TXGW + LGW topologycoming
Planned: LGWs terminate spoke groups and TXGWs stitch clouds together. Today the gateways in a cluster form a WireGuard mesh, both ends publicly routable — no broker, no relay in the middle of your traffic.
Gateways form the edge tier, in your own central VPCs. The design is a Local Gateway (LGW) per spoke group and a Transit Gateway (TXGW) for cross-cloud transit, orchestrated by the SaaS; today a cluster’s role is recorded and its gateways mesh with each other. Workload spokes never run an agent, VM, or sidecar.
Planned: LGWs terminate spoke groups and TXGWs stitch clouds together. Today the gateways in a cluster form a WireGuard mesh, both ends publicly routable — no broker, no relay in the middle of your traffic.
GCP first: VPC peering with ILB next-hop via custom route export, which the GCP integration can build but the platform does not yet run. AWS (GWLB endpoints + VPC peering) and Azure (Gateway LB chaining + VNet peering) follow. Replacing the cross-charging transit layers (TGW, Virtual WAN, NCC) comes with cross-cloud transit.
FRR ships on every gateway and installs the routes the control plane sends. BGP peering between gateways — iBGP and eBGP — is coming, so that a new region or CSP becomes a config change rather than a re-architecture.
Gateways reach the control plane over TLS and prove who they are on every call, with a proof signed by a device key and chained to Telaron’s device authority. A CIS/STIG-aligned, FIPS-140-3-capable base image is coming.
One secure fabric across every cloud — identity-aware policy, encrypted end to end, and no agents in your workloads. Start on the free Community tier; no sales call to get going.