awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
gravitl avatar

gravitl/netmaker

0
View on GitHub↗
11,630 stars·643 forks·Go·48 viewsnetmaker.io↗

Netmaker

Netmaker is a platform for automating and managing virtual mesh networks built on WireGuard. It functions as a centralized control plane that orchestrates encrypted, peer-to-peer tunnels across distributed infrastructure, including cloud environments, on-premise data centers, and containerized clusters. By automating the configuration of routing tables and access policies, the system enables secure, private connectivity between diverse devices and services without requiring manual network administration.

The platform distinguishes itself through its focus on zero-trust network access and software-defined perimeters, which hide network resources from the public internet while enforcing granular, identity-based security policies. It supports complex network topologies by providing dynamic relay-based routing for firewall-traversal and gateway-based bridging for isolated subnets. These capabilities allow for the creation of scalable, high-performance overlays that maintain consistent connectivity even when direct peer-to-peer paths are unavailable.

Beyond core connectivity, the project provides a comprehensive suite of management tools, including automated node provisioning, private service discovery via integrated DNS, and multi-tenant infrastructure support. It also offers robust observability features, such as administrative audit logging and network health monitoring, to ensure operational visibility. The entire networking stack can be self-hosted to maintain data sovereignty, and the platform integrates with external identity providers to streamline authentication and device onboarding.

Features

  • WireGuard Management - Provides a comprehensive platform for setting up and managing WireGuard-based peer-to-peer tunnels.
  • Encrypted Tunneling Protocols - Uses high-performance kernel-level cryptographic primitives to establish secure, point-to-point encrypted tunnels.
  • Software-Defined Perimeters - Hides network resources from the public internet to enforce a software-defined perimeter.
  • Zero Trust Networking - Enforces granular, identity-based security policies to restrict communication and ensure zero-trust access.
  • Mesh Overlays - Maintains a dynamic, decentralized mesh topology where nodes establish direct connections to minimize latency.
  • Networking and Connectivity - Automates secure device connectivity across complex network environments without requiring manual port forwarding.
  • Mesh Networking - Connects distributed devices directly using encrypted tunnels to create high-performance virtual private networks.
  • Self-Hosted Infrastructure - Allows running the entire networking stack within private environments to maintain full data sovereignty.
  • Cloud Application Connectivity - Links disparate on-premise data centers and public cloud environments into a unified, seamless private network.
  • DNS Resolution - Provides internal hostname resolution to simplify service discovery by mapping hostnames to private IP addresses.
  • Encrypted Relaying - Redirects traffic through intermediary nodes to maintain connectivity when direct peer-to-peer paths are blocked by firewalls.
  • Management Dashboards - Provides a centralized interface for configuring, monitoring, and scaling secure tunnels and gateway connections.
  • Automated Node Provisioning - Simplifies large-scale infrastructure deployment by automatically registering new devices using pre-authentication keys.
  • Identity-Aware Infrastructure - Integrates external identity providers to enforce granular, role-based access policies across distributed device fleets.
  • Network Access Control - Defines granular rules to control traffic flow and restrict communication between connected nodes.
  • Network Segmentation - Creates isolated, encrypted network overlays to enforce security boundaries between departments, environments, or workloads without requiring separate physical infrastructure.
  • Control Planes - Coordinates distributed network state and configuration across edge nodes from a centralized management server.
  • VPN Clients - Provides a client interface for users to authenticate, manage their connection status, and tunnel internet traffic through secure network infrastructure.
  • Overlay Networks - Self-hosted platform for managing peer-to-peer virtual networks.
  • Container Networking Tools - Extends secure virtual networking directly into containerized clusters to enable private service access.
  • Multi-Tenancy - Provisions and maintains isolated network environments for multiple customers through a centralized interface.
  • DNS-Based Discovery - Automates internal hostname resolution by mapping network addresses to human-readable names across distributed infrastructure.
  • Gateway Configuration - Configures network appliances and routers to act as entry points, bridging remote traffic into local infrastructure.
  • High Availability Routing - Detects node failures and dynamically reroutes traffic to maintain continuous connectivity.
  • Multi-Cluster Service Connectivity - Automates network configurations across distributed Kubernetes clusters to enable seamless cross-environment service communication.
  • Service Discovery - Automates internal hostname resolution and DNS management to simplify service discovery across distributed networks.
  • Subnet Gateways - Deploys specialized gateway nodes to bridge isolated private subnets and external resources into the virtual mesh.
  • Centralized Identity Management - Provides a unified interface to oversee connectivity status, device configurations, and domain name assignments.
  • Identity Provider Integrations - Integrates with external identity providers to manage user logins, automate device registration, and enforce multi-factor authentication.
  • Just-in-Time Access - Provides temporary, time-bound network permissions to reduce the attack surface.
  • Tag-Based Policies - Groups network nodes using metadata labels to apply consistent access policies across dynamic infrastructure without manual configuration.
  • Static IP Enforcement - Assigns persistent network identifiers to remote devices to ensure consistent access control and simplify resource whitelisting across the network.
  • Address Conflict Resolution - Maps virtual IP addresses to destination networks to allow communication between environments with overlapping address spaces.
  • Tunnel Agents - Deploys background agents to automate the creation and maintenance of secure peer-to-peer network tunnels.
  • Service Exposure - Enables secure access to internal cluster services via private IP or DNS addresses.
  • Device Identity Management - Streamlines the registration of new devices using secure enrollment keys and supports token regeneration to maintain high security standards.
  • Access Policy Automation - Manages network access rules programmatically to integrate security configurations into deployment workflows.
  • Administrative Change Auditing - Maintains a verifiable history of all administrative configuration updates and management actions.
  • Network Monitoring Systems - Tracks performance metrics and connectivity status across the network to ensure reliable operation.
  • Endpoint Integrations - Connects diverse client types and legacy devices to ensure consistent communication across network infrastructure.
  • Relay Selection Optimization - Monitors latency to dynamically assign the fastest available relay server for traffic.
  • OAuth Authentication - Integrates external identity providers to manage user logins and enforce multi-factor authentication for network access.
  • Embedded Secure Connectivity - Integrates networking libraries directly into software to establish zero-trust communication channels.
  • Audit Log Exports - Forwards platform events and administrative actions to external security systems for centralized monitoring.
  • Network Access - Logs individual user sessions and accessed resources to ensure visibility into internal network activity.

Star history

Star history chart for gravitl/netmakerStar history chart for gravitl/netmaker

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does gravitl/netmaker do?

Netmaker is a platform for automating and managing virtual mesh networks built on WireGuard. It functions as a centralized control plane that orchestrates encrypted, peer-to-peer tunnels across distributed infrastructure, including cloud environments, on-premise data centers, and containerized clusters. By automating the configuration of routing tables and access policies, the system enables secure, private connectivity between diverse devices and services without requiring…

What are the main features of gravitl/netmaker?

The main features of gravitl/netmaker are: WireGuard Management, Encrypted Tunneling Protocols, Software-Defined Perimeters, Zero Trust Networking, Mesh Overlays, Networking and Connectivity, Mesh Networking, Self-Hosted Infrastructure.

Which projects share features with gravitl/netmaker?

Projects with overlapping indexed features include: tailscale/tailscale — Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted… netbirdio/netbird — NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the… fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… firezone/firezone — Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to… slackhq/nebula — Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer…

Projects sharing features with Netmaker

These projects share indexed features with Netmaker. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • tailscale/tailscaletailscale avatar

    tailscale/tailscale

    32,596View on GitHub↗

    Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted mesh network. By utilizing a high-performance, user-space implementation of the WireGuard protocol, it establishes secure peer-to-peer tunnels across diverse network topologies without requiring complex firewall configuration. The platform operates on a centralized control plane that manages global network state, authentication, and policy distribution, ensuring that connectivity is governed by identity rather than traditional IP-based rules. What distinguishes Tailscale is it

    Go2faoauthsso
    View on GitHub↗32,596
  • netbirdio/netbirdnetbirdio avatar

    netbirdio/netbird

    26,188View on GitHub↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    Gogolangmeshmesh-networks
    View on GitHub↗26,188
  • fosrl/pangolinfosrl avatar

    fosrl/pangolin

    21,255View on GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    TypeScriptcrowdsecdockerhome-lab
    View on GitHub↗21,255
  • octelium/octeliumoctelium avatar

    octelium/octelium

    3,371View on GitHub↗

    Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,

    Goabacai-gatewayapi-gateway
    View on GitHub↗3,371
  • Compare all 30 related projects→