GOpenCNR / Gelhaus Open Community Network Registry
Your own addresses and ASN on a private network, routed through hubs and encrypted end to end.
A private overlay network run to registry discipline: globally unique private IPv6, IPv4 on request and ASNs from one registry, routed between members over WireGuard and BGP through hubs, encrypted end to end, with every filter and key generated from the registry.
What it is
GOpenCNR, the Gelhaus Open Community Network Registry, is a private network run like a registry. Members get globally unique private IPv6 space, IPv4 on request, and an autonomous system number from one registry, and their networks are routed to each other over WireGuard and BGP through hubs. It is for homelabs, self-hosters, learners and organisations whose sites should reach each other without being exposed to the public internet.
Addresses that are yours to use
Every allocation comes from GOpenCNR's own range, fdc0:0900::/24: a /56 for a person and a /48 for an organisation by default, and more on justification. Space and ASNs are allocated, never owned or sold. They stay yours for as long as you confirm them once a year and use them.
Encrypted end to end
Between agents, traffic is encrypted end to end. Hubs forward it without seeing inside, and they keep counters, not records of who talked to whom. Nothing leaves for the public internet: both ends of every packet are inside GOpenCNR or a named interconnect.
The registry is the truth
Every route filter, ROA, tunnel and firewall rule is generated from the registry and delivered as a signed bundle. Nothing is configured by hand on a hub, and a hub that cannot load fresh data keeps its last good filters rather than opening up. Routes are checked against GOpenCNR's own RPKI and ASPA.
Closed prefixes
A holder can close a prefix to a named audience of other holders. Closed routes travel only through Tier 0's and certified hubs, only members of the audience hold the keys to reach them, and a hub that sees one leak cuts it at once.
On the record
Every registry change is signed by its holder and written to the one transparency log GOpenCSR keeps for the G Open registries. Endpoint addresses and audience members are never published: the log holds only their hashes.
Run with its members
GOpenCNR has its own Registry, Community and Operators Councils. New pools are created only by a motion of its Community Council, and certified hub operators hold seats on its Operators Council. Membership is free. An enterprise tier sells capacity and service, never safety.
Legal
Documents that govern GOpenCNR
Terms and privacy
What applies to everyone who uses it.
Security and trust
How to report a vulnerability, and how keys, signatures and certificates are handled.
Registry policies
Who may see registry and registration data, and how disputes over names are decided.
Governance
Who decides, how councils are elected and vote, and what is expected of the people on them.
Agreements
What operators, partners and customers agree to.