AWS here, GCP there, Azure for that one acquisition — OpenVLAN stitches them into a single private mesh.
A single small instance in each VPC or VNet advertises its routes into the tailnet. No transit gateway attachments, no peering matrices, no per-region hub deployment — approve each route once in the console and every node on the mesh can reach every cloud.
Two clouds both claiming 10.0.0.0/16 used to mean a renumbering marathon. On the mesh, workloads keep their addresses and you address them by MagicDNS name instead — the name resolves to the right place regardless of which provider's range it lives in.
Every cloud has its own hub-and-spoke tax — per-attachment pricing, per-region deployment, per-vendor console. Subnet routers replace the whole diagram with one overlay.
Cross-cloud calls over the internet with IP allowlists are the usual shortcut. The mesh makes them private links with identity instead.
Two VPCs both claim 10.0.0.0/16? The tailnet's 100.64.0.0/10 space and MagicDNS names sidestep the renumbering project.
Autoscaled clusters join and leave constantly. Ephemeral nodes auth with short-lived tokens and clean themselves up.
One flat private network under every workload, whatever provider it landed on.
Autoscaled clusters join and leave constantly; ephemeral nodes auth with short-lived tokens and clean themselves up.
Subnet routers, ACLs, and node tags all manageable as code alongside your existing infrastructure definitions.
The tailnet's dedicated range means no more spreadsheet diplomacy over which cloud owns which CIDR.
Cross-cloud calls over the internet with IP allowlists become private links with identity instead.
Cloud-to-cloud traffic never touches a public IP or a shared transit network you don't control.
Each router carries a tag-based identity; compromise of one node doesn't grant reach into the others.
Every cross-cloud flow is logged with source identity — a paper trail no transit gateway gives you.
Move workloads cloud-to-cloud without a dual-network transitional phase for the apps.
Connect the acquired company's cloud to yours privately, before the org merge finishes.
Stand up the target environment and let both sides talk during the move; cut over when ready.
Some workloads will never leave the data center — the mesh treats it as just another site.
Deploy the first subnet router in about ten minutes.