---
title: "calicoctl user reference"
description: "Reference overview of the calicoctl command-line tool for managing Calico Open Source network policy, BGP, IP address management, and node operations."
product: "Calico Open Source"
version: "3.33 (latest)"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico/latest/reference/calicoctl/overview"
---

# calicoctl user reference

The command line tool, `calicoctl`, makes it easy to manage Calico network and security policy, as well as other Calico configurations.

The full list of resources that can be managed, including a description of each, is described in the [Resource definitions](https://docs.tigera.io/calico/latest/reference/resources/overview.md) section.

> **SECONDARY:** This section provides full reference information for `calicoctl`. To learn how to install and configure `calicoctl`, refer to [Installing calicoctl](https://docs.tigera.io/calico/latest/operations/calicoctl/install.md).

The calicoctl command line interface provides a number of resource management commands to allow you to create, modify, delete, and view the different Calico resources. This section is a command line reference for `calicoctl`, organized based on the command hierarchy.

## Top level help

Run `calicoctl --help` to display the following help menu for the top level calicoctl commands.

```text
The calicoctl command line tool is used to manage Calico network and security
policy, to view and manage endpoint configuration, and to manage a Calico
node instance.

Usage:
  calicoctl [command]

Available Commands:
  apply       Apply a resource by file, directory or stdin
  cluster     Access cluster information
  completion  Generate the autocompletion script for the specified shell
  create      Create a resource by file, directory or stdin
  datastore   Calico datastore management
  delete      Delete a resource by file, directory, stdin, or type and name
  get         Get a resource by file, directory, stdin, or type and name
  help        Help about any command
  ipam        IP address management
  label       Add or update labels of resources
  node        Calico node management
  patch       Patch a pre-existing resource in place
  replace     Replace a resource by file, directory or stdin
  validate    Validate a resource by file, directory or stdin without applying it
  version     Display the version of this binary

Flags:
      --allow-version-mismatch   Allow client and cluster versions mismatch
      --context string           The name of the kubeconfig context to use
  -h, --help                     help for calicoctl
  -l, --log-level string         Set the log level (panic, fatal, error, warn, info, debug) (default "panic")

Use "calicoctl [command] --help" for more information about a command.
```

> **SECONDARY:** In a multi cluster environment if you have a [kubeconfig](https://kubernetes.io/docs/concepts/configuration/organize-cluster-access-kubeconfig/) file with multiple cluster contexts it is possible to directly change the context using calicoctl `--context` argument.

> **SECONDARY:** The versions for Calico and calicoctl should be the same and calls to calicoctl will fail if the versions do not match. If needed, this can be overridden by using the `--allow-version-mismatch` argument.

## Top level command line options

Details on the `calicoctl` commands are described in the documents linked below organized by top level command.

- [calicoctl create](https://docs.tigera.io/calico/latest/reference/calicoctl/create.md)
- [calicoctl replace](https://docs.tigera.io/calico/latest/reference/calicoctl/replace.md)
- [calicoctl apply](https://docs.tigera.io/calico/latest/reference/calicoctl/apply.md)
- [calicoctl patch](https://docs.tigera.io/calico/latest/reference/calicoctl/patch.md)
- [calicoctl delete](https://docs.tigera.io/calico/latest/reference/calicoctl/delete.md)
- [calicoctl get](https://docs.tigera.io/calico/latest/reference/calicoctl/get.md)
- [calicoctl label](https://docs.tigera.io/calico/latest/reference/calicoctl/label.md)
- [calicoctl validate](https://docs.tigera.io/calico/latest/reference/calicoctl/validate.md)
- [calicoctl ipam](https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/overview.md)
- [calicoctl node](https://docs.tigera.io/calico/latest/reference/calicoctl/node.md)
- [calicoctl datastore](https://docs.tigera.io/calico/latest/reference/calicoctl/datastore.md)
- [calicoctl cluster](https://docs.tigera.io/calico/latest/reference/calicoctl/cluster.md)
- [calicoctl version](https://docs.tigera.io/calico/latest/reference/calicoctl/version.md)

## Modifying low-level component configurations

To update low-level Felix or BGP settings (`FelixConfiguration` and `BGPConfiguration` resource types):

1. Get the appropriate resource and store the yaml output in a file using `calicoctl get <resource type> <resource name> -o yaml --export > config.yaml`.
2. Modify the saved resource file.
3. Update the resource using `apply` or `replace` command: `calicoctl replace -f config.yaml`.

See [Configuring Felix](https://docs.tigera.io/calico/latest/reference/felix/configuration.md) for more details.

## Supported resource definition aliases

The following table lists supported aliases for Calico resources when using `calicoctl`. Note that all aliases are **case-insensitive**.

| Resource definition                  | Supported calicoctl aliases                                                   |
| ------------------------------------ | ----------------------------------------------------------------------------- |
| BGP configuration                    | `bgpconfig`, `bgpconfigurations`, `bgpconfigs`                                |
| BGP peer                             | `bgppeer`, `bgppeers`, `bgpp`, `bgpps`, `bp`, `bps`                           |
| Felix configuration                  | `felixconfiguration`, `felixconfig`, `felixconfigurations`, `felixconfigs`    |
| Global network policy                | `globalnetworkpolicy`, `globalnetworkpolicies`, `gnp`, `gnps`                 |
| Global network set                   | `globalnetworkset`, `globalnetworksets`                                       |
| Host endpoint                        | `hostendpoint`, `hostendpoints`, `hep`, `heps`                                |
| IP pool                              | `ippool`, `ippools`, `ipp`, `ipps`, `pool`, `pools`                           |
| IP reservation                       | `ipreservation`, `ipreservations`, `reservation`, `reservations`              |
| Kubernetes controllers configuration | `kubecontrollersconfiguration`, `kubecontrollersconfig`                       |
| Network policy                       | `networkpolicy`, `networkpolicies`, `policy`, `np`, `policies`, `pol`, `pols` |
| Node                                 | `node`, `nodes`, `no`, `nos`                                                  |
| Profiles                             | `profile`, `profiles`, `pro`, `pros`                                          |
| Workload endpoint                    | `workloadendpoint`, `workloadendpoints`, `wep`, `weps`                        |
