Exclusive Access · Invitation Only
Stratum Fabric Status: Available

Isolate, route and meter every tenant on servers you own.

Fabric turns a bare-metal server into a multi-tenant network node: private networks per customer, anti-spoofing, a stateful firewall, NAT, DHCP and DNS, load balancing, BGP and bandwidth plans. Packets are filtered and forwarded in the kernel.

Specification

forwarding In the kernel
management CLI · REST · gRPC
licensing Per node
architecture x86-64 · arm64

Runs on

Debian 11+, Ubuntu 22.04+, RHEL 8+, Rocky Linux 8+ and AlmaLinux 8+, on a recent 6.x kernel. The installer tests your kernel before it changes anything.

Fig.01 — Capabilities

What Fabric does today.

Nine groups. Every ticked line ships today; the few marked as coming will arrive with the multi-server release. Which of them a node can use depends on the plan it is licensed for.

Tenant isolation

Keep customers apart on shared hardware, enforced on every packet.

  • Private networks per tenantTraffic between the private networks of two different tenants is refused in the packet path, with no firewall rule needed.
  • IP-to-MAC bindingEach port is locked to its approved address pair, so no one can impersonate another host.
  • ARP and IPv6 neighbour guardForged ARP replies and neighbour-discovery spoofing are dropped at the edge.
  • Router and DHCP guardTenant ports cannot pose as a router or as an address server, over IPv4 or IPv6.
  • Port lockingA tenant’s hardware address is pinned to the port it belongs to.

Separation covers the private networks you create for a tenant. Public addresses stay reachable, just as they would be on the internet.

Firewall

Stateful rules, checked in the kernel before traffic reaches a workload.

  • Layered rulesFrom network-wide down to a single workload, checked in order; the first match wins.
  • StatefulReplies to connections you allowed are let back in automatically.
  • Rich matchingAddress, network, port, protocol, hardware address or domain name.
  • Scheduled rulesTurn rules on and off by day and time.
  • Blocklist and connection limitsBlock sources, with an optional expiry, and cap how many connections one source may hold.
  • Presets and conflict checksWeb, database, mail and game-server presets; contradictory rules are caught before they apply.

When no rule matches, the default action applies. It starts as allow; set it to deny to let through only what you list.

Gateway, NAT and routing

Every node forwards. Give tenants the internet and publish their services.

  • Outbound NATMany private tenants share one public address to reach the internet, ping included.
  • Port forwardingPublish an internal service on a public address and port.
  • Hairpin NATReach an internal service through its public address from inside the same network (IPv4).
  • IPv6, NAT66 and NAT64Route IPv6, translate it, and let IPv6-only clients reach IPv4-only services.
  • Static and policy routingRouting tables with policy rules by source, destination, mark or interface.

A packet that cannot be translated is dropped. It is never forwarded carrying a tenant’s private address.

DHCP, DNS and addresses

The services every tenant network needs, built in.

  • DHCP serverAddresses per network, with reservations, renewals and flood protection.
  • Authoritative DNSYour own zones and records: A, AAAA, CNAME and more.
  • Split answersGive internal and external clients different answers from one zone.
  • Filtering, caching and signingSinkhole unwanted domains, cache, forward upstream and sign responses.
  • IPv4 address poolsA pool per network, with overlap and conflict checks before anything is applied.

Creating a network creates its address pool. DHCP and DNS are switched on per network, when you want them.

Bandwidth and usage

Sell bandwidth plans and bill for what was used.

  • Per-tenant limitsUpload and download limits with burst allowances, enforced on the node.
  • Your plan’s ceilingEach node’s total throughput follows the speed of the plan you buy.
  • Monthly quotasUsage caps that reset automatically each month.
  • Usage accountingByte and packet counts, with 95th-percentile figures.
  • Flow recordsPer-connection statistics, exported as CSV or JSON.
  • Billing hooksSuspend, resume or limit a tenant from your own billing system through the API.

Load balancing

Spread traffic across backends at layer 4 or layer 7.

  • Virtual IPsOne address in front of many backends.
  • AlgorithmsRound-robin, least-connections, weighted and source-hash.
  • Sticky clientsConsistent hashing keeps each client on the same backend.
  • Health checksUnhealthy backends are taken out of rotation automatically.
  • HTTP routingRoute by host and path, with optional TLS termination.

Multi-host networking

One network across many servers.

  • Overlay networksStretch a Layer-2 network across hosts and racks over your existing IP network (VXLAN).
  • Geneve and VRFsGeneve tunnels, and separate routing tables for tenants whose address ranges overlap.

Coming with the multi-server release

  • ClusteringNodes will share state and elect a leader, keeping addresses, blocklists, peers and floating IPs in step across them.
  • Floating IPs across nodesAddresses will move to a healthy node when one fails.

BGP and peering

Connect to your upstream routers and announce your own networks.

  • BGPAnnounce your networks to upstream routers, and filter what you import and export.
  • RPKI origin validationRoutes with an invalid origin are rejected.
  • Resilient peeringGraceful restart, and fast detection of a failed neighbour.

Coming with the multi-server release

  • Gateway failoverA standby gateway will take over a shared address when the active one fails, and you will decide when it fails back.

Operations and visibility

Run it from scripts, see what it is doing, put it back when someone meddles.

  • Command line and APIEvery feature from one command-line tool, plus REST, gRPC and WebSocket APIs.
  • Scoped API keysKeys that can act for one tenant and nothing else.
  • Metrics, alerts and eventsPrometheus-compatible metrics, threshold alerts and a live event stream.
  • Audit log and webhooksA record of every management action, and signed event notifications to your endpoints.
  • Backups and updatesScheduled backups with retention; signed updates that each node pulls and verifies.
  • Self-repairHand-made changes to managed interfaces are detected and put back; a watchdog restarts the service if it stalls.

Also included

  • Link bonding and consistent packet sizes
  • Stable names for every network card
  • Network-card offload where the card supports it
  • Containers on the same networks and firewall
  • Signed plugins and a plugin marketplace
  • Certificates for every node from your account’s own authority

Fig.02 — Failure modes

What happens when…

Management and traffic are separate. When management stops, for any reason, your customers’ traffic does not.

LicenceYour licence expires
Traffic keeps flowing. You are warned in the week before expiry and get a 14-day grace period after it; after that, changes are frozen until you renew.
ServiceStratum restarts or updates
Packet processing carries on in the kernel. Only changes wait until the service is back.
DriftSomeone changes a managed interface by hand
The change is detected and your configuration is put back. Where the kernel allows it, deleting a managed interface can be blocked outright.
RebootA node reboots
Networks, rules and addresses are applied again from the node’s saved configuration.
OutageA gateway node fails
Automatic gateway failover is coming with the multi-server release. Until then, two nodes can each peer over BGP and announce the same networks, so your upstream keeps a path while either one is up.
LimitsA tenant hits their bandwidth limit
Their traffic is held to the limit they bought.

Fig.03 — Pricing

Licensed per node, per month.

Plans from $39 per node per month. Pay monthly, or save with a longer term. There is also a free Lab plan for non-commercial use.