How Nanami connects users, devices, and private services.
A workspace stores networks and access policies. Clients report presence and connection state. Gateways forward traffic only through allowed routes.
Network control graph
Control intent, regional gateways, and enrolled nodes in one mesh.
Each object has one clear role
User-facing names describe the job. Internal API terms remain in technical reference material.
Users and teams
Define who can use each network and private resource.
Devices
Desktop, CLI, and manual WireGuard clients enroll separately and report their state.
Networks
Group devices and services into an understandable private access boundary.
Routes
Send selected traffic through an assigned device or gateway.
Gateways
Forward traffic to another network and report availability separately from user state.
Control Plane
Checks authentication, access, and changes. Tunnel secrets do not reach ordinary browser UI.
Configuration and observed state remain separate
An assigned route does not mean traffic is flowing. An online device is not necessarily connected. Nanami shows observed state beside configuration.
Control plane
Desired state and access intent
- Workspaces and groups
- Policies and join keys
- Identity and sessions
Gateway fabric
Regional orchestration and path stability
- Gateway manager
- Health reporting
- Runtime metadata
WireGuard data plane
Encrypted packet transport
- Peer config distribution
- Gateway selection
- Node-to-node traffic
Move from the model to the first connection
Quickstart covers environment choice, sign-in, a device, a network, and access without requiring internal terminology.
Nanami Cloud
Nanami operates the service infrastructure.
Self-hosted
Your team runs and maintains Community.