Keep mature apps.
Navidrome, Jellyfin, Forgejo, SSH, and similar services keep their existing clients and workflows.
Kepos makes services on another machine feel local—without a public IP, account, or virtual subnet.
GET THE RIGHT BUILD All three downloads stay available.
01 / THE PRODUCT
Web services open in place. TCP services expose a local address.
02 / PRIVATE TOPOLOGY
The publisher accepts public keys from its local allowlist.
03 / WHY KEPOS
Mesh VPNs connect devices. Kepos exposes only selected services.
Navidrome, Jellyfin, Forgejo, SSH, and similar services keep their existing clients and workflows.
Kepos makes selected access channels direct, authenticated, and P2P instead of exposing a public port.
Browsers, media clients, Git tools, and SSH still use ordinary local URLs or ports.
KEPOS / HOLESAIL
Holesail documents a direct encrypted port tunnel with a connection key or QR flow and TCP plus UDP support. Kepos is for a persistent publisher/subscriber relationship with named services, device identities, and per-service authorization. Read the cited comparison
04 / HOW IT WORKS
HyperDHT finds the publisher and attempts NAT traversal.
The publisher accepts the subscriber only when its public key is allowed.
One encrypted connection carries separate channels for the allowed services.
05 / TECHNICAL LINEAGE
Peer discovery, NAT traversal, and encrypted streams.
Independent service channels over one connection.
A portable JavaScript runtime for Android and desktop hosts.
06 / OPEN SOURCE
Start with the public guide, then use the repository docs for contributor and architecture detail.