Everything RyoProxy manages for you
The complete capability surface of the control plane, grouped by domain. Every entry below is implemented today, with the defaults and limits the platform actually ships.
- [domains]
- 11
- [capabilities]
- 84
- [source]
- implemented surface, not roadmap
Router fleet & agents
Every router runs a sidecar agent that dials out to the control plane, so a fleet of MikroTiks is managed from one screen without exposing a single management port.
Declarative RouterOS config
Router state is described once and reconciled continuously: preview the diff, apply it, and let the platform clean up whatever drifted.
PPPoE & IP rotation
Provision PPPoE lines in bulk and give each one a rotation schedule, a redial policy and a MAC strategy that survives a picky ISP.
Proxy provisioning
Turn each WAN into addressable HTTP and SOCKS endpoints, with credentials, NAT rules and exports handled by the platform.
Upstream forwarding
Route selected address ranges through external upstreams, with per-proxy DNS, pushed live state, and every change tracked as an operation.
WireGuard VPN
Hand out VPN access with per-client policy — expiry, LAN reach, and the exact WAN a client egresses through.
Routing, NAT & VLAN
The everyday network plumbing — VLANs, per-IP routes, DHCP, NAT and dynamic DNS — driven from the same place as everything else.
IP reputation & history
Know the reputation of every line before your customer does, and rotate a blocked IP automatically instead of at 3 a.m.
Access & hardening
Sessions, roles, scoped keys, encrypted credentials and graduated blocking, so a shared control plane stays a safe one.
Automation API
Rotation and status endpoints designed for scripts: one URL, no session, no SDK.
Monitoring & audit
Charts, audit trail and Telegram alerts that answer what changed and whether the fleet is still healthy, without an SSH session.