awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
slackhq avatar

slackhq/nebula

0
View on GitHub↗
17,405 stars·1,146 forks·Go·MIT·43 views

Nebula

Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer connections between distributed hosts. By utilizing a certificate-based identity authority, it enables the construction of private communication fabrics across disparate physical infrastructures, such as multiple cloud providers or on-premises data centers, without requiring central authentication servers.

The project distinguishes itself through a zero-trust architecture that enforces granular, policy-driven firewall filtering based on certificate-derived group memberships. It facilitates direct connectivity between nodes located behind restrictive firewalls and network boundaries by employing a sophisticated discovery protocol, relay nodes, and persistent keep-alive signaling to maintain stable tunnels.

Beyond its core connectivity features, the software provides a comprehensive suite of operational tools for network management and observability. This includes built-in diagnostic utilities for troubleshooting, support for exporting performance metrics to external monitoring systems, and integrated hostname resolution. The system also manages the full lifecycle of cryptographic identities, allowing for secure credential issuance and rotation to maintain network trust.

Features

  • Mesh Networking - Creates a scalable, software-defined mesh network with encrypted tunnels and certificate-based authentication.
  • Overlay Networks - Creates secure virtual private networks by encapsulating traffic within encrypted UDP packets across disparate physical infrastructures.
  • Peer-to-Peer Networking - Establishes decentralized, direct encrypted connections between nodes to bypass restrictive firewalls and NAT environments.
  • Certificate Authorities - Provides a decentralized certificate authority for managing cryptographic host identities without central authentication servers.
  • Traffic Encryption - Secures data transmission between network peers using authenticated encryption to ensure privacy and integrity across untrusted public network segments.
  • Peer Discovery - Operates a central directory service that helps distributed hosts locate and connect to each other across disparate networks without manual configuration.
  • Certificate Authority Management - Generates cryptographic credentials to sign and validate host identities, ensuring only authorized nodes can join and communicate within the network.
  • Encrypted Tunneling - Establishes secure, encrypted tunnels between network peers to ensure privacy across untrusted network segments.
  • Secure Node Networking - Verifies host identity using certificates and private keys to ensure secure peer-to-peer communication.
  • Zero Trust Networking - Enforces zero-trust security by requiring identity-based authentication for all communication between nodes.
  • Group-Based - Restricts communication between nodes using certificate-based security groups to enforce expressive and provider-agnostic access control policies.
  • NAT Traversal Mechanisms - Coordinates peer connectivity through firewalls and NATs using relay nodes and persistent keep-alive signaling.
  • Virtual Network Interfaces - Configures the virtual network device and tunnel lifecycle to handle packet routing and state management for the overlay network.
  • Credential Rotators - Updates or replaces security credentials and certificate authorities across the network infrastructure without interrupting active traffic or connectivity.
  • Firewall Policies - Enforces granular, policy-driven firewall filtering based on certificate-derived group memberships at the host level.
  • Identity Providers - Manages cryptographic host identities and certificate signing to authorize devices within the network.
  • Network Access Control - Defines inbound and outbound firewall rules to control traffic flow and enforce security policies at the host level.
  • Network and Infrastructure Security - Provides infrastructure for managing host identities and private certificate authorities to secure inter-node communication.
  • PKI Management - Issues and validates host certificates to establish trust and authorize communication between nodes within a private network.
  • Overlay Networks - Peer-to-peer overlay network for secure cross-site communication.
  • Infrastructure and Network Security - Scalable overlay networking tool for secure connectivity.
  • Network and Transport Security - Scalable overlay networking tool for secure, performant connectivity.
  • VPN and Networking - Scalable peer-to-peer VPN focused on performance and security.
  • Vpn Services - Scalable overlay networking for secure communication.
  • Virtual Private Clouds - Links servers and services across multiple cloud providers or on-premises data centers into a unified private communication fabric.
  • Connection Management - Establishes direct communication between devices by mapping host addresses and using discovery nodes to bridge connections across different network environments.
  • Encrypted Relaying - Forwards packets through intermediary nodes to establish connectivity between hosts that cannot communicate directly due to network restrictions.
  • Identity Issuance - Assigns unique identities and network addresses to individual nodes to prevent impersonation and enable granular access control.
  • Keep-Alive Signaling - Sends keep-alive packets to prevent firewall state expiration, ensuring persistent connectivity between peers located behind restrictive network boundaries.
  • Source Validation - Confirms that incoming packets originate from the source address authorized by the sender's certificate to prevent unauthorized traffic injection.
  • Remote Signing - Generates valid host certificates by exchanging public keys, eliminating the need to distribute or store sensitive private keys on multiple devices.
  • Network Diagnostics - Includes built-in diagnostic utilities to inspect and troubleshoot the status of network hosts.
  • Network Traffic Optimization - Prioritizes specific network ranges to improve performance and reduce latency for traffic between connected hosts.
  • Non-Overlay Routing - Configures specific network paths to forward traffic through designated nodes, allowing communication with devices that do not run the networking software directly.
  • Overlay Resolution - Provides a built-in domain name service to map network addresses to human-readable hostnames for easier connectivity between nodes.

Star history

Star history chart for slackhq/nebulaStar history chart for slackhq/nebula

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Nebula

These projects share indexed features with Nebula. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • netbirdio/netbirdnetbirdio avatar

    netbirdio/netbird

    26,188View on GitHub↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    Gogolangmeshmesh-networks
    View on GitHub↗26,188
  • easytier/easytierEasyTier avatar

    EasyTier/EasyTier

    12,012View on GitHub↗

    EasyTier is a decentralized peer-to-peer virtual private network and mesh networking tool. It functions as a layer 3 network overlay that establishes secure tunnels between devices without requiring a centralized server or coordinator. It also serves as a WireGuard-compatible VPN, capable of acting as a server for standard WireGuard clients. The project distinguishes itself through multipath latency-based routing and the use of KCP or QUIC proxies to mitigate packet loss and stabilize connections in high-loss environments. It provides a virtual networking manager featuring a web management co

    Rustnat-traversalp2prust
    View on GitHub↗12,012
  • firezone/firezonefirezone avatar

    firezone/firezone

    8,701View on GitHub↗

    Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to internal network resources. It functions as a virtual private network that synchronizes authentication and user groups via OpenID Connect providers. The system implements a group-based access control engine to enforce least privilege by restricting network resources to specific user groups. It utilizes holepunching and relay protocols for NAT traversal to establish encrypted tunnels through firewalls without requiring inbound ports. The platform includes a control plane for managing

    Elixirclouddevsecopselixir
    View on GitHub↗8,701
  • fosrl/pangolinfosrl avatar

    fosrl/pangolin

    21,255View on GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    TypeScriptcrowdsecdockerhome-lab
    View on GitHub↗21,255
Compare all 30 related projects→

Frequently asked questions

What does slackhq/nebula do?

Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer connections between distributed hosts. By utilizing a certificate-based identity authority, it enables the construction of private communication fabrics across disparate physical infrastructures, such as multiple cloud providers or on-premises data centers, without requiring central authentication servers.

What are the main features of slackhq/nebula?

The main features of slackhq/nebula are: Mesh Networking, Overlay Networks, Peer-to-Peer Networking, Certificate Authorities, Traffic Encryption, Peer Discovery, Certificate Authority Management, Encrypted Tunneling.

Which projects share features with slackhq/nebula?

Projects with overlapping indexed features include: netbirdio/netbird — NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the… easytier/easytier — EasyTier is a decentralized peer-to-peer virtual private network and mesh networking tool. It functions as a layer 3… firezone/firezone — Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to… fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… ntop/n2n — n2n is a peer-to-peer VPN that creates an encrypted mesh network by establishing layer 2 overlay networks. It uses UDP… zerotier/zerotierone — ZeroTierOne is a software-defined networking engine that creates virtual local area networks by emulating Ethernet…