fleetmesh connects independent relays into an accountable federation. Relays coordinate through published budgets, cryptographic receipts, zero-knowledge verifiable compute, and declarative orchestration manifests. The protocol builds on established W3C, IETF, and Nostr standards.
Foundations · Core Principles
fleetmesh provides relay operators with verifiable resource bounds while preserving independent local policies.
The mesh evaluates protocol compliance through verifiable arithmetic. Rate limits and sync rules follow explicit contracts. Content moderation remains local to each edge relay face.
Nodes publish signed grant budgets (kind 30801). Peers exchange monotonic receipt hash chains (budget/1.0) to confirm transfer volumes.
Nodes retain complete control of stored data upon joining or leaving the federation. Shard synchronization uses NIP-77 Negentropy range bisection to prevent duplicate transfers.
Protocol compatibility is determined by the SHA-256 digest of published JSON schemas. Nodes with matching schema digests peer directly across the network.
Interoperability · Standards Architecture
fleetmesh builds upon established IETF, W3C, and Nostr specifications to provide transport, identity, replication, and compute.
| Standard / Specification | Category & Footing | Implementation Role in fleetmesh | Specification Anchor |
|---|---|---|---|
| W3C DID Core & did:nostr | W3C Recommendation | Node identity resolution without DNS or central registries. Generates standard DID documents. | Spec § Identity |
| DIDComm Messaging v2 | DIF Specification | Bilateral private messaging with ECDH-1PU and ECDH-ES envelope authentication. | Spec § Control plane |
| BIP-340 & Schnorr Signatures | Bitcoin Standard | secp256k1 x-only pubkeys signing descriptors, grants, reports, and delivery envelope hops. | Spec § Multi-key identity |
| RFC 5869 (HKDF) | IETF RFC Standard | Extract-and-expand key derivation for blinded pair grant identifiers (d tags). |
Spec § Blinded tags |
| FIPS 140-3 Analysis | Enterprise / NIST | Full cryptographic inventory showing approved symmetric layers and sovereign relay edge isolation. | Design Note: FIPS 140 |
| iroh (QUIC) | Modern Decentralized | Direct P2P UDP connections with automatic hole punching through NAT and firewalls. | Spec § Transports |
| libp2p gossipsub | Modern Decentralized | Peer discovery and descriptor swarm propagation via topic /fleetmesh/announce/1. |
Spec § Discovery |
| NIP-59 / NIP-44 (Gift Wrap) | Nostr Protocol | Universal fallback transport over standard relays: kind 21059 live and 1059 store-and-forward. | Spec § Nostr binding |
| TLS 1.3 & WebSocket (wss://) | IETF / Web Standard | Standard public relay faces terminated behind Caddy or Nginx reverse proxies. | Guide: Running a Node |
| NIP-77 (Negentropy) | Nostr Protocol | Range bisection set reconciliation; syncs thousands of events in kilobytes of fingerprints. | Spec § Replication |
| Blossom Media Protocol | Nostr Protocol | SHA-256 content-addressed blob storage integration with bilateral transfer metering. | Spec § Blossom |
| Signed Hop Delivery Envelopes | fleetmesh Normative | Multi-hop forwarding with cryptographic hop signatures (fleetmesh/hop/1) to prevent evasion. |
Spec § Delivery envelopes |
| JSON Schema (Draft 2020-12) | IETF Standard | Formal schemas for every event kind, DIDComm payload, manifest, and decrypted payload. | Schema Browser |
| AIMD Rate Windows | Internet Congestion | Additive Increase, Multiplicative Decrease rate control tailored for bilateral relay capacity. | Spec § Window arithmetic |
| NIP-85 & NIP-66 Projections | Nostr Protocol | Projects relay scores (kind 30385) and face capabilities (kind 30166) to standard clients. | Spec § Projections |
| Kubernetes CRDs & Declarative YAML | Cloud Native / OCI | Declarative manifests (fleetmesh.org/v1alpha1), consumed by meshnode init --manifest; live reconciliation and multi-target export are specified, not yet shipped. |
Spec § Operator surface |
| WASI (WebAssembly System Interface) | Bytecode Alliance / W3C | Deterministic sandbox execution for buyer compute requests with fuel-bounded isolation. | Spec § Compute market |
| Groth16 zk-SNARKs (alt_bn128) | Zero-Knowledge Proofs | Non-interactive zero-knowledge verification for WASM and arithmetic circuits without plaintext leakage. | Spec § Verification |
| Non-Deterministic AI & Compute-Over-Data | Distributed AI / WASI | LLM inference (vLLM/Ollama), Bacalhau batch jobs, and ReAct agent workflows under 4 declared verification modes. | Spec § Compute market |
| Bitcoin Lightning Network (L402) | Payment Layer | Trustless micropayment settlement for compute fuel and asymmetric rate capacity. | Spec § Settlement |
| NIP-61 (Nutzaps / Cashu) | Chaumian Ecash | Sub-satoshi ecash settlement for fine-grained transit and compute verification. | Spec § Settlement |
| NIP-47 (Nostr Wallet Connect) | Nostr Protocol | Automated client-authorized Lightning payment delegation for autonomous node and agent settlement. | Spec § Settlement |
Architecture · Network Topology
fleetmesh supports heterogeneous network roles. Dedicated servers provide backbone routing, local relays peer directly over QUIC, and client applications sync lightweight shards.
Backbone mesh infrastructure. Provides DIDComm mediation for firewalled nodes, publishes regular liveness heartbeats (kind 21801), routes gossipsub topics, and maintains high-capacity bilateral grants.
Community relays. Connects to peers via direct QUIC hole punching, stores authoritative shard data (kind 30803), and participates in bilateral NIP-77 range reconciliation.
Client applications and personal relays. Connects through outbound WebSockets, maintains a bounded local cache, and requires no public inbound ports.
Economics · Bilateral Rate Accounting
Transfer rates are governed by published signed grants, monotonic receipt hash chains, and deterministic remedy schedules.
Remedies for protocol non-conformance follow predefined contractual actions:
| Severity | Condition | Wire Evidence | Deterministic Remedy |
|---|---|---|---|
| S0 · Drift | Traffic within 110% of limits with matching receipts. | Receipt hash chain links. | Clean window period; limits increase along the AIMD schedule. |
| S1 · Overrun | Volume exceeds grant limits with accurate reporting. | Signed receipts referencing the grant. | Capacity halved; private notification sent over complaint/1.0. |
| S2 · Misreport | Receipt counters diverge from measured traffic. | Divergent signed receipts or traffic logs. | Peer moved to probation; public report (kind 30802) published. |
| S3 · Abuse | Traffic outside granted shard filters or malformed frames. | Malformed envelopes or out-of-filter events. | Grant suspended for 24 hours; adverse kind 30802 published with evidence. |
| S4 · Malice | Invalid signatures, corrupted hash chains, or identity spoofing. | Cryptographic signature verification failure. | Peering revoked; active grants deleted; permanent adverse attestation recorded. |
Compute · Execution Fabric & AI Routing
Nodes exchange compute requests over private DIDComm channels, settling jobs through Bitcoin Lightning (L402) or Cashu ecash.
Compute asks (kind 30810) specify fuel limits, target runtime engines, and bid prices.
Payloads and execution parameters are encrypted end-to-end between client and executor over compute/1.0.
Job receipts (kind 30811) use blinded identifiers to maintain confidential execution records.
zk-verify-groth16 verifying zero-knowledge proofs over alt_bn128.Compute asks specify an agreed verification mode prior to job execution:
proof
Zero-Knowledge Verification: Groth16 proof validated against public input digests.
schema-bounds
Syntactic Grammar: Output validated against Draft 2020-12 JSON Schema or grammar rules.
tee-attestation
Hardware Enclave: Hardware signature (NVIDIA CC, AMD SEV-SNP) over model, inputs, and outputs.
quasi-deterministic
Multi-Executor Consensus: Greedy T=0 decoding compared across a 2-of-3 executor quorum.
delivery
Accountable Sealing: Preimage delivery verification with out-of-band evaluation.
Roadmap · Ten Rollout Waves
fleetmesh follows ten structured rollout waves. Each wave delivers an independent capability tested against peer traffic before interface constants freeze.
NIP-77 range-bisection synchronization inside the relay face and event store. Sub-kilobyte range fingerprinting prevents redundant event transfers.
Gateway architecture with dedicated key namespaces and quota limits. Automated boundary tests prevent accidental data leakage.
W3C DID Core, did:nostr resolution, NIP-11801 multi-key descriptors (secp256k1, X25519, Ed25519), and NIP-11802 key revocation.
DIDComm Messaging v2 with ECDH-1PU authentication, authenticated NIP-59 gift-wrap fallback, and firewall traversal.
Kind 30801 published budgets, monotonic receipt hash chains (budget/1.0), AIMD schedules, and the deterministic S0–S4 Severity Ladder.
Direct Iroh QUIC with automatic UDP hole punching, libp2p gossipsub discovery, and WebSocket TLS fallback.
The 40-subcommand meshnode daemon, declarative fleetmesh.org/v1alpha1 manifest suite, meshwatch monitoring, and signed npack packages.
Mediated leaf profiles, QR-paired client links, background push synchronization, and bounded local storage for mobile runtimes.
WASI execution runtime, Groth16 zk-SNARK verification, signed asks and receipts, and multi-rail payment settlement.
vLLM and Ollama LLM routing, Bacalhau compute-over-data, autonomous ReAct loops, and streaming QUIC compute/1.1.
Tooling · Operator & Developer Suite
Tools to deploy, peer, test, monitor, and settle network nodes. The reference implementation runs under Python 3.12 without external runtime dependencies.
Kubernetes-style resources under apiVersion: fleetmesh.org/v1alpha1: MeshNode, Peering, GrantPolicy, ComputeProvider, InferenceRouter. Schema-checked against the normative constants and consumed by meshnode init. The standalone meshctl CLI (built in Rust) provides production declarative manifest management, non-destructive hot-reconciliation, and multi-target compilation.
meshnode init --manifest meshnode.yaml
The core 40-subcommand daemon in node/. Manages keys, relay endpoints, rate windows, peering grants, and the local UNIX control socket.
python3 -m node.meshnode --help
Autonomous monitoring daemon in node/watch.py. Audits connections, storage integrity, and rate limits, returning exit codes 0, 1, or 2 for monitoring systems.
python3 -m node.meshnode watch
Bidirectional bridge in node/bridge.py connecting the mesh with standard Nostr relays. Routes topic shards and backfills historical events.
meshnode bridge sync --relay ...
Local testnet simulator in node/cluster.py. Launches multi-node topologies to validate synchronization and peering.
meshnode cluster start --nodes 5
Payment daemon in node/settlement/. Manages escrows and micropayments across Bitcoin Lightning, Cashu ecash, and Nostr Wallet Connect.
meshnode settle nwc-pay --amount 5000
Step through live deployment commands or author declarative manifests:
# 1. Initialize node directory, keys, and self-signed descriptor
python3 -m node.meshnode init /var/lib/meshnode \
--operator <your-pubkey> \
--class edge \
--relay wss://relay.example.org \
--endpoint wss=wss://mesh.example.org:443 \
--face-port 7777
Need production reverse-proxy (Caddy) and systemd daemon configurations?
Read the Operator Manual →Architecture · Design Notes & Deep Dives
Explore the reference implementation, capacity model, protocol economics, and cryptographic compliance behind fleetmesh.
Architectural overview: distributed compute, shard replication, and protocol resilience.
The 17 core reference node compartments plus up to 6 optional (p2p, gossip, compute, bridge, dvm, updates), typed contracts, SQLite storage models, wire stack, and bilateral accounting loop.
Deployment setup, reverse proxy configuration, 40 CLI commands, systemd service units, and troubleshooting checklist.
The 3-rung load-shedding ladder (Rungs 0–2) and directional strain ledger to maintain reliability under load.
Why fleetmesh settles discrete retrieval requests rather than charging continuous storage rent.
How published budgets and receipt chains establish measurable trust weighting across the mesh.
How fleetmesh compares to the Free Internetworking Peering System (FIPS): packet routing and relay federation.
Algorithm evaluation against the NIST approved list, isolating non-approved signature curves at sovereign edges.
The fleetmesh protocol rendered in ten glass emblems: identity, topology, replication, reputation, and compute.