Solutions

For DevOps & platform teams

Pipelines, runners, databases, and clusters — one private network under all of it, scriptable end to end.

Runners that exist for nine minutes, with real identity

CI jobs spin up, join the mesh with an ephemeral auth key, deploy over private paths, and evaporate. No shared VPN credential in secrets storage, no long-lived cloud keys on the runner — the pipeline's network access is as disposable as the pipeline.

  • ✓Pre-auth'd keys scoped to one job, one environment
  • ✓Deploys hit private endpoints — nothing public to attack
  • ✓Every step attributable in the audit log
# GitHub Actions job — ephemeral node joins, deploys, leaves
- uses: openvlan/actions/login@v2
  with: { authkey: ${{ secrets.OV_AUTHKEY }} }
- run: ./deploy.sh db-prod.internal
- uses: openvlan/actions/logout@v2
 
# runner lifetime: 9 min · network grant: same

The network changes through the same PRs as the app

ACLs, node tags, and users are all Terraform-managed. "Who can reach prod?" is answered by a file in git, reviewed by the same people who review the code — and the drift is impossible because there's no console to click around in.

terraform plan — network change
acl.deploy-dbsrc: group:sre → db-prod:5432+1 rulePR #482
tag.retiredgroup:legacy-ci → *-1 rulePR #482
review2 approvals · checks greenmergeAPPLIED

Where it slots into your day

🔄

CI/CD runners

Ephemeral runners join with auth keys, deploy to any environment, then evaporate. No shared VPN credentials in secrets storage.

🗄️

Database access

Reach staging and prod databases from your laptop — gated by ACL and your identity, logged every time.

📦

Kubernetes operator

Services, pods, and node SSH through the mesh; clusters stop having public edges.

K8s use case →
☁️

Multi-cloud wiring

Subnet routers per VPC replace transit-gateway meshes and cross-cloud peering projects.

Multi-cloud →
🧾

Config as code

ACLs, nodes, and users via Terraform and the HTTP API — network changes go through PR review like everything else.

API reference →
⌨️

Auditable SSH

OpenVLAN SSH replaces bastions; every session ties to a person and can be recorded.

SSH feature →

What teams report back

Bastions deleted

"We removed the jump host and half the security-group rules in one sprint."

Secrets shrunk

"The VPN shared secret, the runner certs, the db password rotation calendar — most of it just went away."

DevOps FAQs

Which CI systems are supported?
Any of them — the action wrappers exist for GitHub Actions and GitLab, and everywhere else it's two shell commands in your job script. The mesh doesn't care what launched the runner.
Can we run self-hosted runners on the mesh?
That's the most common setup: persistent runners join as tagged nodes, and ephemeral ones join per-job with expiring keys. Both patterns are documented with copy-paste examples.
How do auth keys stay safe?
Keys are scoped (tags, destinations, TTL), single-use when you want, and revocable in bulk. A leaked key grants exactly the slice of network it was minted for — and nothing else.
Does Terraform coverage include ACLs?
Yes — ACLs, users, tags, and even tailnet settings are resources. Network changes land in your plan output like any other infrastructure diff.
Is there an API for custom tooling?
A full HTTP API covers everything the console does — devices, keys, routes, ACLs, flow logs. Internal developer platforms build their self-service portals on top of it.

Wire your pipeline in this afternoon

Free plan, ephemeral nodes included.