No open ports. No peeking.
ZenoTunnel publishes services from your Kubernetes cluster or server through European edges. Your side dials out, so you open no inbound ports. The edge routes your traffic but never decrypts it: TLS ends inside your infrastructure.
One small connector on your side, a DNS record, and your own TLS. Nothing listens on your network.
Add it to your Kubernetes cluster with Helm, or run it on any Linux host. It opens one outbound, post-quantum TLS connection to our EU edges.
Add a DNS record for your hostname. We verify that the domain is yours and route it to your tunnel. No load balancer, NAT rules or firewall holes.
Visitors' TLS travels down the tunnel still encrypted. It ends in ZenoIngress or the proxy you already run, where your own WAF and policies inspect it.
Every TLS connection starts with a short, unencrypted greeting that names the website the visitor wants: the server name, or SNI. The ZenoTunnel edge reads that one field, picks your tunnel and passes the rest along exactly as it arrived, still encrypted. The keys that unlock the traffic live only in your infrastructure.
The connector answers the ACME challenge through the tunnel, so the private key never leaves your cluster.
Publish with an HTTPRoute and keep TLS and WAF policy in Git, next to the rest of your cluster configuration.
Your keys and rules already live with you. There is nothing to migrate out of our edge.
ZenoTunnel keeps a tamper-evident audit log that you can verify yourself.
The edge and the reverse tunnel run on the ZenoIngress engine: memory-safe Rust with a footprint of about 5 MB.
EU and Swiss infrastructure and an EU legal entity. No US hyperscaler sits in the data path.
The zt CLI handles domains, tunnels and hostnames. Run more connector replicas for more capacity; each edge sends a visitor to the least-loaded one.
# 1. Verify your domain
$ zt domains add example.eu
$ zt domains verify example.eu --wait 10m
# 2. Create a tunnel and install the connector
$ zt tunnels create prod-k8s
$ helm install zt zenotunnel/connector \
--namespace zenotunnel --create-namespace \
--set enrolment.token="$ZT_TOKEN"
# 3. Publish. Passthrough is the default.
$ zt hostnames publish app.example.eu --tunnel prod-k8s
Use the managed service, or license the whole stack and run it yourself.
We run the edges and the control plane on EU infrastructure. You install the connector and publish. The design-partner pilot has 8 slots: free for 8 weeks, best effort.
License the complete stack (control plane, edges and connectors) and run it in your own data centres, sovereign cloud or air-gapped network. No dependency on us as an operator. From €32,000 per year; evaluation licence on request.
Join the design-partner pilot or talk to us about a platform licence for your own infrastructure.