Your edge network. Not somebody else's.
Cloud Mesh gives you the capabilities a global edge provider sells, ingress protection, geographic load balancing, DNS and private connectivity, as infrastructure your platform owns and runs.
One network across every site, application and agent #
Sovereignty tends to stop at the network. Organisations that carefully keep data and models in-house still route every request through a third-party edge, and hand over their DNS, their certificates and a view of all their traffic in the process. That is not a small residue: it is a supplier who can see who visits you, price the renewal accordingly, and answer to a legal system that is not yours. Cloud Mesh closes that gap by treating the network as part of the platform rather than as plumbing bought separately.
Each cluster's membership is declared, and the mesh turns that declaration into live overlay routing, DNS records, firewall policy and edge routes. The same overlay carries agent traffic: an agent at a remote site, an application in a datacentre and an operator on a laptop all join one authenticated network, where who may talk to whom is a policy rather than a firewall rule somebody remembers to remove.
Health is measured by actively probing real endpoints, never inferred from a status field.
What Cloud Mesh does #
Four ideas carry the product. Everything else is detail.
Your own front door #
A distributed gateway routes traffic to the right cluster under declared policy, with protection in front of every public hostname and several probed endpoints behind it.
- Policy-based routing, not hand-edited config
- Multiple probed endpoints per cluster
- Serves from last known-good while recovering
DNS you run #
Authoritative name resolution is part of the platform rather than a rented dependency, and steers each client toward the nearest healthy site you operate.
- Authoritative servers you own
- Geographic load balancing
- Certificates published in step with routes
One authenticated network #
Clusters, applications, agents and operator devices join one encrypted overlay where policy, not a device-by-device firewall rule, decides who may talk to whom.
- Site to site, agent to site, agent to agent
- Encrypted and auditable end to end
- Private names that resolve across sites
Routing that is declared and signed #
The edge trusts a signed statement about where a hostname should be served rather than whatever it happens to reach, and unsafe advertisements are refused outright.
- Signed routing envelope
- Recovery routes kept structurally separate
- Routes, groups and policies as resources
In more detail #
The full capability surface, grouped by the job it does.
Edge gateway
The front door: a distributed gateway that routes traffic to your clusters under policy.
- Policy-based routing
- Traffic is routed to the right cluster and service by declared traffic policies rather than by hand-edited configuration.
- Protection at the door
- Firewalling and denial-of-service protection sit in front of every public hostname.
- Health-aware upstreams
- Each cluster is reached through several independently probed endpoints, so losing one node cannot take a service off the internet.
- Degrades without dropping
- A recovering cluster keeps serving from the last known-good routing state, and is removed from the pool only when active probing shows it is genuinely unreachable.
Authoritative DNS
System-managed DNS for reduced external dependency, with geographic load balancing built in.
- You run the servers
- Authoritative DNS is part of the platform, so public name resolution is not a third-party dependency.
- Geographic load balancing
- Resolution steers each client toward the nearest healthy site, for failover and for latency.
- Platform and tenant hostnames
- Records for platform services and tenant-specific hostnames are managed together, from the same declared source.
- Certificates in step
- Hostnames and their certificates are published together, so a new route is reachable and trusted at the same moment.
Zero-trust network
Authenticated, encrypted, policy-enforced connectivity for clusters, applications and agents.
- Site to site
- Clusters and facilities join one secure overlay, so a multi-site platform behaves like one network.
- Agents and people
- Agent-to-site and agent-to-agent connectivity with the same authentication and policy as any other member.
- Policy, not firewall rules
- Group and policy management decides who may talk to whom, enforced across the overlay rather than configured device by device.
- Encrypted and auditable
- All overlay traffic is encrypted, and flows are monitored and auditable end to end.
Route publication
How the platform tells the edge where tenant traffic should go, safely.
- Signed routing envelope
- Public hostnames and certificates are published to the edge as a signed envelope, so the edge trusts a verified statement rather than whatever it can reach.
- Guardrails on advertisement
- Route publication refuses unsafe advertisements outright, so a misconfiguration cannot black-hole traffic.
- Infrastructure stays reachable
- The routes that carry recovery traffic are kept structurally separate from tenant routes, so a degraded platform never becomes unrepairable.
- Declared, not clicked
- Routes, groups, policies and DNS records are all declarative resources reconciled into the live network.
Private service discovery
Names that work inside the mesh, across every site.
- Mesh-internal DNS
- Private records let services and clusters resolve each other by name across sites, without exposing anything publicly.
- Stable service identity
- Services keep one name as they move between nodes, zones and sites.
- Cross-site addressing
- An application addresses a service in another region exactly as it addresses a local one.
Network operations
Know what the network is doing before your users tell you.
- Connectivity monitoring
- Continuous per-cluster probing against external anchors, so degradation is seen before it becomes an outage.
- Traffic observability
- Ingress, overlay and DNS behaviour report into the platform's shared metrics, dashboards and alerts.
- Change with confidence
- Network state is declared and reconciled, so a change is reviewable before it is live and revertible afterwards.
- Credential hygiene
- Management credentials are vault-held, expiry-tracked and alerted on, so network automation never stops quietly.
What it is used for #
Three jobs Cloud Mesh takes on.
Publish services sovereignly
Put your platform's public hostnames behind your own edge, with your own DNS and certificates, and no third party in the request path.
Join multiple sites
Connect datacentres, offices and remote installations into one authenticated network with policy between them.
Give agents a network identity
Let agents reach the systems they are permitted to reach, from wherever they run, under policy and with an audit trail.
How it fits in #
Cloud Mesh is declared alongside the rest of the platform and enforced by the same operator model.
- Declarative network resources
- Public hostnames
- Overlay membership
- Network telemetry
What each interface gives you
- Declarative network resources
- Cluster membership, routes, groups, policies and DNS records as version-controlled resources reconciled into live networking.
- Public hostnames
- Platform and tenant hostnames published to the edge with their certificates, from the platform's signed routing envelope.
- Overlay membership
- Clusters, applications, agents and operator devices as authenticated members of one policy-enforced network.
- Network telemetry
- Ingress, overlay, DNS and connectivity metrics in the same observability fabric as everything else.
Map it onto your sites
Tell us where your users, your clusters and your remote installations are. We will show you how the mesh would connect and protect them.