Architecture

How OpenVLAN works

A coordination layer for identity and keys. A AmneziaWG mesh for traffic. That's the whole trick.

Physical device layer below, luminous mesh overlay above, dotted links between

Three moving parts

Nothing to rack, nothing to patch on-prem.

Clients enroll

Each device runs the OpenVLAN client, generates its own key pair locally, and authenticates against your identity provider. Private keys never leave the device.

The coordinator distributes

The coordination server learns public keys, device metadata, and your ACLs — then tells each node which peers it may reach. It never sees payload traffic.

The mesh connects directly

Peers negotiate AmneziaWG tunnels, punch through NAT where possible, and fall back to encrypted relays when direct paths fail. Data flows device-to-device.

Coordination plane vs. data plane

The separation that makes it fast and private.

Coordination plane

  • ✓Identity, groups, device registry
  • ✓Public key distribution
  • ✓ACL evaluation and distribution
  • ✓DNS records for MagicDNS
  • ✓Hundreds of bytes per node — not your traffic

Data plane

  • ✓Direct peer-to-peer AmneziaWG tunnels
  • ✓Encrypted end-to-end between devices
  • ✓Relay fallback only when NAT blocks direct paths
  • ✓No payload ever touches the coordinator
  • ✓Linerate limited only by your own links

What traffic looks like

# laptop → db-prod over the tailnet
$ openvlan status
100.64.0.1 laptop direct macOS
100.64.0.4 db-prod direct linux
 
$ ping db-prod
64 bytes from db-prod.tailnet.com (100.64.0.4): time=1.8 ms
 
# traffic encrypted with AmneziaWG, peer-to-peer
$ ssh db-prod # authenticated by your IdP via OpenVLAN SSH

Common questions

Does OpenVLAN see my traffic?

No. Payload is encrypted between endpoints with AmneziaWG. The coordinator distributes keys and policy only.

What if a direct connection can't be established?

Traffic falls back to encrypted DERP-style relays. Connectivity survives; only latency suffers slightly.

Can policies live outside the cloud?

Enterprise agreements can host the coordination layer in your own environment for data-residency needs.

How is this different from a hub-and-spoke VPN?

There is no hub in the data path. Latency is lower, failure modes fewer, and access rules follow identity instead of network position.

Under the hood

Four ideas do all the work. Everything else on this site is a consequence of them.

Identity is the address

Nodes are known by who owns them, not where they sit. Addresses follow the user across networks and devices.

Keys, rotated constantly

Every node holds fresh keypairs and re-authenticates on a short clock. Stolen credentials age out in minutes.

NAT traversal by default

Direct peer-to-peer paths form through almost any NAT; a relay is the rare fallback, not the everyday road.

Names over numbers

Every resource answers at a stable name under one domain. Humans stop maintaining hosts files.

See it work in minutes

Install on two devices and ping across the mesh before your coffee cools.