IBM Cloud
Calico is installed and configured automatically in your IBM Cloud Kubernetes Service. Default policies are created to protect your Kubernetes cluster, with the option to create your own policies to protect specific services.
IP-in-IP encapsulation
IP-in-IP encapsulation is automatically configured to only encapsulate packets traveling across subnets, and uses NAT for outgoing connections from your containers.
Enabling workload-to-WAN traffic
This is also handled automatically in the IBM Cloud Kubernetes Service. No additional configuration of Calico is necessary.