Management / Control
Enrollment, node and resource inventory, Mesh IP, internal DNS, route policy, configuration, and audit. It does not carry application payloads.
ZERO TRUST CONNECTIVITY
Oten uses an encrypted overlay to connect User Device Nodes, Server Nodes, and resource routes. Direct paths are preferred when network conditions allow; an encrypted relay path is a fallback when NAT or firewall constraints prevent direct connectivity.
System role: Oten Endpoint + Connectivity Services
Evaluation depends on: Requires Device Trust, resource definitions, and Access Policy.
Enrollment, node and resource inventory, Mesh IP, internal DNS, route policy, configuration, and audit. It does not carry application payloads.
Presence and candidate exchange help authenticated nodes establish or re-establish a path. Signal is not an application proxy.
WireGuard-encrypted traffic follows an authorized direct or relayed path. The data plane does not invent business policy.
A fallback service forwards encrypted packets when direct connectivity is not feasible. Relay is not Oten Gateway.
The Agent resolves an internal name or resource from policy-authorized discovery data.
The Control Plane evaluates the user, device, resource, protocol, and current conditions.
The Agent receives scoped peer, route, DNS, and authorization state with bounded validity.
Authenticated nodes gather network candidates and exchange path information through Signal.
A direct UDP path is attempted when feasible; relay fallback is used only when configured and required.
The Agent reports Direct or Relayed state, relevant trade-offs, and policy-safe troubleshooting reasons.
OIDC Authorization Code with PKCE → device registration → posture evaluation → signed policy/configuration → Connected, Restricted, or Blocked.
A Setup Key bootstraps enrollment only. The enrolled Server Node receives its own identity and key; revoking the Setup Key does not implicitly revoke existing nodes.
Exact hosts and named services are preferred over broad subnets. Routing nodes provide paths; they do not automatically become resources available to users.
FAQ
No. Tunnel encryption protects the data path. Zero Trust requires identity- and resource-focused policy, device context, bounded decisions, and enforcement that does not grant trust merely because a node is on a network.
The architecture is designed so relay forwards end-to-end encrypted packets without decrypting the application payload. Relay metadata, authentication, rate limits, and operational boundaries still require explicit security treatment.
No. It improves connectivity under common NAT and firewall constraints, but does not justify a 100% connectivity claim. Availability, capacity, protocol support, and local network policy still affect the outcome.
Next in Oten Access
Review the system boundaries, direct and relayed paths, and the failure behavior that keeps connectivity claims evidence-safe.