Private paths into every cloud you run — without public subnets, transit hubs, or per-cloud appliance sprawl.
Every provider sells you its own hub-and-spoke. Connect three clouds and you're maintaining three incompatible meshes.
Databases and internal APIs get public endpoints "temporarily" — and the IP allowlist grows forever.
IPsec tunnels between offices and clouds: change windows, MTU debugging, and vendor tickets.
A single small instance advertises the VPC's private ranges. Everything on your tailnet reaches them — nothing else can.
AWS, GCP, Azure, Hetzner, OVH: identical setup steps. The cloud stops mattering to your access model.
Access follows the person and the device posture — not a list of office IPs that breaks with every remote worker.
Resources keep private-only endpoints. The control plane never sees payload; peers connect end-to-end encrypted.
Workloads in one cloud reach services in another over the tailnet — no public hops, no NAT gymnastics.
Second subnet router in another AZ: automatic failover, sessions that survive, no BGP archaeology.