Same colleague. Same pipeline. Three places the console lives.
The appliance in the rack is the product. Editions answer a compliance question — who may see management traffic — not a feature question. CoNetworked leases the appliance; it is pre-provisioned before it ships. You do not license-key a VM, and you do not get root.
At a glance
| Cloud | Private | Dark | |
|---|---|---|---|
| Who it is for | Sites that can use a hosted console | Data-residency or internal-only policy | Air-gapped, classified, NERC/CIP, SCADA |
| EvoConsole | CoNetworked cloud | Your datacenter | On the appliance |
| How the site reaches management | Outbound only — no inbound ports | Internal; optional maintenance window | Never on the internet |
| Updates | Signed package; apply or schedule in the console | Signed package in a maintenance window | Signed package on offline media |
| Support | Remote | Remote + a window | Sanitized diagnostic bundle + on-site SLA |
| Sign-in | Hosted accounts | Directory or local | Local accounts only |
The orchestrator, the change pipeline, and Evo are the same binary and the same behaviour. What changes is where the console and the message path run.
Cloud edition
Closest to the familiar “controller in the cloud, gear on site” shape. Administrators open EvoConsole in the browser; the appliance dials out, so firewalls and NAT do not need a hole punched inward.
If the WAN drops, local DHCP and DNS keep serving and queued intent delivers when the path returns. You manage the network, not the appliance OS.
Private edition
The console sits in your datacenter or private cloud. Nothing about an approved change is different — what is different is that management traffic never has to leave your perimeter.
Remote support from CoNetworked happens on your terms: typically a maintenance VLAN or jump host during an agreed window.
Dark edition
The entire stack runs on the appliance. There is no cloud to call — the “controller” is the box in the rack, reached by an internal hostname. No internet, by design. Inference stays local.
Plug in signed media, Evo verifies the signature, asks apply now / wait / schedule, and applies it. The seal does not loosen because the site is air-gapped. It tightens.
One signed package format. One verification step.
Unsigned or tampered media is refused before anything is unpacked. Evo executes the update with its own privilege — there is no wizard of commands for an operator to retype.
Every edition ships as a hardware-bound lease
Customers administer systems connected to EvoEther. They do not administer EvoEther as a platform — the Meraki-shaped ownership model, pointed at DHCP, DNS, IPAM, and the switching layer you already run.
- 1CoNetworked builds and provisions the appliance.
- 2The license is tied to that machine. Term starts at first power-on.
- 3Runtime validation does not need the internet.
- 4Board failure is an RMA, not a forfeited lease — term transfers to the replacement.
- 5End of term: data wiped to a published standard; renew or return.
Start from the compliance question, not the feature list
The features do not fork. If you are unsure, this is the decision.
Choose Cloud
if the constraint is time-to-value and outbound HTTPS is allowed.
Choose Private
if the constraint is “management plane stays inside.”
Choose Dark
if the constraint is “nothing leaves the building, including questions about the network.”
Not sure which edition fits?
Tell us your compliance constraints and we will map them to Cloud, Private, or Dark.