The News
Tigera has launched Calico for VMs on Kubernetes, describing it as the industry’s first eBPF-powered platform to deliver unified networking and network security for both virtual machines and containers on a single Kubernetes-native control plane. The announcement targets enterprises migrating away from VMware who need an NSX alternative that preserves existing network identities, IP addresses, VLANs, and firewall rules without requiring a full network redesign on day one. The platform maps every major NSX capability, including distributed firewalling, BGP-based routing, application delivery, and workload observability, to a direct Kubernetes-native counterpart in Calico, which already secures more than one million clusters daily.
Analyst Take
The VMware migration wave has been building since Broadcom’s 2023 acquisition triggered widespread pricing shock across enterprise IT. Most of the public narrative has focused on hypervisor alternatives and licensing cost comparisons. Tigera is betting that the real friction isn’t compute or storage. The network is the hard part. VM network identities are embedded in firewall rules, DNS configurations, business processes, and compliance evidence chains. Moving a VM without moving its identity means breaking all of those downstream dependencies at once, which is exactly why so many migrations stall after the initial planning phase.
Why the NSX Replacement Narrative Is the Right Frame
Calico for VMs on Kubernetes is positioned less as a Kubernetes networking product and more as an NSX successor. That framing matters for how ITDMs should evaluate it. The question isn’t “which CNI should we use?” The question is “what replaces NSX’s distributed firewall, policy tiers, egress gateway, load balancer, and observability stack, all at once, without requiring us to redesign the network before we’ve finished the migration?” Tigera’s answer is a single control plane that lets teams preserve L2 continuity on day one and migrate to Kubernetes-native L3 patterns on their own timeline. For platform teams running hundreds of VMs alongside containerized workloads, that staged approach is the difference between a migration that’s politically feasible and one that isn’t.
The Converged Platform Bet Is Well-Timed
The second strategic thread in this announcement is the AI workload argument. Tigera’s press materials note that organizations are increasingly self-hosting open large language models to control token costs and keep models physically close to proprietary data. That pulls high-value AI workloads back on-premises and onto the same converged platform that already runs everything else. This is consistent with what ECI Research is observing in its own survey data: in ECI Research’s 2026 Application Development survey, 55.8% of respondents reported that 0–20% of their production workloads run in on-premises data centers, while 30.9% reported 21–40% on-premises. That distribution means most enterprises are already operating in a hybrid posture, not fully cloud-native, and a converged VM-plus-container platform that runs anywhere is directly aligned with where those workloads actually live.
For developers, the eBPF angle deserves attention. eBPF-based enforcement means policy is applied in the kernel data path, not in a sidecar or userspace proxy, which directly reduces per-connection overhead and eliminates the latency penalty that makes kernel-bypass networking attractive for AI inference workloads. The combination of KubeVirt live migration with preserved IP addresses and fast route convergence is also non-trivial: it means VMs can move between nodes without breaking active connections, which is the Kubernetes equivalent of vMotion and one of the features NSX administrators have historically cited as irreplaceable.
The Security Story Deserves Its Own Line
Calico’s policy model enforces microsegmentation on workload identity rather than IP address. That distinction matters operationally. IP-based rules break silently when workloads move; identity-based rules follow the workload. For organizations operating under regulatory pressure, this is a meaningful architectural property. ECI Research’s 2026 Application Development survey found that 47.4% of respondents named software supply chain security as a top investment priority for the next 12 months, and 71.5% cited industry-specific compliance as a regulatory pressure influencing release engineering. A platform that enforces consistent east-west security policy across VMs and containers on a single control plane could address both of those pressures simultaneously, without requiring separate tooling for each workload type.
Looking Ahead
The VMware migration market will remain active through at least 2027–2028 as enterprises work through multi-year transition programs. Tigera’s window to establish Calico as the default NSX replacement is open now, while those programs are still in early execution. The competitive pressure will come from two directions: Kubernetes platform vendors who will integrate their own networking layers more deeply, and from network incumbents who may extend their own policy planes to cover KubeVirt workloads. Tigera’s advantage is that it already operates at scale inside those platforms rather than competing with them.
The longer-term signal in this announcement is the convergence of the AI infrastructure narrative with the VM migration narrative. As self-hosted LLM deployments grow, the demand for a single platform that can run inference workloads, data-adjacent VMs, and containerized services with consistent network policy and observability will intensify. Tigera is positioning Calico as that platform. Whether it can hold that position against hyperscaler-native alternatives and the emerging class of AI-specific networking products will determine whether this launch is remembered as a migration tool or the foundation of something considerably larger.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
