Fleetmesh fleetmesh

The fleetmesh Protocol · part 1 of 10

Overview

Protocol definition, operational incentives, and the three node classes.

Scope

Protocol Scope & Architecture Principles

fleetmesh is an alpha, permissionless relay network open to arbitrary hardware. Participants can run nodes on dedicated servers, virtual machines, Raspberry Pis, laptops, or mobile phones. It maintains independent governance, distinct branding, and its own protocol namespace at fleetmesh.org. The system is engineered as an open standard with zero dependence on any single commercial entity or hosted provider.

Four requirements shape everything below.

  • Two networks, one boundary. The mesh and any private or commercial relay backends share no database, no message bus, no secrets and no identity. They meet at a single gateway that speaks ordinary relay protocol. Either side can be switched off without the other noticing. § Two networks is that boundary in detail.
  • Uses, does not rely on. relay.example.org appears in this specification solely as an illustrative example. No bootstrap host, DNS domain, or single operator is a hardwired constant. The conformance suite includes an automated test that removes all default bootstrap nodes and verifies that the mesh continues operating.
  • A phone is a full node. It holds an independent cryptographic identity, retains a local copy of subscribed data, and earns standing in the reputation system. It operates with intermittent uptime and no inbound public connectivity. A design requiring public IP addresses and TLS certificates is a server federation rather than a mesh.
  • Standards where they exist. Node identity is a W3C DID. Node-to-node negotiation is DIDComm v2, using registered protocols wherever one already covers the job. Transport is iroh and libp2p. Content addressing is multihash/CID. New wire formats appear only where nothing suitable exists, and each is called out as such.
Alpha

The mesh is currently in alpha status. Kind numbers, wire formats, and scoring constants will evolve. Reputation findings gathered during alpha are discarded at general availability rather than carried forward. The core promises in § Alpha contract remain invariant: joining the mesh never risks existing local data, and leaving requires only a single configuration flag.

Terminology

MUST, SHOULD and MAY are used per RFC 2119. A node is a mesh participant identified by a DID. A peer is a node another node holds an active grant with. The subject of a grant is the node it constrains; the issuer published it and will enforce it. The platform means any private backend or hosted cluster; fleetmesh, or the mesh, means this network. An anchor node is a public gateway or routing point, and has no protocol privilege of any kind.

Explicitly out of scope

Custodial signing is permanently out of scope. A service that holds encrypted user keys alongside their unlocking secrets is a custody service. Replicating that state to unknown nodes converts it into an unauthorized key-distribution channel. The same exclusion applies to billing records, push notification subscriptions, and account credentials. The full boundary specification and enforcement mechanisms are detailed in § Two networks.

Payment for transit is also out of scope, deliberately and with a rule attached rather than a shrug — see § Grants & receipts. The schema reserves a settlement object so a later version can add it without a breaking change, and nothing else here depends on it.

Hardware-attested execution is refused rather than deferred. Trusted execution environments are the only practical way to hide a job's input from the node running it, and every one of them terminates in a remote attestation signed by a hardware vendor's root key. A protocol whose confidentiality guarantee resolves to Intel or AMD vouching for an enclave has an authority, and § Governance has none by construction — no registry, no release manager, no host anyone must reach. It would also contradict a node class that runs on a phone. Confidentiality here therefore means confidential from third parties, and verifiability is what constrains the executor; see § Compute market.

Why join

Operational Advantages Over Standalone Relays

Operating a standalone relay isolates an operator from shared threat intelligence, single-disk storage risks, and NAT traversal challenges. Participating in fleetmesh provides collaborative network capabilities without requiring centralized infrastructure:

reverse-reputation spam control
Standalone relays evaluate traffic solely from local observations. Within the mesh, public key behavior includes cryptographically signed evidence from peer operators. Each node weights reports according to local subjective trust without importing external blocklists. Every restriction links to a verifiable grant and reproducible evidence.
redundant data availability
Peers asserting shard coverage retain synchronized event copies. Hardware failures do not cause data loss, enabling rapid partition recovery through state reconciliation.
traversal behind NAT
Direct hole punching combined with DIDComm mediation provides addressability for residential and edge nodes without dedicated static public IP addresses.
efficient state reconciliation
NIP-77 range reconciliation synchronizes disconnected nodes using compact fingerprint trees, avoiding redundant event streaming.
independent telemetry
NIP-66 monitors publish objective availability metrics and latency records, validating node uptime from external vantage points.
content-addressed blob availability
Content-addressed blobs replicate across peers and map to IPFS CIDs, enabling independent archival and retrieval across standard tooling.

Operational expectations: Fleetmesh provides no managed service level agreements, custodial signing, or centralized billing. Participating nodes agree to publish valid accounting receipts, honor active bilateral grants, and address disputes prior to report publication.

Node classes

Three Operational Node Classes

Connectivity constraints determine node classification. Single-board computers can host full relay services but lack public inbound listeners behind firewalls. Mobile devices retain keys and local data caches but pause network sockets during background execution. A node declares its operational role in its signed descriptor, establishing capability bounds across the protocol.

No special class exists for founding operators. Gateways and public relays declare anchor under identical terms as any other node. The protocol defines no privileged keys, reserved names, or administrative constants. Anchor trust derives entirely from accumulated history across verified accounting windows.

ANCHOR EDGE LEAF bootstrap anchor anchor anchor anchor gateway · no privilege VPS · wss + TLS VPS · wss + TLS VPS edge edge edge Raspberry Pi · NAT home server · NAT mini VPS phone browser PWA laptop phone iroh QUIC · NIP-77 range sync · libp2p gossipsub hole-punched QUIC · wss:// when it fails DIDComm routing 2.0 through a mediator · WebRTC · wss://
Anchors form the core mesh with stable inbound addresses. Edges peer with anchors and other edges via hole punching. Leaves route through designated mediators. All anchor nodes operate under uniform protocol rules.

Leaf

phone · browser · laptop

Stores local author data and requested feeds. Operates in the foreground over a single WebSocket to its mediator.

  • MUST NOT be cited by another node as a source of record
  • MUST route through a mediator; no inbound listener, no p2p stack
  • Subject of grants only — does not issue grants, publish reports, or forward hops
  • Publishes no coverage claims

Edge

raspberry pi · home server · nas

Provides durable local storage with high availability behind NAT. Suitable for community, household, or organization deployments.

  • MUST hold every event within its declared coverage, or narrow the claim
  • SHOULD reach peers by hole punching; MAY fall back to an anchor as transit
  • MAY mediate for leaves it has granted
  • Runs the sqlite store; Postgres is not required

Anchor

vps · public ip · tls

Stable wss:// endpoint, valid certificate, and continuous availability. Provides rendezvous routing and mediation across the network.

  • MUST serve NIP-11 over HTTPS and accept anonymous reads within policy
  • MUST act as a DIDComm mediator for at least its own granted leaves
  • SHOULD offer itself as circuit relay / iroh relay for hole punching
  • MUST publish a kind 21801 heartbeat at least hourly — liveness, not attestation: § Grants & receipts forbids publishing a positive report

The leaf profile and mobile operational limits

Mobile operating systems enforce strict background constraints. iOS terminates background sockets upon screen lock, blocks background hole punching, and limits silent push execution to thirty seconds. Android Doze imposes equivalent restrictions.

one transport
wss:// connection to its mediator. Leaves do not negotiate dynamic transport ladders because upper rungs do not survive mobile background execution.
foreground networking, push to wake
The leaf synchronizes during active foreground execution. Its mediator buffers inbound messages under DIDComm routing/2.0 and signals new traffic via Web Push (VAPID). Wake windows operate on a best-effort basis: brief execution windows perform range reconciliation, while offline intervals catch up upon the next application launch.
pull-only, subject-only
A leaf publishes events for its local author and pulls requested content. It does not forward traffic, mediate for peers, issue grants, or file adverse reports. Its protocol scope centers on its bilateral grant from its designated mediator.
bounded storage
Local storage maintains a rolling window based on time or configured byte capacity across local events. Eviction operates by age rather than external request.
keys in the OS keystore
The node key resides in secure storage (iOS Keychain or Android Keystore) and remains separate from the personal social Nostr key. Accounting grants and reports evaluate node networking conduct rather than personal social identity.

Browser progressive web applications share the leaf operational profile. WebRTC and direct browser-to-browser peering remain future roadmap items compatible with this baseline.

Invariant

A peer observing a node failing its declared class obligations files an S2 report. Examples include an anchor whose public endpoint fails to resolve, or an edge returning empty queries within its claimed coverage. Overstating capabilities is a misreport, which the protocol prices under the severity ladder.