Skip to main content

  1. Agentycs
  2. Platform
  3. Cloud Mesh

Your edge network. Not somebody else's.

Cloud Mesh gives you the capabilities a global edge provider sells, ingress protection, geographic load balancing, DNS and private connectivity, as infrastructure your platform owns and runs.

One network across every site, application and agent #

Sovereignty tends to stop at the network. Organisations that carefully keep data and models in-house still route every request through a third-party edge, and hand over their DNS, their certificates and a view of all their traffic in the process. That is not a small residue: it is a supplier who can see who visits you, price the renewal accordingly, and answer to a legal system that is not yours. Cloud Mesh closes that gap by treating the network as part of the platform rather than as plumbing bought separately.

Each cluster's membership is declared, and the mesh turns that declaration into live overlay routing, DNS records, firewall policy and edge routes. The same overlay carries agent traffic: an agent at a remote site, an application in a datacentre and an operator on a laptop all join one authenticated network, where who may talk to whom is a policy rather than a firewall rule somebody remembers to remove.

Health is measured by actively probing real endpoints, never inferred from a status field.

What Cloud Mesh does #

Four ideas carry the product. Everything else is detail.

Your own front door #

A distributed gateway routes traffic to the right cluster under declared policy, with protection in front of every public hostname and several probed endpoints behind it.

  • Policy-based routing, not hand-edited config
  • Multiple probed endpoints per cluster
  • Serves from last known-good while recovering

DNS you run #

Authoritative name resolution is part of the platform rather than a rented dependency, and steers each client toward the nearest healthy site you operate.

  • Authoritative servers you own
  • Geographic load balancing
  • Certificates published in step with routes

One authenticated network #

Clusters, applications, agents and operator devices join one encrypted overlay where policy, not a device-by-device firewall rule, decides who may talk to whom.

  • Site to site, agent to site, agent to agent
  • Encrypted and auditable end to end
  • Private names that resolve across sites

Routing that is declared and signed #

The edge trusts a signed statement about where a hostname should be served rather than whatever it happens to reach, and unsafe advertisements are refused outright.

  • Signed routing envelope
  • Recovery routes kept structurally separate
  • Routes, groups and policies as resources

In more detail #

The full capability surface, grouped by the job it does.

Edge gateway

The front door: a distributed gateway that routes traffic to your clusters under policy.

Policy-based routing
Traffic is routed to the right cluster and service by declared traffic policies rather than by hand-edited configuration.
Protection at the door
Firewalling and denial-of-service protection sit in front of every public hostname.
Health-aware upstreams
Each cluster is reached through several independently probed endpoints, so losing one node cannot take a service off the internet.
Degrades without dropping
A recovering cluster keeps serving from the last known-good routing state, and is removed from the pool only when active probing shows it is genuinely unreachable.
Authoritative DNS

System-managed DNS for reduced external dependency, with geographic load balancing built in.

You run the servers
Authoritative DNS is part of the platform, so public name resolution is not a third-party dependency.
Geographic load balancing
Resolution steers each client toward the nearest healthy site, for failover and for latency.
Platform and tenant hostnames
Records for platform services and tenant-specific hostnames are managed together, from the same declared source.
Certificates in step
Hostnames and their certificates are published together, so a new route is reachable and trusted at the same moment.
Zero-trust network

Authenticated, encrypted, policy-enforced connectivity for clusters, applications and agents.

Site to site
Clusters and facilities join one secure overlay, so a multi-site platform behaves like one network.
Agents and people
Agent-to-site and agent-to-agent connectivity with the same authentication and policy as any other member.
Policy, not firewall rules
Group and policy management decides who may talk to whom, enforced across the overlay rather than configured device by device.
Encrypted and auditable
All overlay traffic is encrypted, and flows are monitored and auditable end to end.
Route publication

How the platform tells the edge where tenant traffic should go, safely.

Signed routing envelope
Public hostnames and certificates are published to the edge as a signed envelope, so the edge trusts a verified statement rather than whatever it can reach.
Guardrails on advertisement
Route publication refuses unsafe advertisements outright, so a misconfiguration cannot black-hole traffic.
Infrastructure stays reachable
The routes that carry recovery traffic are kept structurally separate from tenant routes, so a degraded platform never becomes unrepairable.
Declared, not clicked
Routes, groups, policies and DNS records are all declarative resources reconciled into the live network.
Private service discovery

Names that work inside the mesh, across every site.

Mesh-internal DNS
Private records let services and clusters resolve each other by name across sites, without exposing anything publicly.
Stable service identity
Services keep one name as they move between nodes, zones and sites.
Cross-site addressing
An application addresses a service in another region exactly as it addresses a local one.
Network operations

Know what the network is doing before your users tell you.

Connectivity monitoring
Continuous per-cluster probing against external anchors, so degradation is seen before it becomes an outage.
Traffic observability
Ingress, overlay and DNS behaviour report into the platform's shared metrics, dashboards and alerts.
Change with confidence
Network state is declared and reconciled, so a change is reviewable before it is live and revertible afterwards.
Credential hygiene
Management credentials are vault-held, expiry-tracked and alerted on, so network automation never stops quietly.

What it is used for #

Three jobs Cloud Mesh takes on.

Publish services sovereignly

Put your platform's public hostnames behind your own edge, with your own DNS and certificates, and no third party in the request path.

Join multiple sites

Connect datacentres, offices and remote installations into one authenticated network with policy between them.

Give agents a network identity

Let agents reach the systems they are permitted to reach, from wherever they run, under policy and with an audit trail.

How it fits in #

Cloud Mesh is declared alongside the rest of the platform and enforced by the same operator model.

  • Declarative network resources
  • Public hostnames
  • Overlay membership
  • Network telemetry
What each interface gives you
Declarative network resources
Cluster membership, routes, groups, policies and DNS records as version-controlled resources reconciled into live networking.
Public hostnames
Platform and tenant hostnames published to the edge with their certificates, from the platform's signed routing envelope.
Overlay membership
Clusters, applications, agents and operator devices as authenticated members of one policy-enforced network.
Network telemetry
Ingress, overlay, DNS and connectivity metrics in the same observability fabric as everything else.

Map it onto your sites

Tell us where your users, your clusters and your remote installations are. We will show you how the mesh would connect and protect them.