Architecture

How Nanami connects users, devices, and private services.

A workspace stores networks and access policies. Clients report presence and connection state. Gateways forward traffic only through allowed routes.

Network control graph

Control intent, regional gateways, and enrolled nodes in one mesh.

ControlGatewayNode
Control planePolicy engineGateway us-eastGateway eu-westGateway ap-southapi-gatewaydb-clusterci-runnerk8s-ingressedge-router
Core objects

Each object has one clear role

User-facing names describe the job. Internal API terms remain in technical reference material.

Users and teams

Define who can use each network and private resource.

Devices

Desktop, CLI, and manual WireGuard clients enroll separately and report their state.

Networks

Group devices and services into an understandable private access boundary.

Routes

Send selected traffic through an assigned device or gateway.

Gateways

Forward traffic to another network and report availability separately from user state.

Control Plane

Checks authentication, access, and changes. Tunnel secrets do not reach ordinary browser UI.

State

Configuration and observed state remain separate

An assigned route does not mean traffic is flowing. An online device is not necessarily connected. Nanami shows observed state beside configuration.

Control flow

Control plane

Desired state and access intent

  • Workspaces and groups
  • Policies and join keys
  • Identity and sessions

Gateway fabric

Regional orchestration and path stability

  • Gateway manager
  • Health reporting
  • Runtime metadata

WireGuard data plane

Encrypted packet transport

  • Peer config distribution
  • Gateway selection
  • Node-to-node traffic
Start with Nanami

Move from the model to the first connection

Quickstart covers environment choice, sign-in, a device, a network, and access without requiring internal terminology.

Nanami Cloud

Nanami operates the service infrastructure.

Self-hosted

Your team runs and maintains Community.