In progress GHub Creator and maintainer Open core 2026 - present

GOpenCNR / Gelhaus Open Community Network Registry

Your own addresses and ASN on a private network, routed through hubs and encrypted end to end.

A private overlay network run to registry discipline: globally unique private IPv6, IPv4 on request and ASNs from one registry, routed between members over WireGuard and BGP through hubs, encrypted end to end, with every filter and key generated from the registry.

What it is

GOpenCNR, the Gelhaus Open Community Network Registry, is a private network run like a registry. Members get globally unique private IPv6 space, IPv4 on request, and an autonomous system number from one registry, and their networks are routed to each other over WireGuard and BGP through hubs. It is for homelabs, self-hosters, learners and organisations whose sites should reach each other without being exposed to the public internet.

Addresses that are yours to use

Every allocation comes from GOpenCNR's own range, fdc0:0900::/24: a /56 for a person and a /48 for an organisation by default, and more on justification. Space and ASNs are allocated, never owned or sold. They stay yours for as long as you confirm them once a year and use them.

Encrypted end to end

Between agents, traffic is encrypted end to end. Hubs forward it without seeing inside, and they keep counters, not records of who talked to whom. Nothing leaves for the public internet: both ends of every packet are inside GOpenCNR or a named interconnect.

The registry is the truth

Every route filter, ROA, tunnel and firewall rule is generated from the registry and delivered as a signed bundle. Nothing is configured by hand on a hub, and a hub that cannot load fresh data keeps its last good filters rather than opening up. Routes are checked against GOpenCNR's own RPKI and ASPA.

Closed prefixes

A holder can close a prefix to a named audience of other holders. Closed routes travel only through Tier 0's and certified hubs, only members of the audience hold the keys to reach them, and a hub that sees one leak cuts it at once.

On the record

Every registry change is signed by its holder and written to the one transparency log GOpenCSR keeps for the G Open registries. Endpoint addresses and audience members are never published: the log holds only their hashes.

Run with its members

GOpenCNR has its own Registry, Community and Operators Councils. New pools are created only by a motion of its Community Council, and certified hub operators hold seats on its Operators Council. Membership is free. An enterprise tier sells capacity and service, never safety.