DNSControl
DNSControl is rewriting its record internals in public, one release candidate at a time
A side-by-side editorial comparison of Nebula and Ory Hydra — release velocity, themes, recent moves, and the top alternatives to consider.
Overlay network that rewrote its certificate format, then spent a year fixing what it exposed.
Nebula is a peer-to-peer mesh VPN built around a certificate authority model. The v1.10.0 release was the pivot: IPv6 and multiple addresses in the overlay, plus a new v2 ASN.1 certificate format with a unified interface for external implementations. Everything since has been consequence management — a P256 signature malleability issue that allowed blocklist bypass, a source-IP acceptance flaw tied to the new multi-address certificates, and a run of fixes around route tables and Windows listeners.
Hydra's 2.2 candidates rebuilt the OAuth2 flow store, then reached for verifiable credentials
Ory Hydra is a self-hosted OAuth2 and OpenID Connect server. Its visible release record is the v2.2.0 candidate series from 2023, which did two substantial things: rc.2 moved authorization-code flow state out of the database and into AEAD-encrypted cookies and request parameters, a change shipped with an explicit breaking-change notice; rc.3 then added initial OIDC verifiable-credential issuance and wired logout propagation into Ory Kratos. The feed stops at a v2.2.0-pre.1 tag in February 2024.
Nebula is a peer-to-peer mesh VPN built around a certificate authority model. The v1.10.0 release was the pivot: IPv6 and multiple addresses in the overlay, plus a new v2 ASN.1 certificate format with a unified interface for external implementations. Everything since has been consequence management — a P256 signature malleability issue that allowed blocklist bypass, a source-IP acceptance flaw tied to the new multi-address certificates, and a run of fixes around route tables and Windows listeners.
The project has moved from single-IPv4-per-node assumptions toward a genuinely flexible addressing model, and the security fixes since v1.10.0 map directly onto that change — the new certificate features widened what the code has to validate. v1.11.0 shifts attention to the operational surface instead: structured logging, corrected firewall reject-versus-drop semantics, and Windows WFP filters installed by default.
The stated plan to assert low-s signature form when validating certificates is the concrete next step visible in these entries; expect it to land as a breaking validation change in a future release.
Ory Hydra is a self-hosted OAuth2 and OpenID Connect server. Its visible release record is the v2.2.0 candidate series from 2023, which did two substantial things: rc.2 moved authorization-code flow state out of the database and into AEAD-encrypted cookies and request parameters, a change shipped with an explicit breaking-change notice; rc.3 then added initial OIDC verifiable-credential issuance and wired logout propagation into Ory Kratos. The feed stops at a v2.2.0-pre.1 tag in February 2024.
The through-line is reducing per-request database work in the hot authorization path — first by relocating flow state into encrypted client-side material, then by parallelizing JSON web key set generation and adding scope-claim strategies. Running underneath is tighter coupling to the rest of the Ory stack: the Kratos admin URL config and session-termination hook make Hydra less of a standalone component and more of one piece of an integrated identity suite. The verifiable-credentials work is the one thread pointing somewhere genuinely new, and it shipped against a draft specification.
The candidate series points toward a v2.2.0 general release consolidating the AEAD flow change and the credential-issuance work. The feed's silence after February 2024 gives no basis for judging when, or whether the draft-stage VC support advanced.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Nebula or Ory Hydra.
DNSControl is rewriting its record internals in public, one release candidate at a time
Fission's release feed carries only RC tags, and none of them say what shipped
Kaniko's release feed stops dead in June 2024 after a patch that undid its own change
mod_auth_openidc audited itself, found eight holes, and broke every session on the way out
Kubernetes CNI maintaining four release branches at once, mostly to carry CVE fixes back.
KeePass-compatible password manager frozen mid-patch-run since 2021.
See all Nebula alternatives → · See all Ory Hydra alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Nebula is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Nebula is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Nebula alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Nebula alternatives" section above for the current picks, or visit /alternatives/nebula-networking for the full list with editorial commentary on each.
Top Ory Hydra alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Ory Hydra alternatives" section above for the current picks, or visit /alternatives/ory-hydra for the full list with editorial commentary on each.