CI/CD pipelines that reach private infrastructure
Let GitHub Actions, GitLab CI, and self-hosted runners deploy to VPCs, on-prem clusters, and staging environments — without public ingress or brittle IP allowlists.
Runners shouldn't need public endpoints
Teams open SSH ports or whitelist GitHub's IP ranges that change weekly. Pipelines fail silently when a range rotates, and security reviews stall every release.
Runners join the mesh as first-class nodes
Install the Kimox agent on self-hosted runners or use ephemeral OAuth tokens for cloud-hosted jobs. Pipelines reach internal APIs and kube-apiserver endpoints directly.
Least privilege per pipeline
Tag runners by repo, branch, and environment. A feature-branch job can reach staging but never production — enforced at the network layer, not just in YAML.
Easy setup and management
GitOps-native
Declare runner mesh membership alongside your deployment manifests.
Tag-scoped ACLs
Restrict which repos and branches can reach each environment.
Terraform provider
Provision runner tags and ACL rules as infrastructure code.
Ephemeral tokens
Short-lived OAuth credentials for cloud CI — no long-lived secrets in repos.
Deployment audit trail
Log every pipeline connection attempt with repo and commit metadata.
NAT traversal
Runners behind corporate firewalls connect outbound — no inbound rules.
What customers are saying
“We stopped treating multi-cloud networking as a quarterly project. Kimox made it a one-line Terraform change.”
Priya Sharma
VP of Platform Engineering
“Our editors in Seoul finally work in real time with assets in LA. That was impossible on our old VPN.”
Marcus Chen
Director of Post-Production Technology
“Kimox is the first networking tool our OT and cloud teams both signed off on. That never happened before.”
Elena Rodriguez
Chief Information Security Officer
Frequently asked questions
Plans for every team
Ready to simplify your network?
Start free with up to 3 users. Scale when your team does.
Get started free