Deployment & operations

One binary to install. One file to manage. One screen to watch.

Operations decide whether resilient networking survives contact with a real estate. Atlas is built for the teams who run it: field operators who need point-and-click control, NOC teams who need APIs, and programmes that need everything to work with no internet at all.

No controller to stand upRuns air-gapped
01 · Install

One Linux binary and one configuration file.

Hardened service units, SELinux and AppArmor profiles and an Ansible role — with optional security-baseline chaining — ship with the software. A pilot needs no hardware procurement and no dedicated appliance. Hardening detail

02 · Configure

Plain text that lives in your version control.

Every setting is a human-readable file you can template, review and ship through existing automation. Traffic policy reloads live without a restart; load-time validation catches field-known misconfigurations before they bite. With the mesh enabled, a change pushed at any node gossips to every node over the encrypted tunnels themselves. Gossip · opt-in

And configuration has a front door: a guided wizard, part of the node’s own web interface, that builds a configuration step by step, rolls the change out across the fleet over the Atlas mesh itself — no central controller required — and tracks the rollout as it spreads: which nodes have received it, which have applied it, and how far the propagation has reached. It ships as part of the standard web dashboard.

In practice, the wizard runs entirely offline — on an air-gapped laptop, if the fleet never touches the internet — and everything it writes can equally be typed by hand. The dashboard’s TOML editor is a real editor: syntax highlighting, line numbers, the current line marked, and the daemon’s own validation run before anything is staged.

Changes apply hot, and the apply is transactional — committing opens a confirm window, and a node nobody confirms restores its previous file by itself. Any node can pull every other mesh member’s redacted configuration over the tunnels, because there is no controller to ask, and a compare view puts the selected nodes beside each other: policy that has drifted is flagged, node-local differences that are supposed to differ stay quiet.

03 · Monitor

The same telemetry the daemon uses, exposed to you.

Each node serves its own web dashboard: per-link delay, jitter, loss, capacity and queue depth, live topology, the scheduler’s actual decisions, and the bonding-overhead ledger. For headless estates: a CLI with status, statistics and a live terminal monitor, structured logs to journald or syslog, and a REST API for NOC and C2 integration. Nothing here asks you to adopt a new monitoring stack: the daemon exposes Prometheus metrics for the NMS you already run, exports state changes to a SIEM as RFC 5424 or CEF, and answers a health check that fails when the data path fails rather than when the process dies.

The node’s own view

A dashboard on every node — no SSH required.

Real captures from the Linux web interface: link health, routing state and live topology, served by the daemon itself.

The complete interface tour — nexusatlas.app
Fleet operations

One pane over the whole estate.

The hosted console adds fleet visibility on top of autonomous nodes: enrolment by one-time code the device proves cryptographically, a live map, per-link telemetry roughly every 30 seconds, offline alerts by email or webhook with recovery notices, organisations, projects and roles, an audit trail, and hardware-key second factor. Telemetry is on by default and opt-out — and fields with no genuine source are omitted, never fabricated.

Live service

Hosted relays and exits

Managed relay and exit locations in the EU and North America. A CGNAT-bound node is reachable outbound-only in under a second; direct paths are discovered and upgraded automatically, with the relay kept as a warm standby.

Offering

Private, on-premises relay estates

For closed networks: run the same relay software on your own infrastructure, absent from public discovery entirely — or mix hosted and private in a hybrid estate.

Shipped

Autoconfiguration

Relays are resolved from a cryptographically signed directory, measured, and chosen by latency — one configuration ships to a whole fleet with no hard-coded addresses.

Mobile nodes

The same engine, on a phone.

The Android application runs the unmodified Rust engine: Wi-Fi and cellular bonded into one encrypted tunnel, sub-second failover between them, per-app routing, a built-in field toolkit, and one-tap console enrolment. Verified live against both hosted gateways from a real device. Evaluation builds — not yet in an app store.

The Android tour — nexusatlas.app
Boundaries stated plainly

What operating Atlas assumes today.

The same discipline as everywhere else on this site: the boundary belongs beside the capability.

01

Linux is the supported platform

Servers, industrial computers and single-board computers running Linux. Android is an early implementation; other platforms are not claimed.

02

Opt-in means opt-in

Traffic classes, mesh gossip, traversal and prediction are configuration-gated and off by default — and byte-identical on the wire when off.

03

The console is optional

Fleet telemetry serves operators; the data plane never depends on it. Air-gapped estates run with the console absent and lose nothing but the map.

Request a briefing

Bring the network that is limiting your platform.

We will map the links, vendors, shared failure domains and integration boundary—and define what a useful demonstration or pilot should prove.