Cribl builds data infrastructure for observability — and its people need secure reach into lab environments, demo fleets, and customer-adjacent systems. OpenVLAN replaced a tangle of per-purpose VPNs with one identity-based network.
A distributed company, multiple cloud environments, and a lab strategy that spawns short-lived infrastructure on demand. Field engineers reached demo environments through one VPN, support through a bastion, engineers through cloud-specific VPNs — each with its own client, credential lifecycle, and failure mode. Onboarding a new engineer meant provisioning four kinds of access; offboarding meant hoping nothing was missed.
Cribl standardized on OpenVLAN as the connective tissue: ephemeral lab environments join a dedicated tailnet on creation and disappear with it. Identity comes from their SSO, so access reviews became group reviews instead of credential archaeology.
access tools consolidated into one
to stand up a networked lab environment
standing credentials in field demos
The match between ephemeral infrastructure and ephemeral network identities. When an environment exists for a day, its network access should exist for exactly that day too — not live on in a VPN config file somewhere.
This case study is an illustrative example with fictional data for demonstration purposes.