LinkMesh

Search docs, blog and changelog

ENDE

Air-gapped OpenTelemetry

Manage your OpenTelemetry fleet in an air-gapped network

Disconnected, classified, and restricted networks still need central configuration, rollout, and drift detection — but they can’t call a vendor cloud to get it. LinkMesh runs entirely inside your boundary with no outbound internet at all: collectors reach only your in-network server over port 443, and upgrades come from an internal mirror. Self-hosted, standard upstream collectors, and priced per collector, not per gigabyte.

Deploy LinkMesh →

25 Collectors free after a no-card registration · 5 without one How the free tier works

Central management, with no line out

An air-gapped fleet needs everything a connected one does — consistent config, staged rollout, drift detection — with the one thing it can’t have: a route to the internet. These are the reasons SaaS management doesn’t reach it.

The management plane can’t call out

A disconnected, classified, or restricted network has no route to a vendor cloud. A control plane that phones home simply cannot run there — the config never arrives.

SaaS tools assume the internet

Most fleet-management products enroll collectors against a hosted endpoint. Cut the outbound path and enrollment, config push, and upgrades all quietly stop working.

Every outbound path is attack surface

In regulated and high-side environments, each egress route is something to firewall, justify, and audit. A tool that needs the internet is a tool security has to fight.

Upgrades assume a public repo

Collector and agent updates that pull from a public package repository or vendor CDN break the moment there is no line out — leaving you to patch by hand, host by host.

Manual config doesn’t scale offline

Without a control plane inside the boundary, an air-gapped fleet falls back to SSH and copied files — the exact drift-and-skew problem central management was supposed to solve.

Proprietary agents you can’t inspect

A closed agent running as root on every host is a supply-chain question anywhere, and in a classified environment it is often a non-starter from the first review.

Nothing crosses the boundary

The LinkMesh server, its database, an internal artifact mirror, your collectors, and your backends all sit inside the air gap. Collectors reach the server over one in-network port-443 connection and send telemetry to your in-network backends. There is no line out — not for config, not for upgrades, not for telemetry.

AIR-GAPPED BOUNDARY · no route to the internetLinkMesh Server + your databaseconfig · rollout · drift · health · RBACInternal mirrorinstalls · upgradesport 443 · config · healthupgradesSourceshosts · Kubernetesapps · syslogCollector Fleetotelcol-contrib · Grafana Alloystandard upstream buildsYour Backendsin-networkany OTLPtelemetrytelemetry
One boundary, no exit. Config and health flow to the in-network server, upgrades come from the internal mirror, and telemetry stays on in-network paths — nothing reaches the internet.

01

Runs fully inside the boundary

Problem

A control plane that lives in a vendor cloud cannot manage a fleet that has no route to that cloud. In an air-gapped network, the management plane has to be inside the network too.

LinkMesh

LinkMesh is a single self-hosted server you run on your own VM, Docker host, or Kubernetes cluster, backed by your own database — entirely inside your boundary. Collectors reach it over your own network; nothing depends on a LinkMesh SaaS.

Central collector management that lives where the fleet lives — inside the wire.

How LinkMesh is deployed and secured →
The LinkMesh Collectors view — a fleet of OpenTelemetry collectors with status, version, and host footprint, served from a self-hosted LinkMesh server inside the network.
One in-network server manages the whole fleet — no vendor cloud, no line out.

02

No outbound internet dependency

Problem

Every egress route in a restricted environment is something to firewall, justify, and defend at audit. A management plane that needs the public internet is a control you have to keep explaining.

LinkMesh

LinkMesh has no outbound dependency on a vendor. Collectors connect inbound to your in-network LinkMesh server; you can front it with your own reverse proxy and terminate TLS on infrastructure you control. Nothing in the loop reaches beyond your boundary.

Zero vendor egress to firewall, audit, or explain — the whole loop stays inside.

How-to: front LinkMesh with your own reverse proxy →

03

One in-network connection, over port 443

Problem

Configuring collectors in a locked-down network usually means SSH, a file per host, and a restart you hope worked — because the tools that would automate it need a cloud you can’t reach.

LinkMesh

Each collector opens a single connection to your in-network LinkMesh server over port 443: otelcol-contrib with the standard opampsupervisor over OpAMP, and Grafana Alloy over its native remotecfg endpoint. RemoteConfig, effective-config, and health all flow over that one in-network path — no inbound ports on the hosts, no SSH.

One in-network connection per collector replaces a fleet of SSH sessions — with no cloud involved.

How LinkMesh speaks OpAMP and remotecfg →

04

Install and upgrade from an internal mirror

Problem

Collector and agent updates that pull from a public repository or vendor CDN break the moment there’s no line out, forcing hand-patching across the fleet.

LinkMesh

Enroll and upgrade collectors from an artifact source inside your network — an internal package mirror you populate. The install path is the same one-line enrollment; it just points at your mirror instead of the public internet, so onboarding and updates work with no egress.

Onboarding and upgrades that run entirely off your own mirror, disconnected.

How-to: onboard otelcol-contrib over OpAMP →

05

Standard upstream collectors, no proprietary agent

Problem

A closed agent running as root on every host is a supply-chain risk anywhere, and in a classified environment it is often rejected before it’s even trialed.

LinkMesh

LinkMesh manages standard upstream builds — otelcol-contrib over OpAMP and Grafana Alloy over remotecfg. No forked collector, no closed agent you can’t inspect. Your security team reviews the same open binaries the community runs.

Inspectable, replaceable, open collectors — nothing on the host you can’t audit.

How a collector is modelled in LinkMesh →

06

Scoped access and audit for regulated environments

Problem

A flat, shared control plane is a governance problem: everyone can change everything, and a leaked token can enroll or reconfigure anything on the network.

LinkMesh

Organize collectors into groups with per-group scoped access, and enroll new collectors with scoped enrollment tokens rather than shared credentials. Users see and change only the parts of the fleet they own, and every change is attributable.

Least-privilege management and a clear audit trail, matched to how classified environments are split.

How collector groups and scoping work →
A LinkMesh collector group overview — environment Production, membership, tags, and per-group scoped access controls.
Groups carry environment, membership, and scoped access — the unit you govern against.

What LinkMesh is — and what it isn’t

What it is

A self-hosted control plane that runs entirely inside an air-gapped boundary, managing standard otelcol-contrib and Grafana Alloy collectors over one in-network port-443 connection — with enrollment and upgrades served from an internal mirror.

What it isn’t

It is not a telemetry backend or data store, and it is not a tool that phones home. LinkMesh does not ingest, index, or retain your logs, metrics, or traces, and it has no outbound dependency on a vendor cloud — the telemetry stays on your in-network paths and never transits LinkMesh.

If nothing changes

Left alone, none of this gets cheaper: the volume grows on its own, the data that already left cannot be recalled, and each agent added is one more to remove later.

Once it is running

  • A per-collector bill that a volume spike does not move.
  • Sensitive fields masked on the host, before anything leaves the network.
  • Every config change a diff you can review and roll back.
  • Backends you can swap, because nothing proprietary sits in the path.

Common questions

Does LinkMesh need internet access to work?

No. LinkMesh runs entirely inside your network with no dependency on a LinkMesh SaaS or any vendor cloud. Collectors connect to your in-network LinkMesh server over a single port-443 connection, so it works in fully air-gapped and disconnected environments.

How do collector upgrades work with no line out?

Collectors are enrolled and upgraded from an artifact source inside your network — an internal package mirror you populate. The enrollment path is the same one-line install; it points at your mirror instead of the public internet, so onboarding and updates need no egress.

Does LinkMesh require a proprietary agent?

No. It manages standard upstream collectors — otelcol-contrib over OpAMP and Grafana Alloy over remotecfg. There is no forked build and no closed agent, so nothing runs on your hosts that your security team cannot inspect or replace.

Where is my data stored in an air-gapped deployment?

In the database and infrastructure you provision inside your boundary. LinkMesh is a control plane and carries only configuration, health, and status — your telemetry flows straight from the collectors to your own in-network backends and never transits LinkMesh.

How is this different from the self-hosted control plane?

It is the same self-hosted LinkMesh server, deployed for a fully disconnected network. Self-hosting is about running the control plane on your own infrastructure; air-gapped operation adds that there is no outbound internet at all — enrollment and upgrades come from an internal mirror, and collectors reach only the in-network server.

How is LinkMesh priced?

By managed collector, never by data volume. The first 25 collectors are free after a no-card registration in the OpenSight Customer Portal (5 without one); beyond that it is a flat USD 12.50 · CHF 12.00 · EUR 12.50 per collector per month, billed annually, and the bill stops growing at 200 collectors.

Deploy the control plane inside the air gap

Self-hosted, disconnected-capable, and priced per collector. Stand it up on an in-network VM, enroll and upgrade from your own mirror, and manage the whole fleet with no line out. The first 25 Collectors are free after a no-card registration in the OpenSight Customer Portal (5 without one).

Install the control plane on any Linux VM — Ubuntu / Debian

curl -fsSL https://artifacts.saas.opensight.ch/binaries/linkmesh-server/latest/linkmesh-server_latest_amd64.deb -o linkmesh-server.deb && sudo apt install -y ./linkmesh-server.deb

RHEL / Rocky / AlmaLinux, air-gapped install, and the full walkthrough: Install guide →

Test this in your own environment

Use these maintained guides to move from product evaluation to a working configuration.

Check versions and limitations first