Hi HN, this is Alex and Dillon from Gravitl, based in the mountains of Asheville, North Carolina. We built Netmaker (
https://github.com/gravitl/netmaker), a virtual networking platform for cross-cloud computing and Kubernetes. It’s secure, automated, and extremely fast.
Networking across environments is hard and slow. WireGuard can solve this, but it’s tough to run at scale. WireGuard is a fast and efficient VPN protocol that is growing quickly in popularity. Linus Torvalds called it a “work of art,” and it was added to the Linux kernel in 2020. It now runs on most major operating systems.
We created Netmaker to automate WireGuard-based networks at scale. It opens up a bunch of use cases that are otherwise infeasible. With Netmaker, our users are managing edge networks, connecting fleets of unmanned aerial drones, and cloud-bursting k8s clusters for machine learning.
Alex got the idea for Netmaker while he was in New Mexico, staying in the desert to escape the pandemic. We were trying to run a distributed Kubernetes cluster. Our goal was to create a cloud provider with no infrastructure, using compute provided by users. To start, we bought a couple raspberry pis and some cloud VM's, hooked them all together, and ran a k3s cluster across them using WireGuard.
We realized we needed a mesh VPN to do this at scale. None of the existing options gave us everything we needed, so we built Netmaker. We put it on GitHub, and it became so popular that we decided to work on Netmaker exclusively.
Netmaker works on a client-server model (https://docs.netmaker.org/architecture.html). A central config server tells each machine where its peers are and how to reach them. The local client automates network settings and DNS on each machine. The result is a flexible virtual network that stays in sync whenever machines are added, removed, or there is a change in state.
Without Netmaker this is challenging, because WireGuard requires reconfiguration whenever any peer in the network changes. In addition, the network can be blocked by factors like NAT, firewalls, and port availability. Netmaker anticipates and solves for these factors, while being compatible across Mac, Linux, Windows, and FreeBSD.
There are other solutions out there with similarities, but we’ve got some key distinctions. After all, we created Netmaker out of necessity, because the other solutions didn’t meet our requirements. First off, Netmaker is super fast because it can use kernel WireGuard. There are some other WireGuard-based solutions like Tailscale, but they use userspace WireGuard, which is much, much slower.
Second, Netmaker is tailored towards the cloud and Kubernetes. Stuff like OpenVPN was built before the cloud became a go-to deployment strategy.
Finally, Netmaker is fully self-hostable. A lot of existing options are SaaS, but our users want control of any servers that are routing their traffic or managing their virtual networks.
As for what’s next, with Dillon at the lead, we’re putting in a lot of work to overhaul the code base, implement community-driven features, and pull Netmaker towards a “pure WireGuard” vision. We're planning an enterprise release in the coming months which will have a few features that businesses need at scale, without taking away from the free community version. In the meantime, we have a simple support subscription for the existing community edition: https://gravitl.com/plans.
We’re always looking for ways to do things better. If you have thoughts, we’d love to hear them, and if you’re doing anything cool with WireGuard that could be relevant to our project, we’d love to hear that too. We’ve also got a community on Discord you’re welcome to join at any time: https://discord.gg/zRb9Vfhk8A
Thanks for reading, and Happy New Year!
A couple questions from me, if you don't mind.
I currently use Tailscale for my home lab. My current model is similar to old-school road warrior VPNing, where I have my router as a node that routes to the LAN using the internal (non-meshed) IPs. Does your solution support that? How easy is it to deploy and configure it in that way?
Another feature I use is "exit nodes", i.e. my router as a gateway to the Internet, similar to what consumer VPNs (Mullvad, PrivateInternetAccess, etc) do. This offers me 2 things: more security when I'm on insecure networks (airport or other public WiFi, etc); and allows me to access things as though I'm at home when I'm traveling abroad. This is a one-time configuration and I can easily switch it on and off on demand via the desktop or phone app. Is this an option in your product?
Edit: s/customer/consumer/