Open source

Open clients, open tooling

The pieces you run on your machines are open source — inspect them, build them, patch them.

Read the code that carries your packets

The clients are the data plane — every encrypted byte you send flows through code in public repos. That's the part we most want you to audit, patch, and fork: it's where trust is earned, not claimed in a PDF.

  • ✓Full client sources on every platform we ship
  • ✓Operator, provider, CLI, and relay server too
  • ✓Permissive licenses — BSD-3, Apache-2.0, MPL-2.0
the repos, by license
clientsall platforms, data planeBSD-3OPEN
k8s operatorCRDs, ingress, egressApache-2.0OPEN
tf providerpolicy as codeMPL-2.0OPEN
cli + sdksgo · python · tsBSD-3OPEN
relay serverself-host fallbackBSD-3OPEN

Reproducible builds, signed releases

"Trust the source" only helps if the binary matches it. Release artifacts are built reproducibly and signed — two maintainers on two continents can produce byte-identical binaries, and you can verify the one you downloaded against either.

# verify a release before you install it
$ cosign verify openvlan/client:1.8.2 \
  --certificate-identity "build@openvlan"
 
# build it yourself, compare hashes
$ nix build .#client-1.8.2 && sha256sum result
# identical. good.

What's open

Clients (all platforms)

Linux, macOS, Windows, iOS, Android, FreeBSD — full sources, reproducible builds where platforms allow.

Kubernetes operator

Ingress, egress, and CRDs — Apache-2.0.

Operator use case →

Terraform provider

Network policy as code, reviewed in your repo.

For DevOps →

CLI & libraries

The openvlan CLI and API client libraries in Go, Python, and TypeScript.

Relay (DERP-style) server

Run your own encrypted relay for fallback paths you fully control.

Community tools

Exporters, linters, and UIs from the ecosystem.

Browse →

Free for open-source projects

Maintainers deserve infrastructure that's free, like their software.

Open source plan

  • ✓Premium features for the project's tailnet
  • ✓Up to 25 users covering CI, staging, and dev VMs
  • ✓For actively maintained, public-license projects

Apply with your repo

What we ask

  • ✓A link back somewhere reasonable (README footer is fine)
  • ✓Tell us what you build — we love the stories

Also see the startup program →

Contributing

Good first issues

Labeled and mentored — the on-ramp for new contributors.

Docs PRs

Found a gap in the docs? One-paragraph PRs are celebrated.

The docs →

Security reports

Not via PR — use the disclosure process.

Trust Center →

Open source FAQs

Why is the coordination server closed-source?
The split is deliberate: the data plane — the code that touches your packets — is fully open. The coordination layer is identity, key exchange, and policy distribution, which is where multi-tenant operations live. Enterprises that need it fully in-house get the self-hosted coordinator.
Can I self-host the whole thing?
Everything except the hosted coordination plane: clients, relay server, and all tooling run wherever you want. The self-hosted coordinator (Enterprise) closes the gap for teams with data-residency or air-gap requirements.
Do you accept big features as PRs?
Yes, with an RFC first — a one-page design doc in the repo, discussed in the open before code. It's how the FreeBSD client and the AmneziaWG-userspace transport both landed. Small fixes need no RFC; just open the PR.
What license are the clients under?
BSD-3-Clause for clients, CLI, SDKs, and the relay server; Apache-2.0 for the Kubernetes operator; MPL-2.0 for the Terraform provider. All permissive or weak-copyleft — vendor them, ship them, keep your changes if you want.
How do security reports work for open repos?
Never as public issues. The disclosure process in the Trust Center takes reports privately; fixes ship to the open repos with credit once the release is out. The bounty program pays for the boring reports too — crashes found by fuzzing count.

Fork us, file issues, ship fixes

The best mesh network is one you can read the source of.