Platform

CI/CD connectivity

Pipelines that reach what they must — and nothing else. Ephemeral identities, private deploy targets, zero credential sprawl.

Why pipelines leak

Static secrets in runners

Deploy keys, cloud credentials, and tokens stored in CI variables live for years and get copied into forks.

Flat network access

The runner sits where it can reach everything — so a compromised dependency can too.

Unattributable actions

When ten pipelines share one service account, audit logs can't say which job touched production.

The OpenVLAN way

Ephemeral identities

Each job joins the tailnet with a short-lived, pre-authenticated key. It expires when the job ends — nothing to rotate or leak.

Scoped per pipeline

The frontend pipeline reaches the CDN API; the database migration job reaches the DB. Neither can touch the other's targets.

Private deploy targets

Staging and production keep private endpoints. Runners connect as tailnet peers — no public ingress for robots.

Native integrations

GitHub Actions, GitLab CI, and Jenkins orbs/actions generate and use ephemeral keys automatically.

Per-job audit trail

Flow logs record which pipeline identity connected where — attribution by construction.

Self-hosted runners anywhere

Runners in your account, your VPC, or a homelab — the control plane stays ours, the compute stays yours.

Example: GitHub Actions

# .github/workflows/deploy.yml
- uses: openvlan/github-action@v2
  with:
    oauth-client-id: ${{ secrets.OV_CLIENT_ID }}
# the runner now has an ephemeral tailnet identity
- run: ./deploy.sh staging-web.internal

Ship faster with less to leak