Development previewFeatures and availability may change while we test.
Back to products
Buyer decision aidReview approved

Compare public publish paths by boundary.

A sourced view of public reach, first use, origin networking, TLS handling, private routing, and lifecycle as verified on 2026-10-02.

Facts verified on

Publication status

Approved for publication

Which publish boundary fits the service?

Read each boundary and gap directly. This page does not rank or declare a winner.

  1. Public reach

    Arivaran Beam Publish

    Beta

    With an already installed and enrolled agent, the reviewed Beta publish command can request a public HTTPS URL.

    Recorded runs on clean Linux machines (July and October 2026), a clean Windows 11 machine (October 2026) and a clean Apple silicon Mac (5 October 2026) went from install to a fetched public URL and back down.

    Beam Publish setup guide

    Tailscale Funnel

    Available

    Tailscale Funnel shares a local service over the public internet with tailscale funnel and a target.

    Serve is the separate command for access limited to a tailnet. This fact does not infer plan, SLA, or platform eligibility.

    tailscale funnel command

    NetBird Reverse Proxy

    Beta

    NetBird Reverse Proxy exposes a peer or network resource through a public domain without opening ports on the target machine.

    NetBird labels Reverse Proxy beta. Self-hosted deployments require the supported Traefik TLS-passthrough setup.

    Reverse Proxy
  2. First-use path

    Arivaran Beam Publish

    Beta

    On Linux and macOS, first use is the published install command, an agent sign-in, and then aasetup publish localhost:3000. On Windows, the signed installer replaces the install command.

    On 2026-10-02 get.arivaran.ai resolved and served its install page. Linux, Windows and, since 2026-10-05, macOS on Apple silicon each have a recorded install-to-URL run. Publishing without an account needs an invite and an emailed code.

    Beam Publish setup guide

    Tailscale Funnel

    Available

    The official example uses tailscale funnel localhost:3000.

    Funnel accepts several target types and restricts public listening to documented ports.

    tailscale funnel command

    NetBird Reverse Proxy

    Beta

    The official temporary-service example uses netbird expose 8080.

    The ephemeral service lives only while the command runs. Dashboard services have a separate lifecycle.

    Reverse Proxy
  3. Origin network path

    Arivaran Beam Publish

    Beta

    The installed agent dials outward for the Beta publish path, so the origin does not open an inbound port for the public visitor.

    Recorded runs on clean Linux, Windows and Apple silicon macOS machines in October 2026 published through this outbound path.

    Beam Publish setup guide

    Tailscale Funnel

    Available

    Tailscale Funnel shares a local service over the public internet with tailscale funnel and a target.

    Serve is the separate command for access limited to a tailnet. This fact does not infer plan, SLA, or platform eligibility.

    tailscale funnel command

    NetBird Reverse Proxy

    Beta

    NetBird Reverse Proxy exposes a peer or network resource through a public domain without opening ports on the target machine.

    NetBird labels Reverse Proxy beta. Self-hosted deployments require the supported Traefik TLS-passthrough setup.

    Reverse Proxy
  4. TLS and provider visibility

    Arivaran Beam Publish

    Beta

    Publishing where the relay cannot read your traffic is an opt-in route that runs in production, and that route cannot ask visitors to sign in. A plain browser rejects its certificate unless the visitor checks the fingerprint the agent prints.

    The default publish, invite publishes, and every publish with visitor sign-in or address rules let the relay terminate TLS and read HTTP, so they are not provider-blind.

    Beam Publish setup guide

    Tailscale Funnel

    Available

    Tailscale documents automatic HTTPS certificates and default TLS termination by the node's Tailscale daemon.

    No broader provider-visibility conclusion is inferred from that statement.

    tailscale funnel command

    NetBird Reverse Proxy

    Beta

    HTTP mode terminates TLS at the proxy and can enforce browser authentication; TLS mode uses SNI routing and passes encrypted traffic through.

    Layer 4 modes do not support browser or header authentication because there is no HTTP layer.

    Reverse Proxy
  5. Private-network routing

    Arivaran Beam Publish

    Unavailable

    This evidence does not establish Beam as a general buyer-operated subnet-routing or exit-routing product.

    Admin-approved subnet routes and exit nodes exist in early form and are not yet shown across platforms. Choose a private-network product when subnet routes, exit nodes, and broad overlay administration are the primary job.

    Arivaran product-site information architecture

    Tailscale Funnel

    Available

    Tailscale supports subnet routers for reaching private subnets and devices that do not run the client.

    Exit nodes are a separate routing role for internet-bound traffic.

    Subnet routers

    NetBird Reverse Proxy

    Available

    NetBird Networks maps private resources into the overlay through routing peers with access denied until policy allows it.

    Exit-node use remains under the separate Routes model.

    Networks
  6. Lifecycle and maturity

    Arivaran Beam Publish

    Beta

    A free publish is public to anyone with the URL and stops after 300 seconds of idle time.

    Paid and operator-configured limits differ. The free tier allows three publishes at once and 600 requests a minute; an invite publish allows one, ending when its grant of at most two hours expires.

    Beam Publish setup guide

    Tailscale Funnel

    Available

    A Funnel started with --bg resumes after a device or Tailscale restart; foreground mode must be restarted manually.

    The operator can turn a configured Funnel off with the matching command and off argument.

    tailscale funnel command

    NetBird Reverse Proxy

    Beta

    CLI expose is temporary, while a saved service can be enabled or disabled without deleting its configuration.

    Availability remains beta and deployment prerequisites vary between cloud and self-hosted clusters.

    Reverse Proxy

Sources and review boundary

Each fact links to its source and shows the date it was checked. If a required fact is out of date or missing, it is not shown.

Third-party names belong to their respective owners. Product and legal or trademark review are pending, so these pages are not yet approved for production.

Release-ready. Saved on this browser.