2026
networkingd is a control plane for many VPN gateway nodes. It owns users, groups, plans, devices and policy, compiles them into per-node desired state, and hands out client configurations. Each gateway runs a node agent that pulls its desired state and drives local data-plane daemons to match.
| Plane | Role |
|---|---|
| Ingress | End-user tunnels in (WireGuard, OpenVPN, OpenConnect) |
| Egress | Outbound paths from gateway nodes |
| Policy | Who may use which node, ingress, egress and limits |
| Fleet | Many gateways under one control plane |
| Identity | Users, groups, plans, subscriptions |
| Portal API | What client apps and the web portal call |
Client apps / web portal / admin console
│ HTTPS + bearer token
▼
controlplane (Go, REST /v1/*)
│ node token + desired state
┌───────┴───────┐
▼ ▼
node-agent node-agent … N
│ │
▼ ▼
local daemons over HTTP / Unix sockets only
wireguardd · openvpnd · openconnectd · dnsd · netpolicyd
The boundary rules are strict and written down: the control plane never
imports a daemon's internals and never shells out to wg or openvpn; the
agent talks to local daemons only through their HTTP APIs; and client apps
talk only to the portal API, never to a node. Each daemon is its own
repository — wireguardd,
openvpnd,
openconnectd,
dnsd and netpolicyd —
pulled in as a submodule.
partial, and the
same generation is tried again.It is an internal product control plane, not a public multi-tenant SaaS. The portal API (auth, devices, egress, billing, tickets) and the admin console are in use; native client apps are still being designed and built; IKEv2 and SSO/OIDC are planned, not shipped. The source is private.
Go and chi for the control plane and agent; React 19, TanStack Start / Router / Query / Table, shadcn/ui and Tailwind v4 for the admin console and portal; Prometheus and Alertmanager for observability.