---
title: "calicoctl ipam check"
description: "Reference for the calicoctl IPAM check command in Calico Open Source, used to audit IP address allocation consistency across the cluster."
product: "Calico Open Source"
version: "3.33 (latest)"
section: "Reference"
canonical_url: "https://docs.tigera.io/calico/latest/reference/calicoctl/ipam/check"
---

# calicoctl ipam check

This section describes the `calicoctl ipam check` command.

Read the [calicoctl overview](https://docs.tigera.io/calico/latest/reference/calicoctl/overview.md) for a full list of calicoctl commands.

## Displaying the help text for 'calicoctl ipam check' command

Run `calicoctl ipam check --help` to display the following help menu for the command.

```text
Check the integrity of Calico's IPAM data structures and report leaked or
improperly allocated IP addresses. The report it produces can later be passed
to ipam release.

Usage:
  calicoctl ipam check [flags]

Examples:
  # Check IPAM and write a report of problem IPs.
  calicoctl ipam check --show-problem-ips -o report.json

Flags:
  -c, --config string       Path to the file containing connection configuration in YAML or JSON format. (default "/etc/calico/calicoctl.cfg")
  -h, --help                help for check
      --kubeconfig string   Path to Kubeconfig file.
  -o, --output string       Path to output report file.
      --show-all-ips        Print all IPs that are checked.
      --show-problem-ips    Print all IPs that are leaked or not allocated properly.

Global Flags:
      --allow-version-mismatch   Allow client and cluster versions mismatch
      --context string           The name of the kubeconfig context to use
  -l, --log-level string         Set the log level (panic, fatal, error, warn, info, debug) (default "panic")
```

### Examples

Example workflow for checking consistency and releasing leaked addresses.

**Lock the data store**

```bash
calicoctl datastore migrate lock
```

> **SECONDARY:** Once the data store is locked, new pods will not be able to be launched until the data store is unlocked.

**Generate a report using the check command**

```bash
calicoctl ipam check -o report.json
```

**Release any unnecessary addresses**

```bash
calicoctl ipam release --from-report report.json
```

**Unlock the data store**

```bash
calicoctl datastore migrate unlock
```

## See also

- [Installing calicoctl](https://docs.tigera.io/calico/latest/operations/calicoctl/install.md)
