Privilege-separated control plane
The public web layer runs without system privileges and stays separate from infrastructure operations.
A web control plane separated from privileged node agents.
The public web layer runs without system privileges and stays separate from infrastructure operations.
OpenVPN, Xray VLESS + REALITY, AmneziaWG and WireGuard are represented through a consistent control model.
Only small allowlisted agents perform privileged actions on managed VPN nodes.
Read-only filesystems, dropped capabilities and internal networks reduce the exposed attack surface.
TLS termination, security headers, request filtering and structured access logs are handled at the edge.
Atomic updates, health checks, backups and automatic rollback keep releases predictable.