OpenVLAN vs building it yourself

AmneziaWG is free. The coordination plane, key lifecycle, ACL engine, and on-call rotation are not.

What DIY actually involves

Key distribution

Generating and exchanging keys for every device, securely, forever. One stale key is an incident.

IPAM & config

Hand-assigning addresses, writing per-peer config files, tracking which peer is which human.

NAT traversal

STUN/TURN-style relaying when peers can't punch through — you run the relays too.

ACL enforcement

AmneziaWG is all-or-nothing per interface. Per-resource access means iptables art on every box.

Identity integration

SSO, SCIM offboarding, group sync — the part every DIY mesh eventually fails an audit on.

Maintenance

Upgrades, revocation lists, monitoring, and the person who owns it all leaving the company.

The honest math

DIY AmneziaWG meshOpenVLAN
Time to working meshDays–weeks (first time)Minutes
Adding a deviceKey exchange + config edit + restartLogin
Revoking accessManual, every affected hostIdP offboard, automatic
Per-resource ACLsDIY firewall rulesPolicy as code
Behind hard NATRun your own relaysAutomatic fallback
Audit trailWhatever you buildFlow logs + session recording

When DIY genuinely makes sense

Two devices, one person

Laptop-to-server for yourself? Plain AmneziaWG is perfect. Add a third human and reconsider.

Extreme compliance regimes

Air-gapped or sovereign requirements where you must own every byte — see our self-hosted coordination docs.

AmneziaWG is the engine. Skip building the car.