Fleetmesh fleetmesh

details · system architecture & design notes · how fleetmesh is built and operated

System Details & Reference Architecture

fleetmesh connects Nostr relays into a federated mesh. This section documents system operation: the reference implementation (meshnode), subsystem compartments, wire protocols, the bilateral accounting engine, and supporting design notes.

Implementation Overview

The reference implementation in node/ is a typed Python daemon that runs alongside an existing relay to provide peering and accounting.

The daemon isolates execution into twenty core compartments, plus up to six optional ones (p2p, gossip, compute, bridge, dvm) the config enables, coordinates bilateral budgets over DIDComm v2, synchronizes events through Negentropy range reconciliation, and meters transfers with signed receipt hash chains.

Reference Architecture

The anatomy of a mesh node

The reference node is built around the executable specification in ref/. It runs under Python 3.12, requiring only the standard library and the cryptography package. Internal components adhere to typed protocols defined in node/interfaces.py.

Subsystems & Isolation

Explicit failure boundaries in node/subsystem.py prevent cascading faults.

Compartments
20 core compartments in tick order: link, trust, strain, peering, budget, capacity, sync, reporter, discovery, announce, lan, presence, retention, scheduler, settlement, mediation, blob_wire, blob_replication, paid_fetch, and sidecars. Up to 6 optional ones join the order when the config enables them: p2p after lan, gossip after p2p (before presence), compute and bridge after scheduler, dvm, then updates last - it reports on all the others. The list is held to node/app/core.py by scripts/check-cli.py.
Refusal Channel
Refusals record structured reasons (capacity, auth, rate, schema) in internal logs.
Contracts
Static typing and formal runtime protocols define clear boundaries between storage, sync, peering, and accounting.

State & Storage Model

Persistent storage across restarts and host reboots.

events.sqlite
Deduplicated event store with tag indexing, Negentropy ranges, and query support.
grants.sqlite
Active, pending, and historical peering grants.
accounts.sqlite
Meters per peer per window, receipt hash chains, and directional strain records.
control.sock
Local UNIX domain socket exposing the runtime command interface to operator tooling.

Transport & Wire Stack

Encrypted overlays across Nostr and TCP connections.

Identity
Multi-key binding: secp256k1 (nostr DID), X25519 (DIDComm agreement), and Ed25519 (transport signatures).
Overlay
Encrypted DIDComm v2 messages (kind 21059) routed through relays without open inbound ports.
Sync Face
Async relay server supporting NIP-01, NIP-11, and NIP-77 Negentropy reconciliation in delivery envelopes.

Bilateral Accounting

Bilateral coordination between peers without global consensus.

Grants
Kind 30801 published parameters defining request ceilings, event limits, and cadence.
Receipts
Signed, chained receipts issued on cadence, verified in the issuer frame.
Window Loop
AIMD window evaluation: clean windows expand limits; discrepancies trigger deterministic S0–S3 actions.

Compute & ZK Verification

Deterministic WASI and Groth16 zk-SNARK verification fabric.

Wasmtime / WASI
Sandboxed WebAssembly runtime in node/compute/executors/wasm.py with bounded fuel and fuel rate pricing.
Groth16 Verifier
Zero-knowledge proof verification over alt_bn128 in node/zk.py.
Order Book
Cryptographic ask and receipt pipeline over kinds 30810 and 30811 with encrypted payload delivery.

Multi-Rail Settlement

Micropayment rails and escrow settlement in node/settlement/.

Lightning (L402)
Preimage escrow and invoice settlement with BOLT11 payments.
Cashu Ecash
Chaumian ecash mint swaps and melts (NUT-04/05) for instant token settlement.
NWC (NIP-47)
Nostr Wallet Connect support for client-delegated automated settlement.

Declarative Orchestration

Declarative manifests and local testnet simulation.

Manifests
fleetmesh.org/v1alpha1 resources under manifests/, held to the constants by scripts/check-manifests.py and consumed by meshnode init --manifest. The standalone meshctl CLI (built in Rust) provides production declarative manifest management, non-destructive hot-reconciliation, and multi-target compilation (Kubernetes, Podman Quadlets, systemd, Compose).
Cluster Engine
Multi-node local testnet simulator in node/cluster.py configuring mesh, star, ring, and line topologies.
watch.py
Machine-readable invariant auditing daemon with exit codes 0, 1, and 2 for monitoring agents.

Universal Relay Bridge

Bidirectional ingress and egress across standard Nostr relays.

Ingress & Egress
Continuous subscription and delivery in node/bridge.py with cryptographic signature verification and provenance tracking.
Smart Shard Routing
Automatic detection and indexing of topic tags (#t) for local mesh replication.
Reconciliation
Range-bounded historical backfill (reconcile) over external WebSocket relays.

DVM Gateway & Projections

NIP-90 deterministic compute and NIP-32 client moderation integration.

NIP-90 Gateway
Translates compute requests (kinds 5000–5999) into sandboxed WASI jobs in node/dvm/, producing signed responses.
NIP-32 Labels
Adverse findings project kind 1985 moderation labels under fleetmesh.reputation (s1-divergence, s2-misreport, s3-overrun, s4-tamper).
NIP-85 Scores
Relay scores published as kind 30385 assertions referencing kind 30802 dispute evidence.

Technical Guides & Design Notes

In-depth implementation and design articles

live · read only · § Discovery · § Coverage · § Relay projection

The mesh, as it says it is

Every node publishes descriptors, heartbeats, and coverage claims as standard Nostr events. This page queries relays directly from the browser to display network topology, claims, and relay assertions without external servers.

Watch the mesh →

thesis · vision · § Compute layer · § Shard exchange · § Verifiable delivery · § Identity

The future of the mesh: why bilateral reputation relays matter

Architectural overview: verifiable transmission, shard replication, distributed compute escrow, cryptographic identity, and network resilience against sybil swarms.

Read the overview →

field guide · § Implementation · § Operator surface · § Conformance

Running a node and operator manual

Operational guide to node/meshnode: four-command setup, systemd service configuration, Caddy TLS reverse proxying, telemetry with meshwatch, the 40-command CLI reference, and troubleshooting procedures.

Read the operator guide →

subsystems · § Grants · § Capacity · § Strain ledger

Capacity management, load shedding & strain ledgers

How node/capacity.py manages capacity ceilings and executes a three-rung load-shedding ladder under peak pressure, and how node/strain.py tracks directional anomalies.

Read the capacity guide →

accounting · § Grants & receipts · § Severity ladder · § Trust weighting

Reverse reputation and receipt hash chains

Published bilateral budgets, receipt hash chains, and the deterministic five-step severity ladder (S0–S4). Includes an interactive simulator demonstrating convergence and sybil resistance.

Read the deep dive →

economics · § Grants · § Replication · § Settlement

Retrieval-based storage settlement

Why fleetmesh settles discrete retrieval requests rather than charging continuous storage rent, and how storage aligns with transit settlement.

Read the economic analysis →

standards · § Identity · § Cryptography · § FIPS 140-3

Cryptographic boundaries and FIPS 140-3 compliance

Audit of cryptographic algorithms in fleetmesh against NIST standards. Isolates non-approved curves at external relay edges to enable federal deployment compliance.

Read the compliance audit →

comparison · § Transports · § Discovery · § Overlay routing

fleetmesh and the Free Internetworking Peering System

Architectural comparison between fleetmesh and the FIPS overlay network: packet routing and application-level relay federation.

Read the network comparison →

visual overview · § Architecture · 10 Emblems

Protocol concepts in ten emblems

Core mechanisms of fleetmesh rendered visually: cryptographic identity knots, discovery lattices, Negentropy range reconciliation, reverse reputation, and the compute market.

View the concept emblems →

The formal rules and protocol schemas are codified in the fleetmesh Specification and the Schema Browser. These pages document operational rationale and reference code.