EVIDENCE-PENDING PREVIEW
Still allowlisting IP and MAC addresses in the age of AI?
AI makes address spoofing cheap. Beam makes trust hardware-bound.
Stop treating an address—or a copyable certificate file—as an identity.
Beam Publish
BetaThe diagram shows the mechanism, its current result, and the limit that remains in force.
Step 1 of 3Enrollment and mTLS survive address churn
An endpoint keeps its enrolled identity and active mTLS credential while DHCP, NAT, or interface addresses change. Route and locality decisions remain configuration-specific and require their own current evidence.
Step 2 of 3Stable identity, separately gated path
An address change does not rename the enrolled endpoint. The consuming product keeps its own policy, while stronger membership and locality outcomes remain separate evidence gates.
Step 3 of 3Evidence boundary
Stronger membership and locality-authorization outcomes remain production-dark pending #19093, #19094, #19112–#19115, and accepted activation evidence in #19095.
Mechanism
An endpoint keeps its enrolled identity and active mTLS credential while DHCP, NAT, or interface addresses change. Route and locality decisions remain configuration-specific and require their own current evidence.
Platform state
Publish is beta and public distribution is not implied by in-tree command and service code.
Evidence boundary
Stronger membership and locality-authorization outcomes remain production-dark pending #19093, #19094, #19112–#19115, and accepted activation evidence in #19095.
Before you start
Accepted installer and activation, abuse controls, domain and certificate ceremony, package distribution, and operator acceptance.
Evidence reviewed 2026-08-26