diff --git a/classes/cluster/k8s-aio-calico/kubernetes/compute.yml b/classes/cluster/k8s-aio-calico/kubernetes/compute.yml
index 9da4945..338f0e1 100644
--- a/classes/cluster/k8s-aio-calico/kubernetes/compute.yml
+++ b/classes/cluster/k8s-aio-calico/kubernetes/compute.yml
@@ -19,14 +19,13 @@
       kubelet:
         address: ${_param:single_address}
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          etcd:
+            ssl:
+              enabled: true
     common:
       addons:
         virtlet:
diff --git a/classes/cluster/k8s-aio-calico/kubernetes/control.yml b/classes/cluster/k8s-aio-calico/kubernetes/control.yml
index a26ab0a..b14ecf9 100644
--- a/classes/cluster/k8s-aio-calico/kubernetes/control.yml
+++ b/classes/cluster/k8s-aio-calico/kubernetes/control.yml
@@ -51,9 +51,10 @@
       kubelet:
         address: ${_param:single_address}
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/k8s-aio-calico/kubernetes/init.yml b/classes/cluster/k8s-aio-calico/kubernetes/init.yml
index 42fc07e..38acf28 100644
--- a/classes/cluster/k8s-aio-calico/kubernetes/init.yml
+++ b/classes/cluster/k8s-aio-calico/kubernetes/init.yml
@@ -18,7 +18,7 @@
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_calico_policy_image: calico/kube-policy-controller:v0.5.4
diff --git a/classes/cluster/k8s-aio-contrail/kubernetes/compute.yml b/classes/cluster/k8s-aio-contrail/kubernetes/compute.yml
index 70d5ee6..ab8467f 100644
--- a/classes/cluster/k8s-aio-contrail/kubernetes/compute.yml
+++ b/classes/cluster/k8s-aio-contrail/kubernetes/compute.yml
@@ -39,14 +39,6 @@
         engine: opencontrail
         opencontrail:
           address: ${_param:opencontrail_control_address}
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
     common:
       hyperkube:
         image: ${_param:kubernetes_hyperkube_image}
diff --git a/classes/cluster/k8s-aio-contrail/kubernetes/control.yml b/classes/cluster/k8s-aio-contrail/kubernetes/control.yml
index 2cbdba3..8f89385 100644
--- a/classes/cluster/k8s-aio-contrail/kubernetes/control.yml
+++ b/classes/cluster/k8s-aio-contrail/kubernetes/control.yml
@@ -17,10 +17,6 @@
         engine: docker_hybrid
       ssl:
         enabled: true
-      setup:
-        calico:
-          key: /calico/v1/ipam/v4/pool/${_param:calico_private_network}-${_param:calico_private_netmask}
-          value: '{"masquerade":true,"cidr":"${_param:calico_private_network}/${_param:calico_private_netmask}"}'
   kubernetes:
     common:
       addons:
@@ -40,10 +36,6 @@
       etcd:
         ssl:
           enabled: true
-      network:
-        etcd:
-          ssl:
-            enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/k8s-aio-contrail/kubernetes/init.yml b/classes/cluster/k8s-aio-contrail/kubernetes/init.yml
index 7a7e9c3..ccbd551 100644
--- a/classes/cluster/k8s-aio-contrail/kubernetes/init.yml
+++ b/classes/cluster/k8s-aio-contrail/kubernetes/init.yml
@@ -16,9 +16,6 @@
     etcd_initial_token: IN7KaRMSo3xkGxkjAAPtkRkAgqN4ZNRq
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
-    kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
-    kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
     kubernetes_netchecker_agent_image: quay.io/l23network/k8s-netchecker-agent:v1.0
     kubernetes_netchecker_server_image: quay.io/l23network/k8s-netchecker-server:v1.0
@@ -60,10 +57,6 @@
     cluster_node03_address: ${_param:kubernetes_control_node03_address}
     cluster_node03_port: 4001
 
-    # calico
-    calico_private_network: 192.168.0.0
-    calico_private_netmask: 16
-
   linux:
     network:
       host:
diff --git a/classes/cluster/k8s-compact/kubernetes/compute.yml b/classes/cluster/k8s-compact/kubernetes/compute.yml
index 198c172..876a87f 100644
--- a/classes/cluster/k8s-compact/kubernetes/compute.yml
+++ b/classes/cluster/k8s-compact/kubernetes/compute.yml
@@ -13,14 +13,13 @@
       kubelet:
         address: ${_param:single_address}
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          etcd:
+            ssl:
+              enabled: true
     common:
       addons:
         virtlet:
diff --git a/classes/cluster/k8s-compact/kubernetes/control.yml b/classes/cluster/k8s-compact/kubernetes/control.yml
index d64e5c3..5b7cf53 100644
--- a/classes/cluster/k8s-compact/kubernetes/control.yml
+++ b/classes/cluster/k8s-compact/kubernetes/control.yml
@@ -55,9 +55,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/k8s-compact/kubernetes/init.yml b/classes/cluster/k8s-compact/kubernetes/init.yml
index d0c3740..5c62919 100644
--- a/classes/cluster/k8s-compact/kubernetes/init.yml
+++ b/classes/cluster/k8s-compact/kubernetes/init.yml
@@ -27,7 +27,7 @@
     kubernetes_controller-manager_token: uXrdZ1YKF6qlYm3sHje2iEXMGAGDWOIU
     kubernetes_dns_token: 0S1I4iJeFjq5fopPwwCwTp3xFpEZfeUl
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_calico_policy_image: calico/kube-policy-controller:v0.5.4
diff --git a/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/compute.yml b/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/compute.yml
index 77b7cc9..0acf4ee 100644
--- a/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/compute.yml
+++ b/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/compute.yml
@@ -7,7 +7,7 @@
 - cluster.k8s-ha-calico-cloudprovider
 parameters:
   _param:
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
@@ -21,14 +21,13 @@
   kubernetes:
     pool:
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          etcd:
+            ssl:
+              enabled: true
     common:
       hyperkube:
         image: ${_param:kubernetes_hyperkube_image}
diff --git a/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml b/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml
index 306fb15..0e7a474 100644
--- a/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-calico-cloudprovider/kubernetes/control.yml
@@ -49,9 +49,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/k8s-ha-calico-syndic/kubernetes/compute.yml b/classes/cluster/k8s-ha-calico-syndic/kubernetes/compute.yml
index 2a6126f..59bfeb0 100644
--- a/classes/cluster/k8s-ha-calico-syndic/kubernetes/compute.yml
+++ b/classes/cluster/k8s-ha-calico-syndic/kubernetes/compute.yml
@@ -7,7 +7,7 @@
 - cluster.k8s-ha-calico-syndic
 parameters:
   _param:
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
@@ -19,14 +19,13 @@
   kubernetes:
     pool:
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          etcd:
+            ssl:
+              enabled: true
     common:
       hyperkube:
         image: ${_param:kubernetes_hyperkube_image}
diff --git a/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml b/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml
index a7dda44..9052688 100644
--- a/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-calico-syndic/kubernetes/control.yml
@@ -38,9 +38,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/k8s-ha-calico/kubernetes/compute.yml b/classes/cluster/k8s-ha-calico/kubernetes/compute.yml
index e18d628..fe3558f 100644
--- a/classes/cluster/k8s-ha-calico/kubernetes/compute.yml
+++ b/classes/cluster/k8s-ha-calico/kubernetes/compute.yml
@@ -20,14 +20,13 @@
         address: ${_param:single_address}
         fail_on_swap: ${_param:kubelet_fail_on_swap}
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          etcd:
+            ssl:
+              enabled: true
     common:
       addons:
         virtlet:
diff --git a/classes/cluster/k8s-ha-calico/kubernetes/control.yml b/classes/cluster/k8s-ha-calico/kubernetes/control.yml
index c57e955..2185d59 100644
--- a/classes/cluster/k8s-ha-calico/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-calico/kubernetes/control.yml
@@ -59,9 +59,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/k8s-ha-calico/kubernetes/init.yml b/classes/cluster/k8s-ha-calico/kubernetes/init.yml
index 1afffc1..67b29eb 100644
--- a/classes/cluster/k8s-ha-calico/kubernetes/init.yml
+++ b/classes/cluster/k8s-ha-calico/kubernetes/init.yml
@@ -21,7 +21,7 @@
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_calico_policy_image: calico/kube-policy-controller:v0.5.4
diff --git a/classes/cluster/k8s-ha-contrail/kubernetes/compute.yml b/classes/cluster/k8s-ha-contrail/kubernetes/compute.yml
index db900d2..57faff7 100644
--- a/classes/cluster/k8s-ha-contrail/kubernetes/compute.yml
+++ b/classes/cluster/k8s-ha-contrail/kubernetes/compute.yml
@@ -42,14 +42,6 @@
         config:
           api:
             host: ${_param:opencontrail_control_address}
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
         contrail_cni:
           image: ${_param:kubernetes_opencontrail_cni_image}
     common:
diff --git a/classes/cluster/k8s-ha-contrail/kubernetes/control.yml b/classes/cluster/k8s-ha-contrail/kubernetes/control.yml
index 012a0d0..098b933 100644
--- a/classes/cluster/k8s-ha-contrail/kubernetes/control.yml
+++ b/classes/cluster/k8s-ha-contrail/kubernetes/control.yml
@@ -18,10 +18,6 @@
         engine: docker_hybrid
       ssl:
         enabled: true
-      setup:
-        calico:
-          key: /calico/v1/ipam/v4/pool/${_param:calico_private_network}-${_param:calico_private_netmask}
-          value: '{"masquerade":true,"cidr":"${_param:calico_private_network}/${_param:calico_private_netmask}"}'
   kubernetes:
     common:
       addons:
@@ -58,10 +54,6 @@
       etcd:
         ssl:
           enabled: true
-      network:
-        etcd:
-          ssl:
-            enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/k8s-ha-contrail/kubernetes/init.yml b/classes/cluster/k8s-ha-contrail/kubernetes/init.yml
index 2a341ba..67e7296 100644
--- a/classes/cluster/k8s-ha-contrail/kubernetes/init.yml
+++ b/classes/cluster/k8s-ha-contrail/kubernetes/init.yml
@@ -22,9 +22,6 @@
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
-    kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
-    kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_opencontrail_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/contrail-integration/contrail-cni:v1.0.0
 
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
@@ -88,10 +85,6 @@
     cluster_node03_address: ${_param:etcd_control_node03_address}
     cluster_node03_port: 4001
 
-    # calico
-    calico_private_network: 192.168.0.0
-    calico_private_netmask: 16
-
   linux:
     network:
       host:
diff --git a/classes/cluster/sl-k8s-calico/kubernetes/compute.yml b/classes/cluster/sl-k8s-calico/kubernetes/compute.yml
index 7faf456..bc4272d 100644
--- a/classes/cluster/sl-k8s-calico/kubernetes/compute.yml
+++ b/classes/cluster/sl-k8s-calico/kubernetes/compute.yml
@@ -7,7 +7,7 @@
 - cluster.sl-k8s-calico
 parameters:
   _param:
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
@@ -19,14 +19,13 @@
   kubernetes:
     pool:
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          etcd:
+            ssl:
+              enabled: true
     common:
       hyperkube:
         image: ${_param:kubernetes_hyperkube_image}
diff --git a/classes/cluster/sl-k8s-calico/kubernetes/control.yml b/classes/cluster/sl-k8s-calico/kubernetes/control.yml
index 7afdd01..94481d8 100644
--- a/classes/cluster/sl-k8s-calico/kubernetes/control.yml
+++ b/classes/cluster/sl-k8s-calico/kubernetes/control.yml
@@ -39,9 +39,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/sl-k8s-contrail/kubernetes/compute.yml b/classes/cluster/sl-k8s-contrail/kubernetes/compute.yml
index 8a508c4..5fafd8e 100644
--- a/classes/cluster/sl-k8s-contrail/kubernetes/compute.yml
+++ b/classes/cluster/sl-k8s-contrail/kubernetes/compute.yml
@@ -35,14 +35,6 @@
         engine: opencontrail
         opencontrail:
           address: ${_param:opencontrail_control_address}
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
     common:
       hyperkube:
         image: ${_param:kubernetes_hyperkube_image}
diff --git a/classes/cluster/sl-k8s-contrail/kubernetes/control.yml b/classes/cluster/sl-k8s-contrail/kubernetes/control.yml
index 04d188a..ba70eae 100644
--- a/classes/cluster/sl-k8s-contrail/kubernetes/control.yml
+++ b/classes/cluster/sl-k8s-contrail/kubernetes/control.yml
@@ -16,10 +16,6 @@
         engine: docker_hybrid
       ssl:
         enabled: true
-      setup:
-        calico:
-          key: /calico/v1/ipam/v4/pool/${_param:calico_private_network}-${_param:calico_private_netmask}
-          value: '{"masquerade":true,"cidr":"${_param:calico_private_network}/${_param:calico_private_netmask}"}'
   kubernetes:
     common:
       addons:
@@ -39,10 +35,6 @@
       etcd:
         ssl:
           enabled: true
-      network:
-        etcd:
-          ssl:
-            enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/sl-k8s-contrail/kubernetes/init.yml b/classes/cluster/sl-k8s-contrail/kubernetes/init.yml
index 37b89f9..f6898b3 100644
--- a/classes/cluster/sl-k8s-contrail/kubernetes/init.yml
+++ b/classes/cluster/sl-k8s-contrail/kubernetes/init.yml
@@ -16,9 +16,6 @@
     etcd_initial_token: IN7KaRMSo3xkGxkjAAPtkRkAgqN4ZNRq
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
-    kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
-    kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
     kubernetes_netchecker_agent_image: quay.io/l23network/k8s-netchecker-agent:v1.0
     kubernetes_netchecker_server_image: quay.io/l23network/k8s-netchecker-server:v1.0
@@ -56,10 +53,6 @@
     cluster_node03_address: ${_param:kubernetes_control_node03_address}
     cluster_node03_port: 4001
 
-    # calico
-    calico_private_network: 192.168.0.0
-    calico_private_netmask: 16
-
   linux:
     network:
       host:
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/compute.yml b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/compute.yml
index 6ee687b..535bd05 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/compute.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/compute.yml
@@ -14,15 +14,14 @@
   kubernetes:
     pool:
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
-        mtu: ${_param:kubernetes_mtu}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          mtu: ${_param:kubernetes_mtu}
+          etcd:
+            ssl:
+              enabled: true
     common:
       hyperkube:
         image: ${_param:kubernetes_hyperkube_image}
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml
index 87ebedb..df19368 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/control.yml
@@ -44,9 +44,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: ${_param:kubernetes_netchecker_enabled}
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/init.yml b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/init.yml
index c1cc38f..a769d1c 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/init.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-dyn/kubernetes/init.yml
@@ -19,7 +19,7 @@
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_calico_policy_image: calico/kube-policy-controller:v0.5.4
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/compute.yml b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/compute.yml
index c84a223..aa3d759 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/compute.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/compute.yml
@@ -14,15 +14,14 @@
   kubernetes:
     pool:
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
-        mtu: ${_param:kubernetes_mtu}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          mtu: ${_param:kubernetes_mtu}
+          etcd:
+            ssl:
+              enabled: true
     common:
       hyperkube:
         image: ${_param:kubernetes_hyperkube_image}
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml
index c03d2c2..ed10270 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/control.yml
@@ -45,9 +45,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: ${_param:kubernetes_netchecker_enabled}
diff --git a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/init.yml b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/init.yml
index 044be55..e35f3c5 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/init.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico-minimal/kubernetes/init.yml
@@ -19,7 +19,7 @@
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
diff --git a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/compute.yml b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/compute.yml
index b4eee22..c41b40f 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/compute.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/compute.yml
@@ -15,15 +15,14 @@
       kubelet:
         fail_on_swap: ${_param:kubelet_fail_on_swap}
       network:
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
-        mtu: ${_param:kubernetes_mtu}
+        calico:
+          image: ${_param:kubernetes_calico_image}
+          calicoctl_image: ${_param:kubernetes_calico_calicoctl_image}
+          cni_image: ${_param:kubernetes_calico_cni_image}
+          mtu: ${_param:kubernetes_mtu}
+          etcd:
+            ssl:
+              enabled: true
     common:
       addons:
         virtlet:
diff --git a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml
index 9ba031c..aff2a3f 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/control.yml
@@ -46,9 +46,10 @@
         ssl:
           enabled: true
       network:
-        etcd:
-          ssl:
-            enabled: true
+        calico:
+          etcd:
+            ssl:
+              enabled: true
       namespace:
         netchecker:
           enabled: ${_param:kubernetes_netchecker_enabled}
diff --git a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/init.yml b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/init.yml
index 8736a3d..18599c4 100644
--- a/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/init.yml
+++ b/classes/cluster/virtual-mcp11-k8s-calico/kubernetes/init.yml
@@ -23,7 +23,7 @@
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
+    kubernetes_calico_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
     kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
     kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
     kubernetes_calico_policy_image: calico/kube-policy-controller:v0.5.4
diff --git a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/compute.yml b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/compute.yml
index 5cc9124..11fd26c 100644
--- a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/compute.yml
+++ b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/compute.yml
@@ -40,14 +40,6 @@
         config:
           api:
             host: ${_param:opencontrail_control_address}
-        etcd:
-          ssl:
-            enabled: true
-        image: ${_param:kubernetes_calico_image}
-        calicoctl:
-          image: ${_param:kubernetes_calicoctl_image}
-        cni:
-          image: ${_param:kubernetes_calico_cni_image}
         contrail_cni:
           image: ${_param:kubernetes_opencontrail_cni_image}
     common:
diff --git a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml
index 71cbf9c..364879f 100644
--- a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml
+++ b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/control.yml
@@ -16,10 +16,6 @@
         engine: docker_hybrid
       ssl:
         enabled: true
-      setup:
-        calico:
-          key: /calico/v1/ipam/v4/pool/${_param:calico_private_network}-${_param:calico_private_netmask}
-          value: '{"masquerade":true,"cidr":"${_param:calico_private_network}/${_param:calico_private_netmask}"}'
   kubernetes:
     common:
       addons:
@@ -47,10 +43,6 @@
       etcd:
         ssl:
           enabled: true
-      network:
-        etcd:
-          ssl:
-            enabled: true
       namespace:
         netchecker:
           enabled: true
diff --git a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/init.yml b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/init.yml
index ff8a2fe..0cc1a00 100644
--- a/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/init.yml
+++ b/classes/cluster/virtual-mcp11-k8s-contrail/kubernetes/init.yml
@@ -22,10 +22,6 @@
     kubernetes_docker_package: docker-engine=1.12.6-0~ubuntu-xenial
 
     # component docker images
-    kubernetes_calicoctl_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/ctl:latest
-    kubernetes_calico_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/node:latest
-    kubernetes_calico_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/projectcalico/calico/cni:latest
-    kubernetes_calico_policy_image: calico/kube-policy-controller:v0.5.4
     kubernetes_opencontrail_cni_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/contrail-integration/contrail-cni:v1.0.0
 
     kubernetes_hyperkube_image: docker-prod-virtual.docker.mirantis.net/mirantis/kubernetes/hyperkube-amd64:v1.8.6-5
@@ -77,10 +73,6 @@
     cluster_node03_address: ${_param:kubernetes_control_node03_address}
     cluster_node03_port: 4001
 
-    # calico
-    calico_private_network: 192.168.0.0
-    calico_private_netmask: 16
-
   linux:
     network:
       purge_hosts: true
