One makes private services public to specific people. The other makes them private-network-reachable to your whole team, forever.
| OpenVLAN | ngrok | |
|---|---|---|
| Primary job | Private network for your org | Public ingress tunnels |
| Team access to shared services | Every member, any protocol | Per-tunnel endpoints |
| Expose one service publicly | Funnel (specific services) | Core product, polished |
| Webhook/dev testing | Funnel + local dev nodes | Best-in-class DX |
| Device-to-device (SSH, Taildrop) | Built in | Out of scope |
| Long-lived infra access | Stable names & ACLs | Tunnel URLs/agents |
| Free tier | Personal, 100 devices | Generous for 1 agent |
You need to show a local web app to the outside world, receive webhooks in dev, or add auth to a public endpoint — fast.
The audience is your team, not the public — and the traffic includes SSH, databases, k8s, and files, not just HTTP.