Status & limitations
What has been proven on real hardware, and what has not.
The project's README ends with a section headed "Honest about where this actually is". It is reproduced here rather than summarised, because the difference between "implemented" and "exercised on hardware" is the whole point of publishing it.
Built, not yet proven
- Linux routing — Verified on Windows and macOS on real hardware. The Linux code paths are complete and compile, but subnet routing and exit nodes have not been exercised on a real Linux host.
- ICE nomination — Hole punching is covered by simulation tests including symmetric-NAT scenarios, but nomination has not been confirmed between two machines on separate networks.
- Reverse Proxy — Complete and unit-tested on both ends, never run end to end against a live public domain.
Deliberate boundaries
- Single tenant — One deployment serves one network. There is no organisation identifier anywhere in the schema.
- No web dashboard — The admin UI is the desktop client.
- No cloud SSO — Directory login via LDAP or Active Directory is the supported path; OIDC is a preview.
- Licensing — Not yet licensed for redistribution.