UpdatesExplore the release notes
Back to Blog

Why We Built Baseguard

A laptop, a staging server, a private database. Connecting them should be a small part of the job. We built Baseguard to keep it that way.

You need to reach a staging server from your laptop. The server is running. You have permission to use it. But before you can get to work, someone needs to sort out the network.

That small task can turn into a separate job: finding the right VPN configuration, checking an address, figuring out which rule is blocking the connection.

We built Baseguard because we wanted that part of the day to be simpler.

Start with two machines

Most of the work we want to do over a private network is ordinary. Open an internal dashboard. Connect to a database. Let a build runner fetch a container image.

Our starting point was a laptop and a server. Install Baseguard on both, sign in, and bring them into the same private network. They can find each other even when one is at home and the other is in a cloud account.

Baseguard tries to connect them directly. If a direct path is unavailable, an encrypted relay carries the connection. You do not need to set up port forwarding on the router to make the server reachable through Baseguard.

See how the mesh works.

Use a name you can remember

An address is useful to a machine. A name is usually more useful to the person working with it.

A node called build-01 gets a DNS name automatically. You can use the full name shown in the console. With the appropriate search domain configured, you can use the short name too.

You should not have to keep a note of private IP addresses just to get back to the same server tomorrow.

The Names and DNS lesson walks through an example.

Make access a decision you can read

Connecting the machines is only part of the job. A developer may need the staging application. A build runner may need the registry. Neither necessarily needs access to everything else.

In Baseguard, you group nodes with tags and write rules between those groups. A rule can allow dev to reach staging over HTTPS on port 443. The names in the rule describe the access you mean to give.

That still requires a decision from you. You choose the groups, services and ports. If your network has a starter allow-all rule, remove it when you are ready to limit access. Rules are enforced on the nodes, and Preview helps you review their configuration.

We want the setup to be easy to understand, including the parts you need to change.

Walk through an access rule.

Leave a record for the next person

A working network is easier to maintain when changes do not depend on someone's memory.

The audit log records administrative changes, including who made them and when. If a rule was edited or a node was removed, the next person has somewhere to look.

It is a small thing until you need it. Then it saves you from piecing together a change from chat messages and guesses.

Try one useful connection

You do not need to move your whole infrastructure to try Baseguard. Start with your laptop and one machine you regularly need to reach.

Connect them. Use the server's name. Give that connection the access it needs. See whether it makes an everyday task easier.

That is the experience we are building around.

Start with your first network.

Keep reading

All articles

Networking · 5 min read

Use Pi-hole or AdGuard Home Remotely with Baseguard

Run a DNS filter on one Baseguard node and use it across your connected devices, including on mobile data. Your DNS server stays private.

Read the article
Get Started

Ready to try Baseguard?

Connect two devices, then follow a short lesson to see how your private network works.

Get started for free