Everything from your first openvlan up to running a multi-region tailnet as code.
Install the CLI, sign in, and your device joins the network with a stable address and a name. No config files to write, no certificates to babysit, no ports to open — the install script detects your platform and the rest is a browser login.
Every guide is versioned alongside the clients and reviewed each release cycle. If your admin console shows a toggle these pages never mention, that's a docs bug — file it and the PR usually lands within days.
Your private network: all your devices, one address space (100.64.0.0/10 by default), one DNS namespace.
Anything joined to the tailnet — laptop, server, container, phone. Every node gets a stable identity.
The rulebook of who may talk to what. Deny by default, expressed against users, groups, and tags.
Every node is reachable by short name — ssh build-01 just works, no IP memorization.
Advertise whole CIDRs into the tailnet so existing networks join without touching each host.
Stable identities for shared/automated nodes — tag:prod, tag:ci — so policy doesn't depend on who enrolled them.
| Command | What it does |
|---|---|
| openvlan up | Connect / re-authenticate this device |
| openvlan down | Disconnect |
| openvlan status | Show peers, routes, and connection state |
| openvlan ip | Print this node's tailnet address |
| openvlan up --advertise-routes=10.0.0.0/16 | Become a subnet router |
| openvlan up --advertise-exit-node | Offer internet egress through this node |
| openvlan logout | Remove keys and leave the tailnet |
The knowledge base has answers; support has humans.