Identity-based, least-privilege access to every resource — enforced on every connection, on every device, with nothing implied and everything logged.
Network location stopped meaning safety years ago. In OpenVLAN, users authenticate through your SSO and every device gets its own short-lived identity — so access decisions are made about a person on a specific machine, not about an IP address that could be anyone behind the router.
No rule means no access — there is no implicit trust anywhere in the mesh. ACLs read like sentences your auditors can parse without a consultant: who, from which device, may reach which resource, on which port. Every change lands in version control with a reviewer's name attached.
You don't rip out the network on day one. You move the fence, then the keys, then the rules.
Users log in with the SSO you already run. Every device gets a short-lived identity — not a shared secret that outlives employment.
Firewalls stop being the only lock. Each host, database, and cluster checks the caller's identity and device posture itself.
ACLs read like sentences: "engineers on company laptops may SSH to production, everyone else may not." Nothing is implied.
The pieces vendors usually sell separately — identity, policy, audit — arrive together.
Okta, Entra, Google, or any OIDC provider. One login session governs every resource.
Every machine gets its own node identity and keypair — laptops, servers, CI runners alike.
Credentials rotate on a short clock. Stolen material ages out in minutes, not quarters.
Unmanaged or non-compliant devices connect into a restricted scope, or not at all.
No rule, no access. Nothing is implied by network position anywhere in the mesh.
Rules read like sentences — auditors parse them without a consultant in the room.
Every change is a reviewed pull request. Roll back any rule and see who approved it.
Scope by user, group, tag, port, or protocol — down to a single database login.
Every session maps to a person and a device. Anonymous service access is opt-in only.
Destination, port, duration, and bytes for each session — exportable as JSON or CSV.
Who changed which rule, when, and with whose approval — recorded automatically.
Ship access and policy events to Datadog, Splunk, or any webhook endpoint.
Turn on SSO, write one ACL file, and watch implicit access disappear.