San Jose, Calif. — July 23 2026 — Tigera, the company behind the Calico open‑source project, announced the general availability of Calico for VMs on Kubernetes, an eBPF‑powered platform that delivers networking and network‑security functions for both virtual machines and containers from a single Kubernetes‑native control plane. The move targets enterprises that are migrating away from VMware’s NSX stack but want to retain the same level of automation, policy enforcement, and observability without redesigning their networks.
What the announcement is
Calico for VMs on Kubernetes bundles the familiar networking, micro‑segmentation, load‑balancing and observability capabilities that NSX provided, but re‑engineers them to run natively inside Kubernetes clusters. The solution supports lift‑and‑shift migrations of existing VMs, preserving IP addresses, VLAN assignments and firewall rules on day one, while also offering a path to modernize toward pure Kubernetes‑native networking (L3, BGP, egress gateways) at the customer’s pace.
How the technology works
At its core, the platform leverages eBPF to enforce policies at the kernel level, providing the same granularity traditionally achieved with NSX’s distributed firewall. A built‑in L2 bridge extends legacy VLAN segments into the Kubernetes fabric, allowing VMs to stay on their original Layer 2 networks during migration. Once inside the cluster, Calico’s BGP‑based routing, multi‑VRF tenant routing, and egress gateways replace the need for separate Tier‑0/1 gateways. Policy tiers, staged rollout, and DNS‑aware controls give security teams the same “plan‑monitor‑enforce” workflow they used with NSX, now applied to both pods and VMs.
Why it matters for enterprises
Enterprises are already grappling with three intertwined challenges: moving compute and storage to Kubernetes, keeping network continuity, and avoiding vendor lock‑in. According to a 2025 Gartner forecast, 70 % of large enterprises will have migrated at least 30 % of their workloads to Kubernetes. Yet, network identity—hard‑coded IPs, VLANs, and firewall rules—remains a blocker. Calico for VMs on Kubernetes promises to eliminate that blocker by letting organizations migrate VMs “as‑is” while still gaining the benefits of Kubernetes‑native networking.
For marketing and ad‑tech teams, the convergence of VMs and containers on a single platform simplifies data pipelines that feed AI‑driven campaign optimization. Self‑hosted large language models (LLMs) that sit close to proprietary customer data can now run on the same converged infrastructure, reducing latency and token‑costs while maintaining strict compliance with privacy regulations such as GDPR and CCPA.
Competitive landscape
NSX remains the de‑facto standard for on‑premises VM networking, but its reliance on a separate control plane and proprietary APIs makes it less agile in a Kubernetes‑first world. Open‑source alternatives like Cilium and Cisco ACI have introduced eBPF‑based networking for containers, yet none currently provide a unified VM‑plus‑container stack. Calico’s differentiator is its long‑standing open‑source pedigree (over 1 million daily clusters) combined with a commercial support model that mirrors the enterprise‑grade features of NSX—without the need for a separate hypervisor‑specific overlay.
Implications for marketing and ad‑tech teams
- Unified data flow – With VMs and containers sharing the same network policy and observability stack, ad‑tech platforms can ingest logs, flow data, and telemetry from both environments through a single Service Graph.
- AI‑ready infrastructure – The platform’s eBPF‑based packet inspection enables low‑overhead monitoring of AI agents that process user‑level signals in real time, a growing requirement for programmatic advertising.
- Regulatory compliance – Policy‑as‑code and staged rollout allow security teams to enforce privacy‑by‑design controls across all workloads before they go live, simplifying audit trails for regulators.
Market Landscape
The broader market is shifting toward “converged” networking solutions that blur the line between traditional VM data‑centers and cloud‑native container platforms. IDC projects that global spending on network security for hybrid clouds will exceed $45 billion by 2027, driven largely by the need to protect workloads that span on‑prem, public cloud, and edge locations. Vendors that can offer a single control plane for both VMs and containers are positioned to capture a larger share of that spend.
Tigera’s announcement arrives as several hyperscalers—Google, Amazon, and Microsoft—are expanding their managed Kubernetes services with built‑in networking plugins. However, those services typically lock customers into the provider’s ecosystem. Calico for VMs on Kubernetes, by contrast, is platform‑agnostic, supporting OpenShift, VKS, SUSE, Mirantis, Canonical, and other distributions, giving enterprises the flexibility to avoid vendor lock‑in while still meeting internal security and performance standards.
Top Insights
- Seamless lift‑and‑shift – Calico lets enterprises migrate VMs to Kubernetes without renumbering IPs or re‑architecting VLANs, cutting migration timelines by up to 40 % (internal Tigera testing).
- eBPF security parity – The eBPF‑driven firewall matches NSX’s micro‑segmentation granularity while delivering lower latency and higher scalability.
- Unified observability – A single Service Graph visualizes traffic across VMs and containers, reducing the need for multiple monitoring stacks.
- Vendor‑agnostic – Works across all major Kubernetes distributions, preventing lock‑in to a single cloud or on‑prem provider.
- AI‑ready – Supports self‑hosted LLM workloads on the same network fabric, lowering token costs and improving data residency regulatory compliance.
Get in touch with our Adtech experts
