simplicity of operations for VMs running in Kubernetes that VM administrators are used to with NSX. It is one network, one security policy model, and one observability stack spanning VMs and containers alike, so a virtual machine migrated to Kubernetes keeps its IP address, lives on the same network as the containers beside it, and inherits the same microsegmentation, routing, load balancing, quality of service, and flow visibility. What NSX did for the data center, Calico now does natively inside Kubernetes for both workload types, simultaneously.
"The market is converging on one self-hosted platform for containers and VMs, and the economics and AI trends driving it are only accelerating," said Pervez Sikora, President at Tigera, Inc. "Calico enables the convergence of VMs and containers under one management plane, turning that converged platform from an aspiration into an operational reality."
A complete stack for VM networking on Kubernetes
Calico for VMs on Kubernetes is designed to help teams connect, secure and observe VM workloads through a unified set of networking, security and observability capabilities. Every capability and outcome delivered by NSX has a direct Kubernetes-native counterpart in Calico:
- Connect – Calico Networks provide connectivity to VM workloads and to the networks and services around them. L2 Bridge capabilities can extend existing network VLANs (Segments) into Kubernetes for workloads that require Layer 2 or network continuity during and after migration. BGP-based routing, egress gateway, load balancing and ingress gateway functions support delivering applications and services to consumers.
- Secure – Calico network policy, policy tiers, staged policy and DNS policy provide Kubernetes-native controls for access enforcement and microsegmentation. Policies can be planned, monitored and validated before enforcement, helping teams maintain security posture as workloads move and apply consistent controls across VMs and containers.
- Observe – Calico Service Graph, flow logs, DNS logs, L7 visibility and packet capture provide context for troubleshooting and security operations. Teams can investigate VM-to-VM, VM-to-pod, pod-to-pod and cross-cluster flows with Kubernetes-aware workload context using eBPF-enabled deep packet inspection.
Every NSX outcome, delivered Kubernetes-natively
The Calico Unified Platform is built around a simple principle for architects who have been tasked with a VM migration project: preserve outcomes, not objects. Every capability NSX administrators depend on has a direct, Kubernetes-native counterpart in Calico:
- Connectivity and networking — L2 bridge that extends existing VLANs into Kubernetes so VMs keep Layer 2 continuity during migration.
- Segmentation and isolation — NSX segments, overlay networks, and VLAN-backed segments map to Calico networks, overlay networks
- Distributed firewalling — the NSX distributed firewall maps to Calico network policy, policy tiers, and staged policy, enforcing east-west microsegmentation on workload identity rather than IP address, with safe rollout before enforcement.
- North-south control and routing — Tier-0 and Tier-1 gateway behavior maps to Calico BGP peering, Multi-VRF tenant routing, and egress gateways, advertising VM and load balancer IPs upstream with predictable source identity.
- Application delivery — the NSX Advanced Load Balancer (AVI) maps to the Calico Load Balancer and Ingress Gateway, providing stable VIPs, Maglev-based L4 distribution, and L7 routing, all Kubernetes-native.
- Workload mobility — vMotion maps to KubeVirt live migration with Calico, preserving IP addresses and policy with minimal packet loss and fast route convergence as VMs move between nodes.
- Quality of service and observability — NSX QoS and Traceflow map to Calico QoS controls and a full observability stack: Service Graph, flow logs, DNS logs, L7 logs, and packet capture, with complete Kubernetes workload context.
- Multi-cluster Ops — Cluster-mesh to help manage multiple clusters across regions.
Proven at scale
Calico secures more than 1 million clusters daily and is recognized as a Leader and Outperformer by GigaOM for container networking. Leading enterprises including NVIDIA, Royal Bank of Canada, Bloomberg, Chipotle, GoDaddy, and Upwork rely on the Calico platform. That same platform is now extended to carry their virtual machines.
Availability
Calico for VMs on Kubernetes is now generally available.
To learn more about migrating VMs without losing NSX-grade network automation and security, and to see the platform in action, schedule a demo or view a self-paced demo.
About Tigera
Tigera, Inc., the inventor and maintainer of Calico Open Source and the company behind Calico and Lynx, secures and governs VMs, Kubernetes workloads and AI agents across the enterprise by providing deep visibility and enforcement control via eBPF. The company's offerings secure Kubernetes workloads and AI agents across 1M+ clusters in multicloud and hybrid environments. Leading enterprises including NVIDIA, Royal Bank of Canada, Bloomberg, Chipotle, GoDaddy, and Upwork trust Tigera for their Kubernetes security, networking and AI agent security needs.
To learn more about Tigera's offerings, visit tigera.io.
View original content to download multimedia:https://www.prnewswire.com/news-releases/tigera-launches-ebpf-powered-calico-for-vms-on-kubernetes-vm-migration-that-doesnt-require-rebuilding-the-network-302832737.html
SOURCE Tigera, Inc.
