Both are open-philosophy mesh overlays born from the same problem. One is a project you operate; the other is a product.
| OpenVLAN | Nebula | |
|---|---|---|
| Control plane | Managed (or self-hosted) | Self-hosted lighthouses |
| Identity | SSO/IdP + device identity | Certificates (own CA) |
| Key rotation | Automatic | Manual cert lifecycle |
| Firewalling | ACLs as code + GUI | Static host firewall rules |
| Consumer clients | macOS, Windows, iOS, Android | Limited third-party apps |
| Relay fallback | Automatic relay network | Manual lighthouse config |
| Cost of operation | None (SaaS) | Your time + on-call |
You want full self-hosting, have strong Go/Linux skills, and your fleet is servers you already configure-manage.
Heterogeneous fleets (laptops, phones, NAS, k8s), identity from your IdP, and zero control-plane operations.
Nebula proved the certificate-based mesh model at scale (Slack born it). OpenVLAN's bet: make that model boring and managed.