Development previewFeatures and availability may change while we test.

EVIDENCE-PENDING PREVIEW

Still allowlisting IP and MAC addresses in the age of AI?

AI makes address spoofing cheap. Beam makes trust hardware-bound.

Stop treating an address—or a copyable certificate file—as an identity.

BetaService publishing

Beam Publish

Beta

The diagram shows the mechanism, its current result, and the limit that remains in force.

  1. Step 1 of 3Enrollment and mTLS survive address churn

    An endpoint keeps its enrolled identity and active mTLS credential while DHCP, NAT, or interface addresses change. Route and locality decisions remain configuration-specific and require their own current evidence.

  2. Step 2 of 3Stable identity, separately gated path

    An address change does not rename the enrolled endpoint. The consuming product keeps its own policy, while stronger membership and locality outcomes remain separate evidence gates.

  3. Step 3 of 3Evidence boundary

    Stronger membership and locality-authorization outcomes remain production-dark pending #19093, #19094, #19112–#19115, and accepted activation evidence in #19095.

Mechanism

An endpoint keeps its enrolled identity and active mTLS credential while DHCP, NAT, or interface addresses change. Route and locality decisions remain configuration-specific and require their own current evidence.

Platform state

Publish is beta and public distribution is not implied by in-tree command and service code.

Evidence boundary

Stronger membership and locality-authorization outcomes remain production-dark pending #19093, #19094, #19112–#19115, and accepted activation evidence in #19095.

Before you start

Accepted installer and activation, abuse controls, domain and certificate ceremony, package distribution, and operator acceptance.

Evidence reviewed 2026-08-26

Release-ready. Saved on this browser.