Tigera Launches Calico Unified Platform 3.23: The Definitive VMware Migration Solution with One Network and One Security Model for Every VM and Container on Kubernetes
Organizations undertaking VMware migration initiatives require an alternative to NSX for network automation and simplicity of operations for virtual machines and containers in a single unified platform
This is a Press Release edited by StorageNewsletter.com on July 21, 2026 at 2:00 pmTigera, Inc., the inventor and maintainer of Calico Open Source and the company behind Calico and Lynx, launched the Calico Unified Platform: the industry’s first and only platform to deliver networking and network security for both virtual machines and containers on a single Kubernetes-native control plane.
With it, enterprises migrating from VMware can move their VM estates onto Kubernetes and keep every networking and security outcome they had under NSX, without operating two parallel stacks and without redesigning their network.
The timing is not incidental. Broadcom’s post-acquisition licensing changes have driven significant price increases pushing a wave of organizations to move virtual machines off vSphere and onto Kubernetes using KubeVirt and OpenShift Virtualization. But migrating the VM is the easy part. The hard part is the network: VMs depend on static IPs, VLANs, distributed firewalls, and route advertisement that NSX provided, and none of that functionality is Kubernetes native. Teams have been forced to bolt a legacy network-virtualization stack onto their new Kubernetes platform, recreating the very complexity and lock-in they are migrating off of VMware to escape.
The Calico Unified Platform ends that complexity. It is one network, one policy model, and one observability stack spanning VMs and containers alike, so a virtual machine migrated to Kubernetes keeps its IP address, lives on the same network as the containers beside it, and inherits the same microsegmentation, routing, load balancing, quality of service, and flow visibility. What NSX did for the data center, Calico now does natively inside Kubernetes for both workload types, simultaneously.
“Organizations are urgently exploring modernization projects to migrate off of VMware estates” said Alain Mayer, VP, product, Tigera, Inc. “With the Calico Unified Platform, a VM and a container are first-class citizens of the same network, governed by the same policy, seen through the same lens. This is the best solution on the market for automating and simplifying networking and network security across VMs and containers, solving one of the most difficult components in the migration process.”
Every NSX outcome, delivered Kubernetes-natively
The Calico Unified Platform is built around a simple principle for architects considering a VMware migration project: preserve outcomes, not objects. Every capability NSX administrators depend on has a direct, Kubernetes-native counterpart in Calico:
- Segmentation and isolation – NSX segments, overlay networks, and VLAN-backed segments map to Calico networks, overlay networks, and an L2 bridge that extends existing VLANs into Kubernetes so VMs keep Layer 2 continuity during migration
- Distributed firewalling – the NSX distributed firewall maps to Calico network policy, policy tiers, and staged policy, enforcing east-west microsegmentation on workload identity rather than IP address, with safe rollout before enforcement
- North-south control and routing – Tier-0 and Tier-1 gateway behavior maps to Calico BGP peering, Multi-VRF tenant routing, and egress gateways, advertising VM and load balancer IPs upstream with predictable source identity
- Application delivery – the NSX Advanced Load Balancer (AVI) maps to the Calico Load Balancer and Ingress Gateway, providing stable VIPs, Maglev-based L4 distribution, and L7 routing, all Kubernetes-native
- Workload mobility – vMotion maps to KubeVirt live migration with Calico, preserving IP addresses and policy with minimal packet loss and fast route convergence as VMs move between nodes
- Quality of service and observability – NSX QoS and Traceflow map to Calico QoS controls and a full observability stack: Service Graph, flow logs, DNS logs, L7 logs, and packet capture, with complete Kubernetes workload context
- One model across any workload, any environment
Because the same policy, routing, egress, QoS, and observability patterns apply to VMs and containers alike, platform teams operate a single model instead of two. That model extends consistently across clusters, distributions, and on-premises, cloud, and edge deployments, eliminating platform-specific configuration and the vendor lock-in that defined the previous era. Organizations can migrate first and modernize later: preserve existing IPs, VLANs, and firewall rules on day one, then consolidate to Kubernetes-native patterns on their own timeline, without fragmenting operations along the way.
Availability
The Calico Unified Platform is available across Calico Enterprise, Calico Cloud, and Calico Open Source. Tigera offers a structured VMware-to-Kubernetes migration path: assess the VMware topology, map VLAN and overlay segments, migrate VMs with networking and security preserved, then modernize.












