Scope
Protocol Scope & Architecture Principles
fleetmesh is an alpha, permissionless relay network open to arbitrary hardware.
Participants can run nodes on dedicated servers, virtual machines, Raspberry Pis, laptops, or mobile phones.
It maintains independent governance, distinct branding, and its own protocol namespace at fleetmesh.org.
The system is engineered as an open standard with zero dependence on any single commercial entity or hosted provider.
Four requirements shape everything below.
- Two networks, one boundary. The mesh and any private or commercial relay backends share no database, no message bus, no secrets and no identity. They meet at a single gateway that speaks ordinary relay protocol. Either side can be switched off without the other noticing. § Two networks is that boundary in detail.
-
Uses, does not rely on.
relay.example.orgappears in this specification solely as an illustrative example. No bootstrap host, DNS domain, or single operator is a hardwired constant. The conformance suite includes an automated test that removes all default bootstrap nodes and verifies that the mesh continues operating. - A phone is a full node. It holds an independent cryptographic identity, retains a local copy of subscribed data, and earns standing in the reputation system. It operates with intermittent uptime and no inbound public connectivity. A design requiring public IP addresses and TLS certificates is a server federation rather than a mesh.
- Standards where they exist. Node identity is a W3C DID. Node-to-node negotiation is DIDComm v2, using registered protocols wherever one already covers the job. Transport is iroh and libp2p. Content addressing is multihash/CID. New wire formats appear only where nothing suitable exists, and each is called out as such.
The mesh is currently in alpha status. Kind numbers, wire formats, and scoring constants will evolve. Reputation findings gathered during alpha are discarded at general availability rather than carried forward. The core promises in § Alpha contract remain invariant: joining the mesh never risks existing local data, and leaving requires only a single configuration flag.
MUST, SHOULD and MAY are used per RFC 2119. A node is a mesh participant identified by a DID. A peer is a node another node holds an active grant with. The subject of a grant is the node it constrains; the issuer published it and will enforce it. The platform means any private backend or hosted cluster; fleetmesh, or the mesh, means this network. An anchor node is a public gateway or routing point, and has no protocol privilege of any kind.
Explicitly out of scope
Custodial signing is permanently out of scope. A service that holds encrypted user keys alongside their unlocking secrets is a custody service. Replicating that state to unknown nodes converts it into an unauthorized key-distribution channel. The same exclusion applies to billing records, push notification subscriptions, and account credentials. The full boundary specification and enforcement mechanisms are detailed in § Two networks.
Payment for transit is also out of scope, deliberately and with a rule attached rather than
a shrug — see § Grants & receipts. The schema reserves a
settlement object so a later version can add it without a breaking change, and
nothing else here depends on it.
Hardware-attested execution is refused rather than deferred. Trusted execution environments are the only practical way to hide a job's input from the node running it, and every one of them terminates in a remote attestation signed by a hardware vendor's root key. A protocol whose confidentiality guarantee resolves to Intel or AMD vouching for an enclave has an authority, and § Governance has none by construction — no registry, no release manager, no host anyone must reach. It would also contradict a node class that runs on a phone. Confidentiality here therefore means confidential from third parties, and verifiability is what constrains the executor; see § Compute market.
Why join
Operational Advantages Over Standalone Relays
Operating a standalone relay isolates an operator from shared threat intelligence, single-disk storage risks, and NAT traversal challenges. Participating in fleetmesh provides collaborative network capabilities without requiring centralized infrastructure:
Operational expectations: Fleetmesh provides no managed service level agreements, custodial signing, or centralized billing. Participating nodes agree to publish valid accounting receipts, honor active bilateral grants, and address disputes prior to report publication.
Node classes
Three Operational Node Classes
Connectivity constraints determine node classification. Single-board computers can host full relay services but lack public inbound listeners behind firewalls. Mobile devices retain keys and local data caches but pause network sockets during background execution. A node declares its operational role in its signed descriptor, establishing capability bounds across the protocol.
No special class exists for founding operators. Gateways and public relays declare anchor under identical terms as any other node. The protocol defines no privileged keys, reserved names, or administrative constants. Anchor trust derives entirely from accumulated history across verified accounting windows.
Leaf
phone · browser · laptop
Stores local author data and requested feeds. Operates in the foreground over a single WebSocket to its mediator.
- MUST NOT be cited by another node as a source of record
- MUST route through a mediator; no inbound listener, no p2p stack
- Subject of grants only — does not issue grants, publish reports, or forward hops
- Publishes no coverage claims
Edge
raspberry pi · home server · nas
Provides durable local storage with high availability behind NAT. Suitable for community, household, or organization deployments.
- MUST hold every event within its declared coverage, or narrow the claim
- SHOULD reach peers by hole punching; MAY fall back to an anchor as transit
- MAY mediate for leaves it has granted
- Runs the sqlite store; Postgres is not required
Anchor
vps · public ip · tls
Stable wss:// endpoint, valid certificate, and continuous availability. Provides rendezvous routing and mediation across the network.
- MUST serve NIP-11 over HTTPS and accept anonymous reads within policy
- MUST act as a DIDComm mediator for at least its own granted leaves
- SHOULD offer itself as circuit relay / iroh relay for hole punching
- MUST publish a kind 21801 heartbeat at least hourly — liveness, not attestation: § Grants & receipts forbids publishing a positive report
The leaf profile and mobile operational limits
Mobile operating systems enforce strict background constraints. iOS terminates background sockets upon screen lock, blocks background hole punching, and limits silent push execution to thirty seconds. Android Doze imposes equivalent restrictions.
wss:// connection to its mediator. Leaves do not negotiate dynamic transport ladders because upper rungs do not survive mobile background execution.
routing/2.0 and signals new traffic via Web Push (VAPID). Wake windows operate on a best-effort basis: brief execution windows perform range reconciliation, while offline intervals catch up upon the next application launch.
Browser progressive web applications share the leaf operational profile. WebRTC and direct browser-to-browser peering remain future roadmap items compatible with this baseline.
A peer observing a node failing its declared class obligations files an S2 report. Examples include an anchor whose public endpoint fails to resolve, or an edge returning empty queries within its claimed coverage. Overstating capabilities is a misreport, which the protocol prices under the severity ladder.