Pipelines, runners, databases, and clusters — one private network under all of it, scriptable end to end.
CI jobs spin up, join the mesh with an ephemeral auth key, deploy over private paths, and evaporate. No shared VPN credential in secrets storage, no long-lived cloud keys on the runner — the pipeline's network access is as disposable as the pipeline.
ACLs, node tags, and users are all Terraform-managed. "Who can reach prod?" is answered by a file in git, reviewed by the same people who review the code — and the drift is impossible because there's no console to click around in.
Ephemeral runners join with auth keys, deploy to any environment, then evaporate. No shared VPN credentials in secrets storage.
Reach staging and prod databases from your laptop — gated by ACL and your identity, logged every time.
Services, pods, and node SSH through the mesh; clusters stop having public edges.
K8s use case →Subnet routers per VPC replace transit-gateway meshes and cross-cloud peering projects.
Multi-cloud →ACLs, nodes, and users via Terraform and the HTTP API — network changes go through PR review like everything else.
API reference →OpenVLAN SSH replaces bastions; every session ties to a person and can be recorded.
SSH feature →"We removed the jump host and half the security-group rules in one sprint."
"The VPN shared secret, the runner certs, the db password rotation calendar — most of it just went away."