📊 Key Data
  • 58% of organizations plan to migrate VMs to Kubernetes (2024 Portworx report).
  • Calico for VMs preserves IP addresses and Layer 2 network continuity during migration.
  • eBPF-powered platform enables kernel-level networking control without legacy stacks.
🎯 Expert Consensus

Experts would likely conclude that Tigera's solution significantly reduces the technical barriers to VM-to-Kubernetes migration, accelerating enterprise modernization by unifying networking for both workload types under a single Kubernetes-native framework.

about 23 hours ago
Tigera's Calico Breaks the Networking Logjam for VM-to-Kubernetes Migration

Tigera's Calico Breaks the Networking Logjam for VM-to-Kubernetes Migration

SAN JOSE, CA – July 23, 2026 – For years, the enterprise IT world has been on a steady march toward the cloud-native promised land, with Kubernetes as its orchestrating engine. Yet, a significant portion of critical business applications remain housed in traditional virtual machines (VMs), creating a digital divide within the data center. The great migration of these workloads has been stymied not by a lack of will, but by a formidable and often underestimated technical barrier: the network. Today, Tigera, the company behind the widely adopted Calico Open Source project, has launched a solution that aims to dismantle that barrier, potentially accelerating a new wave of enterprise modernization.

The new platform, Calico for VMs on Kubernetes, is engineered to solve the persistent networking headache that has plagued organizations attempting to move their VM estates from established environments like VMware. By allowing VMs to run alongside containers on a single Kubernetes platform without requiring a costly and complex network overhaul, Tigera is addressing a core structural problem that has held back digital transformation initiatives across the globe.

The Migration's Hidden Hurdle: The Network

For any organization that has embarked on a large-scale migration from a legacy virtualization platform, the story is familiar. Migrating the compute and storage components of a VM is often the easy part. The project grinds to a halt when it confronts the network. A VM’s network identity—its IP address, its VLAN, its relationship to firewalls and load balancers—is deeply woven into the fabric of business logic and operational processes. Changing it is akin to changing a person’s identity and expecting all their legal documents to remain valid; it breaks everything.

This challenge is amplified by the architectural mismatch between traditional VM networking, which often relies on Layer 2 constructs like VLANs, and the flat, Layer 3-centric world of Kubernetes. Teams accustomed to the sophisticated network automation of tools like VMware’s NSX find native Kubernetes networking capabilities to be a stark and often inadequate replacement. This friction has imposed a heavy “networking tax” on modernization efforts, leading to stalled projects and operational silos where VM and container worlds are managed by different teams with different tools.

The market’s desire to bridge this gap is clear. Technologies like KubeVirt, which enable VMs to run on Kubernetes, have seen growing interest, with a 2024 Portworx report indicating that 58% of organizations plan to migrate VMs to Kubernetes. However, networking remains a common point of failure, with challenges around live migration, IP address preservation, and policy enforcement. Until now, the choice has often been between a painful network redesign or maintaining costly, parallel infrastructures.

A Blueprint for Seamless Transition

Tigera’s strategy with Calico for VMs is built on a simple, powerful principle: preserve outcomes, not objects. Instead of trying to replicate the specific components of a legacy system like NSX, the platform provides Kubernetes-native counterparts that deliver the same essential results. This allows enterprises to migrate first and modernize later. On day one, a VM can be lifted from VMware and shifted to a Kubernetes cluster, keeping its IP address and Layer 2 network continuity via Calico’s L2 bridge capabilities. All surrounding firewall rules and routing tables remain untouched.

Once settled in its new home, the VM lives on the same network as its containerized neighbors, governed by the same unified control plane. What NSX did for the virtualized data center, Calico now aims to do natively inside Kubernetes for both workloads simultaneously. This unified model extends across policy, routing, quality of service, and observability. The NSX distributed firewall maps to Calico’s robust network policy engine; NSX load balancing maps to Calico’s Kubernetes-native load balancer; and vMotion’s workload mobility is mirrored by KubeVirt’s live migration, where Calico ensures the VM’s IP address and policies follow it seamlessly across the cluster.

This approach effectively eliminates the operational schism between old and new. A single platform team can operate a single model for networking and security, regardless of whether the workload is a decade-old monolithic application in a VM or a newly developed microservice in a container. This consistency extends across different Kubernetes distributions and hybrid environments, breaking the vendor lock-in that defined the previous era of IT infrastructure.

Under the Hood: The Power of eBPF

The technological linchpin of this unified platform is eBPF (extended Berkeley Packet Filter), a revolutionary capability within the Linux kernel that allows for safe and efficient custom programs to run directly in the kernel’s networking path. While the technology has been developing for years, its application is now hitting a critical inflection point, enabling a new generation of infrastructure software.

By leveraging eBPF, Calico can bypass legacy networking stacks like iptables, resulting in significant performance gains and lower latency. More importantly, it provides an unprecedented level of visibility and control. The platform can observe every network flow, DNS query, and application-layer transaction for both VMs and containers without requiring cumbersome sidecar proxies or agents. This deep, kernel-level observability provides a single, consistent source of truth for troubleshooting and security forensics across the entire converged environment.

Tigera is not alone in harnessing eBPF; the technology also powers other prominent cloud-native networking solutions like Cilium, signaling a broad industry shift toward this more efficient and powerful paradigm. By extending its proven eBPF-powered data plane to manage VMs, Tigera is making a strategic bet that the future of enterprise networking lies in this kernel-level programmability, moving intelligence out of proprietary hardware and into open, flexible software.

Building the Foundation for an AI-Ready Enterprise

The convergence of VMs and containers is not merely an exercise in operational tidiness; it is a strategic imperative driven by the voracious demands of artificial intelligence. As organizations increasingly self-host large language models to control costs and keep proprietary data secure, high-value AI workloads are moving back on-premise. These data-adjacent workloads require a robust, high-performance platform that can handle both traditional and modern application components.

A converged platform running both VMs and containers is the natural home for this new class of application. It allows enterprises to place AI models and agents physically close to the data they process, much of which still resides in legacy systems running on VMs. Calico for VMs provides the unified networking and security fabric essential for this architecture, ensuring low-latency communication and consistent policy enforcement between AI agents in containers and data sources in VMs.

“The market is converging on one self-hosted platform for containers and VMs, and the economics and AI trends driving it are only accelerating,” said Pervez Sikora, President at Tigera, Inc. “Calico enables the convergence of VMs and containers under one management plane, turning that converged platform from an aspiration into an operational reality.”

By providing a clear, low-friction path for migrating and managing legacy workloads within a modern, Kubernetes-native framework, this new class of technology does more than just solve a technical problem. It fundamentally reframes the relationship between legacy and future infrastructure. This shift from segregated systems to a unified operational plane marks a significant step in dismantling the technical debt that has long hindered enterprise evolution.

Topics & Related

Event:
Product Launch
Theme:
Cloud Migration
Sector:
Cloud & Infrastructure
Enterprise IT

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 44327