The OpenVLAN operator joins your clusters to the tailnet — pods, services, and operators reachable privately from anywhere.
No load balancer provisioning, no certificate ceremony, no ingress controller tuning. The operator watches for the annotation and publishes the service straight onto the tailnet, where it gets a MagicDNS name and identity-based access control.
Workloads authenticate with short-lived credentials issued at deploy time. When a pod is evicted or a node is reclaimed, its access evaporates with it — nothing long-lived to scrape from a config map and reuse elsewhere.
Expose cluster services to the tailnet with a simple annotation — no public load balancer, no cert drama.
Let pods reach databases and internal APIs through subnet routes, with source identity intact.
Dev, staging, and prod clusters on one mesh — namespaces stay isolated by ACL, not by network.
Pods in different clusters call each other by name over encrypted paths; no cross-cluster peering required.
Services and pods become first-class tailnet citizens via CRDs, managed like everything else in your cluster.
Ephemeral clusters authenticate with expiring auth keys; nothing long-lived to leak.
Debug node-level issues with OpenVLAN SSH — no bastion pod, full session audit.
The API server itself can drop its public endpoint and live entirely on the mesh.
Developers hit their namespace's services from laptops; nothing about the cluster is public.
CI applies manifests to clusters over the mesh; cloud keys stay out of the runner.
Cluster workloads reach the on-prem Oracle DB through the office subnet router.
Install, upgrade, and configure with the tooling your team already reviews in PRs.