# gravitl/netmaker

Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.

Repository: https://github.com/gravitl/netmaker
Canonical: https://ross.abutalabs.com/products/netmaker
Homepage: https://netmaker.io
Language: Go
License: NOASSERTION
License Family: other
Topics: wireguard, vpn, mesh, zero-trust, devsecops, k8s, kubernetes, wireguard-ui, cloud, security, wg-quick, wireguard-vpn, vpn-server, virtual-networking, self-hosted, mesh-network, overlay-network, ipv6-support, secure-remote-access, site-to-site
Last push: 2026-08-26T18:07:06+00:00

## Health v2 (maintenance only)
Score: 91/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 76, longevity 100
- inputs: {"age_days": 1987, "days_push": 7, "days_rel": 82, "gap_med": 53.5, "n_releases_24m": 11}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 11763, forks 651 (observed 2026-08-28T04:10:49.715364+00:00)

## What it is
Netmaker is an open-source platform that automates the creation and management of WireGuard-based virtual mesh networks, from homelab to enterprise scale. It provides a server with an admin UI plus a netclient agent to build peer-to-peer overlay networks with gateways, ACLs, DNS, and metrics.

## Use cases
- set up a self-hosted WireGuard mesh VPN across my servers
- connect remote employees securely to the office network
- link multiple office or cloud sites with site-to-site networking
- replace a legacy VPN with a faster WireGuard overlay
- manage a fleet of edge devices behind CGNAT or firewalls
- create a full-tunnel VPN with an internet egress gateway
- control which devices can talk to each other with ACLs

## When to choose
- you want fast, kernel-level WireGuard performance with automated peer configuration
- you need self-hosted mesh networking with a central management UI and API
- you need remote access gateways, site-to-site routing, relays, and failover in one platform
- you want zero-trust access control and private DNS across a distributed network

## When to avoid
- you only need a simple single-server VPN without mesh management overhead
- you prefer a fully managed service and don't want to run a control server
- you need a non-WireGuard protocol or unsupported client platforms
- you require a permissive open-source license for commercial redistribution (license is custom)

## Facets
- artifact type: service
- maturity: active
- function: vpn, networking, security, self-hosted, monitoring, auth
- domain: networking, security, self-hosted, infrastructure-as-code
- platform: windows, self-hosted, go
- tags: wireguard, mesh-vpn, overlay-network, zero-trust, site-to-site, sd-wan, remote-access, egress-gateway, acl, private-dns, devops, linux, macos, docker, kubernetes

## Member repositories
- gravitl/netmaker (main) score 91

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:10:49.715364+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:15:20.561275+00:00, confidence not recorded.
  - readme: https://github.com/gravitl/netmaker (fetched 2026-08-28T04:10:49.715364+00:00, sha 30a798dd0b4a)
  - homepage: https://netmaker.io (fetched 2026-08-29T08:13:33.832944+00:00, sha 5057270adbd2)
  - site_page: https://www.netmaker.io/features/egress (fetched 2026-08-29T08:13:33.842602+00:00, sha bdc03696bf8e)
  - site_page: https://www.netmaker.io/features/mesh (fetched 2026-08-29T08:13:33.845129+00:00, sha b71973f6bb95)
  - site_page: https://www.netmaker.io/features/remote-access (fetched 2026-08-29T08:13:33.847539+00:00, sha a285ff9978af)
  - site_page: https://www.netmaker.io/features/relay (fetched 2026-08-29T08:13:33.849760+00:00, sha 5baeef11a6ad)
  - site_page: https://www.netmaker.io/features/acls (fetched 2026-08-29T08:13:33.851384+00:00, sha 9baeaf14ea3a)
  - site_page: https://www.netmaker.io/features/dns (fetched 2026-08-29T08:13:33.853063+00:00, sha c944dab6de44)
  - site_page: https://www.netmaker.io/features/metrics (fetched 2026-08-29T08:13:33.854663+00:00, sha c41cdf6c88a6)
  - site_page: https://www.netmaker.io/features/failover (fetched 2026-08-29T08:13:33.856240+00:00, sha 0dc3eb46d095)
- Data as of 2026-08-30T08:39:29.467469+00:00.
