{"repo":"forgekeep/nebula-mesh","free":true,"listed":false,"github":"https://github.com/forgekeep/nebula-mesh","clone":"git clone https://github.com/forgekeep/nebula-mesh.git","description":"Self-hosted control plane for Slack Nebula mesh VPN — issue certificates, manage hosts, distribute config from one place. Go + SQLite + htmx.","language":"Go","stars":22,"topics":["certificate-authority","devops","golang","htmx","infrastructure","mesh-network","nebula","networking","pki","self-hosted"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"nebula-mesh Self-hosted control plane for Slack's Nebula mesh VPN — issue certificates, manage hosts (including iOS / Android via QR), distribute config, rotate CAs, and roll out changes from one place. UI : hosts · host detail · host create (advanced) · networks · profile Auth : login · register · 2FA setup · 2FA enabled + recovery codes · login → TOTP prompt --- Nebula gives you a fast, mTLS-authenticated overlay network. But on its own, it leaves the operator to hand-roll certificate issuance, rotation, distribution and revocation — usually with shell scripts and a CA on a laptop. nebula-mesh is the missing management layer: a single Go binary plus an enrollment agent that turn Nebula into a self-service mesh you can run on one VM. Install in 30 seconds On a fresh Debian / Ubuntu VM ( amd64 ): init binds 127.0.0.1:8080 by default, so the server is reachable locally: open http://127.0.0.1:8080/ui/ (or tunnel with ssh -L 8080:127.0.0.1:8080 ) and log in with the password printed by init . For remote access , terminate TLS — set tls cert + tls key , or front with nginx/caddy/traefik and keep the loopback bind. Serving plaintext on a routable address is refused unless you explicitly set allow insecure http: true (or pass --insecure-http ) — see Security. For RPM / macOS / FreeBSD / Windows / Docker / source — and the host-side agent — see Install below. For host enrolment and CLI walk-through, see Quickstart. Jump to: Why · Features · Architecture · Install · Quickstart · Oper","default_branch":null,"files":null,"tree":[],"storefront":"/r/forgekeep","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/forgekeep/nebula-mesh/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}