Remote access without a hosted control plane by Tanveer AhmedRemote access without a hosted control plane by Tanveer Ahmed

Remote access without a hosted control plane

Tanveer Ahmed

Tanveer Ahmed

The problem

Remote administration normally costs you one of two things: a management port published to the internet, or a hosted control plane whose terms can change under you. And the networks you have to work from — hotel Wi-Fi, mobile CGNAT, corporate proxies — fight the tunnel either way.

What I did

Built an estate administered entirely over an encrypted overlay with no management port published anywhere: a self-hosted control plane, one subnet router into the LAN, split-horizon DNS so internal names resolve to internal addresses inside the tunnel, and a connection ladder that tries direct, then a router port mapping, then a relay.

The result

Every host reachable by name from anywhere, nothing administrable from the public internet, and no third party able to change the terms. The write-up names the load-bearing component too — the single subnet router — because a design review that hides its own weak point isn't a review.
Like this project

Posted Sep 28, 2026

An estate administered entirely over an encrypted overlay: self-hosted control plane, split-horizon DNS, and no management port published anywhere.