Cloud connectivity

Private paths into every cloud you run — without public subnets, transit hubs, or per-cloud appliance sprawl.

The cloud connectivity mess

A transit hub per cloud

Every provider sells you its own hub-and-spoke. Connect three clouds and you're maintaining three incompatible meshes.

Public endpoints by default

Databases and internal APIs get public endpoints "temporarily" — and the IP allowlist grows forever.

Site-to-cloud ceremony

IPsec tunnels between offices and clouds: change windows, MTU debugging, and vendor tickets.

With OpenVLAN

One subnet router per VPC

A single small instance advertises the VPC's private ranges. Everything on your tailnet reaches them — nothing else can.

Same pattern, every cloud

AWS, GCP, Azure, Hetzner, OVH: identical setup steps. The cloud stops mattering to your access model.

Identity, not IP allowlists

Access follows the person and the device posture — not a list of office IPs that breaks with every remote worker.

No public exposure

Resources keep private-only endpoints. The control plane never sees payload; peers connect end-to-end encrypted.

Cloud-to-cloud without egress

Workloads in one cloud reach services in another over the tailnet — no public hops, no NAT gymnastics.

Failover that isn't painful

Second subnet router in another AZ: automatic failover, sessions that survive, no BGP archaeology.

Five minutes to your first VPC

# on any instance inside the VPC
$ curl -fsSL https://www.openvlan.com/install.sh | sh
$ openvlan up --advertise-routes=10.0.0.0/16
# approve the route once in the console, then anywhere:
$ ssh admin@db-internal

Your clouds, one private mesh