Platform

Direct access to infra. No bastions required.

Every server, VPC subnet, and cluster becomes reachable by name from anywhere — without a single inbound port open to the internet. Bastion hosts, jump boxes, and allowlisted office IPs become unnecessary.

Direct tunnel from laptop to server rack, bastion dissolving in the background

One command advertises a whole subnet

Any Linux box or VM in your VPC, office, or data center becomes a subnet router with a single flag. The entire range joins your network — hundreds of databases, internal services, and admin panels become reachable by name or IP, without installing anything on any of them.

subnet router — routes
vpc-router-a10.0.0.0/16us-eastAPPROVED
office-gw192.168.1.0/24hqAPPROVED
rack-gw10.20.0.0/16dc1APPROVED
edge-relay172.16.8.0/22fieldPENDING
Approve from the console or Terraform — the audit log records who and when.

Close the front door

The fastest way to shrink your attack surface is to stop listening on the internet entirely. With access flowing through the mesh, the bastion's public IP, the VPN endpoint, the temporary firewall rule for a migration — all of it goes away. If nothing accepts inbound connections, there's nothing to scan, brute-force, or zero-day.

firewall — inbound listeners
bastion :22public ssh0.0.0.0/0CLOSED
vpn-gw :443tls endpointpublicCLOSED
k8s :6443api serverpublicCLOSED
db :5432migration windowtemp ruleREMOVED
everything elsemesh onlyidentity-gatedPRIVATE
Inbound ports open to the internet after OpenVLAN: zero.

Three access patterns, zero gateways

Pick the pattern that fits the resource. All three run on the same identity and the same ACL engine.

Direct node

Install the client on the host itself. It joins the mesh, gets a stable name and IP, and is reachable by anyone the ACL allows.

Subnet router

One machine advertises an entire VPC or office subnet. Hundreds of resources become reachable without touching any of them.

Egress exit

Route outbound traffic through a trusted node — fixed source IP for partner allow-lists, or a compliant region for regulated data.

What teams build with it

From multi-cloud backbones to a single contractor's scoped endpoint.

Multi-cloud overlay

AWS, GCP, and Azure ranges on one network — no transit gateways or inter-cloud peering to maintain.

Advertise any subnet

VPCs, office LANs, and data center racks join with one command per site, approved centrally.

Reachable by name

Every advertised resource resolves under one domain. Humans stop maintaining hosts files.

NAT & CGNAT traversal

Edge sites and LTE devices join without port forwarding or carrier negotiations.

No inbound ports

Zero public listeners to patch or defend. Access is outbound-only from each node.

Per-identity ACLs

Who reaches which range, port, and tag — decided by policy, visible in pull requests.

Encrypted overlay

AmneziaWG end to end, including the hop across the public internet between sites.

Vendor scoped access

Contractors get an identity that reaches exactly one service and expires Friday.

Database maintenance

Run migrations from a laptop over the overlay — no public endpoint, no temp firewall rule.

Kubernetes access

API servers, nodes, and pod networks stay private, reachable from laptop or CI.

Hybrid on-prem + cloud

The rack in the office and the region in the cloud behave like one network.

Edge & IoT fleets

Devices behind LTE or CGNAT phone home through the mesh — reachable and patchable.

Questions and answers

Do I install something on every server?
No — that's the point of subnet routing. One machine per network advertises the range; everything behind it becomes reachable without a per-host install. Direct installs are for hosts you want named individually.
What about high availability for subnet routers?
Run two routers advertising the same range; the mesh failovers between them automatically. Most teams point one at each availability zone or office uplink.
Does traffic hairpin through a central server?
No. Traffic takes direct paths between the user and the subnet router closest to the destination — usually the one inside that network. No central choke point, no bandwidth bottleneck.
Can we control which users reach which subnet?
Yes — standard ACLs apply to advertised routes exactly like direct nodes. "Support may reach the office LAN, only port 443" is one rule.
How does this differ from VPC peering?
Peering connects clouds to each other; the mesh connects people and workloads to everything. No CIDR-collision planning, no per-pair transit gateways, and users join the same network without any of it.
What if the subnet router dies?
Advertised routes stop; everything else keeps working. Monitoring treats routers like any other node — alerts fire, failover takes over, and the audit log shows exactly when.
Can containers and Kubernetes pods join directly?
Yes. Sidecar containers and operator-managed pods get their own identities, or you can advertise pod CIDRs from a node and keep workloads untouched.

Your infra, reachable. The internet, locked out.

Advertise your first subnet in under ten minutes.