A coordination layer for identity and keys. A AmneziaWG mesh for traffic. That's the whole trick.
Nothing to rack, nothing to patch on-prem.
Each device runs the OpenVLAN client, generates its own key pair locally, and authenticates against your identity provider. Private keys never leave the device.
The coordination server learns public keys, device metadata, and your ACLs — then tells each node which peers it may reach. It never sees payload traffic.
Peers negotiate AmneziaWG tunnels, punch through NAT where possible, and fall back to encrypted relays when direct paths fail. Data flows device-to-device.
The separation that makes it fast and private.
No. Payload is encrypted between endpoints with AmneziaWG. The coordinator distributes keys and policy only.
Traffic falls back to encrypted DERP-style relays. Connectivity survives; only latency suffers slightly.
Enterprise agreements can host the coordination layer in your own environment for data-residency needs.
There is no hub in the data path. Latency is lower, failure modes fewer, and access rules follow identity instead of network position.
Four ideas do all the work. Everything else on this site is a consequence of them.
Nodes are known by who owns them, not where they sit. Addresses follow the user across networks and devices.
Every node holds fresh keypairs and re-authenticates on a short clock. Stolen credentials age out in minutes.
Direct peer-to-peer paths form through almost any NAT; a relay is the rare fallback, not the everyday road.
Every resource answers at a stable name under one domain. Humans stop maintaining hosts files.
Install on two devices and ping across the mesh before your coffee cools.