Reach private networks before the tool runs.
VPN connections (IPsec, SSTP or WireGuard, client or server role) sit in the same governed catalog as SSH and Ansible. Typical path: gateway first, then SSH or playbooks on the far side.
What VPN provides
Catalog-gated `vpn` connector. Writer can see connections; mutating connections follows admin roles. Secrets stay referenced, not pasted into workflows.
IPsec, SSTP, WireGuard
Supported protocols are IPsec, SSTP and WireGuard. The connection record also has a client or server role.
Network path
VPN is the path to private hosts. It does not replace SSH profiles, Ansible allowlists or product audit.
Test the gateway
Validate the connection from admin before workflows depend on it. Gateway unavailable is a first-class failure, not a silent skip.
Then SSH or Ansible
After the tunnel is up, governed SSH profiles and Ansible playbooks run on the reachable hosts.
Ready to move beyond the chatbot?
Build AI that understands your business, follows your processes, finishes the work — and keeps token spend under your control.