OpenVLAN plugs into the identity providers, clouds, databases, and pipelines you already run — usually with nothing more than a tag or a token.
Authenticate users and sync groups with your existing directory.
SAML / OIDC SSO with group sync.
SSO plus SCIM provisioning.
One-click domain trust.
Org-based identity for dev teams.
Group-synced access.
Bring your own IdP.
Directory + device trust.
Enterprise federation.
Advertise VPC subnets, tag instances, connect clusters.
VPC subnets via subnet routers.
Subnet routing + tag sync.
VNet advertisement.
VCN connectivity.
Operator for cluster access.
Containers as first-class nodes.
deb / rpm / static binaries.
VMs and LXC containers.
Reach databases privately; audit every session.
Authenticating proxy support.
Private access + query audit.
Replica sets over the mesh.
Reach instances without public endpoints.
Brokers and consumers, privately.
Cluster access by identity.
Private connectivity patterns.
Analytics DBs behind policy.
Ship network telemetry where your team already looks.
Flow logs and node metrics.
Session logs via HEC.
Dashboard-ready metrics.
Node exporter templates.
Log shipping integrations.
Node-down alerting.
Audit stream to Azure SIEM.
JSON events anywhere.
Manage the network like code; connect runners per job.
Full network-as-code provider.
Modules for ACLs and nodes.
Ephemeral runner nodes.
Job-scoped connectivity.
Agent enrollment plugin.
Provider for every resource.
Declarative cluster joins.
Everything scriptable.
Clients and packages for the hardware you already own.
MSI + winget + Intune-ready.
Universal binary + MDM profiles.
deb, rpm, Arch, Alpine.
App Store client.
Play Store + managed configs.
Native package.
Community package.
Subnet router packages.
…plus many more. If it runs AmneziaWG or speaks IP, it can probably join a tailnet.
Most integrations are just a tagged node or a webhook away.