Mercari's infrastructure spans regions and clouds. OpenVLAN gave every engineer the same identity-based path to it — without a single VPN gateway.
A global marketplace doesn't have one network — it has dozens. Mercari's SRE and platform teams ran access differently per environment: bastion chains in one cloud, security groups and allowlists in another, ad-hoc tunnels for the rest. Every new region or cluster meant new access machinery, and every incident meant figuring out which path was even supposed to work.
The platform team deployed OpenVLAN alongside existing access paths: nodes enrolled through the identity provider, and a handful of subnet routers advertised each cloud's private ranges. ACLs replaced per-environment allowlists — one policy file in Git describing who could reach which service groups. Ephemeral test environments simply joined the tailnet for their lifetime and disappeared with it.
"Access used to be something each environment solved for itself. Now it's a property of the network. Engineers stopped noticing it — which is the point." — Platform Engineering, Mercari