// the find
omniedgeio/omniedge
Bringing intranet on the internet with Zero-Config Mesh VPNs.
OmniEdge is a Rust mesh VPN that builds WireGuard tunnels between devices behind NAT, aimed at people running robot fleets, Jetson or Pi clusters, and lab networks that need each device reachable by virtual IP. The repo holds the CLI, a Tauri desktop app, an OpenWrt package, and a built-in SSH and SFTP stack in one Cargo workspace. It is the V2 rewrite of an older Go and n2n project.
- The tree has dedicated policy, recording, emergency and fleet modules, and the standalone SSH server takes explicit network allowlists and a user-mapping flag. Access control looks like a first-class concern rather than an afterthought.
- The plugin host runs WASM through wit-bindgen with a declared capability list per plugin, such as network-status, peer-info and http-client. That is a reasonable shape for an extension system in a daemon that would otherwise need fully trusted code.
- The crate boundaries are clear. omni-core, omni-api, omni-tun, omni-proto, omni-ssh and omni-plugin each have their own Cargo.toml, so one subsystem can be read without the others.
- The support table is honest about its gaps. MIPS is excluded for toolchain reasons, L2 is marked preview and Linux-only, and RISC-V is labelled Experimental instead of supported.
- The performance numbers are self-reported. The Cpk 2.92 and the 0.3ms overhead come from the project's own 50-run study on one cloud setup, and the 99%+ NAT traversal figure has no source in the repo. Treat them as claims to verify on your own network.
- The data plane lives in another repo. The README says OmniNervous supplies the P2P daemon, NAT traversal and relay, so the packet path and most of the hard connectivity logic are not visible here. Connectivity bugs will span two repos.
- The standalone `ssh-server --permissive` option accepts connections from any IP, and the examples show it without a warning. Someone who copies that onto a host with a public address ends up with an SSH listener open to the internet, relying only on authentication.
- Maintenance is hard to judge from outside. The last push was 27 February 2026, about seven months before today, and the Discord badge still points at the placeholder ID 1234567890.