The fortified gate between the open internet and your edge.
CHERT Katula stands in front of your sites and devices — resolving their DNS, filtering their traffic, and carrying it through an authenticated tunnel to hardware that never has to face the internet directly. Your infrastructure, your keys, one console.
gate operational · self-hosted authoritative DNS · real TLS at the edge
Traffic never reaches your box until it has passed the wall.
Every request enters through Katula. It is resolved, inspected, and filtered at the edge, then handed to your ChertBox over a tunnel only Katula can open.
The open internet
Visitors, clients, and — inevitably — probes and attacks, all arriving at your public name.
inspect
CHERT Katula
Your own nameservers answer. The WAF and edge filter reject what shouldn't pass.
tunnel
Your ChertBox
No public IP. No open ports. Reachable only through the tunnel the gate holds open.
Six systems, one wall — run from a single control plane.
Self-hosted DNS
Your own authoritative nameservers, replicated across nodes. Every domain you serve resolves from infrastructure you control — no third party in the path.
Application firewall
The OWASP Core Rule Set enforced at the gate. Injection, cross-site scripting, and known exploits are blocked before they reach anything behind you.
Encrypted tunnels
Your box stays reachable without a public IP or a single open port. An authenticated tunnel carries traffic through the gate — and only an enrolled box can open one.
Fleet management
Provision, monitor, and update every box from one place. Configuration and inventory live in one source of truth — the whole fleet, one pane of glass.
Single sign-on
One identity across every console. Access is SSO-gated end to end, so the control plane is never left open to the world.
Full observability
Metrics, logs, and alerts across the whole edge. NOC and SOC views show exactly what your gate is doing — and warn you before it becomes a problem.
The gate is yours — not rented from someone else's cloud.
01 Your infrastructure
Katula runs on servers you own. DNS, certificates, and keys stay inside your perimeter — nothing critical to your name depends on a third-party edge.
02 Defense in depth
Edge filtering, a web application firewall, authenticated tunnels, and SSO stack in front of every box. An attacker has to pass all of it — not one shared front door.
03 Nothing exposed by accident
Boxes carry no public IP; consoles are never on the open internet. What faces the world is only what you deliberately put through the gate.
Put your edge behind the wall.
Bring your domains and your boxes; Katula becomes the gate in front of them.