n0-computer/iroh
71.8
Strong · 29 September 2026
45.5k
lines of production code
Rust
primary language
2
measurements over time
What this system is
This system is a Rust-based networking library and infrastructure suite designed for decentralized, peer-to-peer communication using QUIC. It provides core components for establishing direct connections with NAT traversal, including a relay server for fallback connectivity and a DNS-based service for endpoint discovery and address resolution. The architecture supports pluggable transports, custom authentication hooks, and robust path selection to optimize network performance across varying conditions.
How it got here
2023–2024 — Iroh 1.3.0 workspace restructuring and relay modernization
22 changes.
The project reorganized into a multi-crate workspace targeting Rust 2024, introducing dedicated crates for DNS, relay, and base networking types. Significant architectural changes included replacing the legacy echo client with a modular Endpoint API, upgrading the relay protocol to v2 with WebSocket support, and implementing a new DNS server with DoH and Pkarr capabilities.
2025–2026 — Network transport and discovery refactoring
15 changes.
This period focused on restructuring the core networking stack by introducing pluggable address lookup services, configurable path selection, and custom transport support. Significant effort was dedicated to improving NAT traversal and connection resilience through dedicated actors for relay management and remote state, alongside comprehensive integration tests simulating complex network conditions.
Features
Add Dockerfiles for iroh-relay and iroh-dns-server
New Dockerfiles have been added to the repository to enable containerized deployment of the iroh-relay and iroh-dns-server components. The main Dockerfile builds these services from source using a multi-stage Rust build process, while a CI-specific Dockerfile allows for pre-built binaries. The images expose standard ports for HTTP/HTTPS, STUN (3478/udp), DNS (53/udp), and metrics (9090), allowing users to run these services in isolated environments.
docker · high confidence
Added test utilities for qlog emission and in-memory transport simulation
The test utilities module now includes support for generating qlog files during testing via the new \QlogFileGroup\ builder, which writes logs when the \qlog\ feature is enabled and the \IROH\_TEST\_QLOG\ environment variable is set. Additionally, a new in-memory test transport (\TestNetwork\ and \TestTransport\) has been added, allowing tests to simulate network communication between endpoints using internal channels instead of real network interfaces.
_iroh/src/test\utils · high confidence
HTTP server implementation with DoH, Pkarr, and TLS support
The HTTP server module in iroh-dns-server has been implemented to handle DNS-over-HTTPS (DoH) queries via GET and POST endpoints, allowing responses in either raw DNS message or JSON format. It introduces a Pkarr publishing endpoint for upserting signed packets and retrieving them by public key. The server supports configurable rate limiting (disabled, simple IP-based, or smart proxy-aware) and flexible TLS certificate management, including manual loading, self-signed generation, and automatic Let's Encrypt provisioning via ACME.
iroh-dns-server/src/http · high confidence
Initial release of iroh-dns crate
The iroh-dns crate is introduced to provide DNS-based endpoint discovery for Iroh, utilizing the pkarr signed packet format for publishing and resolving endpoint information. This release includes the core library structure, a build script for configuring target-specific aliases (such as wasm\_browser and crypto provider features), and documentation. It also establishes the changelog and release configuration for the new module.
iroh-dns · high confidence
Initial release of iroh-relay crate with changelog and documentation
The iroh-relay crate is now available as a standalone package, including a new CHANGELOG.md that documents versions 1.0.2 through 1.3.0, a README.md detailing server setup, access control modes (allowlist, shared token, HTTP callout), and local testing instructions, and a LICENSE-BSD3 file acknowledging code derived from Tailscale. The build system uses cfg\_aliases for feature detection, and the release process is configured to automatically update the changelog.
iroh-relay · high confidence
Introduce iroh-base as the foundational library for network addressing and cryptography
The \iroh-base\ crate is introduced to centralize core types previously scattered across the codebase. It provides \EndpointAddr\ and \TransportAddr\ (supporting Relay, IP, and custom transports) for network-level endpoint addressing, and implements cryptographic key handling via \PublicKey\, \SecretKey\, and \Signature\ types. Additionally, it defines \RelayUrl\ for identifying relay servers. This change establishes a dedicated base layer for these fundamental concepts, separating them from higher-level networking logic.
iroh-base/src · high confidence
Introduce iroh-bench benchmarking tool with configurable worker threads and transport options
Added a new benchmarking suite in iroh/bench/src that allows users to measure transfer performance between iroh, noq, and s2n endpoints. The tool now supports configuring the number of Tokio worker threads per endpoint (via the --workers flag) to optimize task distribution and avoid congestion control issues. It also exposes options for controlling maximum concurrent streams, initial MTU, and enabling IPv6. The benchmark includes detailed statistics reporting, such as throughput, duration, time-to-first-byte (TTFB), and chunk metrics, and supports qlog tracing for performance analysis.
iroh/bench/src · high confidence
Introduce iroh-relay crate with v2 protocol, QUIC address discovery, and bearer token authentication
The iroh-relay crate is now available, providing a complete relay server and client implementation. The relay protocol has been updated to v2 (iroh-relay-v2), which removes the Health frame and adds a Status frame. A new QUIC server is included to support QUIC Address Discovery (QAD) for improved NAT traversal. The server now supports bearer token authentication via HTTP headers or URL query parameters, configurable access control (allowlist, denylist, or HTTP POST verification), and rate limiting. The client supports WebSocket connections and can run in browsers (Wasm). Default ports are defined for HTTP (80), HTTPS (443), QUIC (7842), and metrics (9090).
iroh-relay/src · high confidence
Introduces configurable path selection and socket-level metrics
The socket layer now supports configurable path selection via a new \BiasedRttPathSelector\ that prioritizes primary paths over backups (such as relays) and applies RTT biases (e.g., a 3ms preference for IPv6) with a 5ms hysteresis threshold to prevent flapping. This is accompanied by a new \Metrics\ struct that exposes counters for relay connection states (success, failure, closure, rate-limiting), transport path additions/removals, and actor loop activity, enabling users to monitor connection health and transport usage.
iroh/src/socket · high confidence
New DNS server examples for publishing and resolving endpoint info
Added three new command-line examples in \iroh-dns-server/examples\ to demonstrate interacting with the iroh DNS discovery system. The \publish\ example allows users to sign and publish endpoint information (relay URLs, direct addresses, and user data) to PKARR relays or DNS origins in staging, production, or local development environments. The \resolve\ example enables looking up endpoint details by ID or domain name via DNS or a custom nameserver. The \convert\ example provides a utility to translate between human-readable Z32 public keys and binary Endpoint IDs.
iroh-dns-server/examples · high confidence
New DNS-based endpoint discovery module
The \iroh-dns\ crate has been introduced to handle DNS-based endpoint discovery, allowing iroh endpoints to publish and resolve their addressing information via DNS TXT records. This module implements the pkarr signed packet format for secure record publication and provides a configurable DNS resolver that supports fallback nameservers and Android JNI integration. Users can now discover peers by resolving \\_iroh\ TXT records associated with their z32-encoded endpoint IDs, enabling decentralized address lookup without relying solely on the Mainline DHT.
iroh-dns/src · high confidence
New bulk transfer benchmark with configurable workers and metrics
Added a new \bulk.rs\ benchmark binary in the iroh-bench tool that allows users to run bulk data transfer tests against iroh, noq, and s2n endpoints. The benchmark now supports configuring the number of worker threads per endpoint via the \workers\_per\_ep\ option, enabling more granular performance tuning. When the \metrics\ feature is enabled, the tool collects and prints detailed Socket, NetReport, and RelayServer metrics at the end of the test run. The binary also includes support for IPv6 and a local relay mode for testing without external infrastructure.
iroh/bench/src/bin · high confidence
New endpoint configuration presets and pluggable connection hooks
The endpoint module now exposes \presets::N0\ and \presets::Minimal\ to simplify initialization by automatically configuring the crypto provider, relay mode, and address lookup services. Additionally, \EndpointHooks\ allow applications to intercept connection establishment, enabling custom logic to accept or reject connections before they start or after the TLS handshake completes.
iroh/src/endpoint · high confidence
New examples for 0-RTT, custom transports, and authentication hooks
The examples directory now includes several new demonstrations of iroh capabilities: 0rtt.rs shows how to benchmark and use 0-RTT connection resumption; custom-transport.rs demonstrates pluggable transport backends with a test network and path selection; auth-hook.rs implements a pre-connection authentication protocol using EndpointHooks; incoming-filter.rs shows how to require QUIC address validation for direct connections; and home-relay-status.rs illustrates how to monitor relay connection states and authentication failures.
iroh/examples · high confidence
New pluggable address lookup services with DNS, memory, and PKarr support
The address lookup system has been refactored into a modular, pluggable architecture, replacing the previous optional discovery mechanisms with dedicated services. Users can now configure DNS-based discovery (querying TXT records for relay URLs), in-memory lookups for manually added endpoint information (useful for out-of-band data like tickets), and PKarr-based publishing and resolution. The DNS lookup includes staggered retry intervals to improve reliability, while the PKarr publisher defaults to filtering out direct IP addresses for security, publishing only relay URLs unless explicitly configured otherwise. Metrics are now available to track lookup success, failures, and per-service performance.
_iroh/src/address\lookup · high confidence
Support for custom network transports
Users can now integrate non-standard networking protocols by implementing the \CustomTransport\, \CustomEndpoint\, and \CustomSender\ traits defined in \iroh/src/socket/transports/custom.rs\. This new capability allows applications to bind iroh endpoints to custom address types and handle packet reception and transmission through their own logic, provided the \unstable-custom-transports\ feature is enabled.
iroh/src/socket/transports · high confidence
Removals
Removed legacy echo client/server binary
The \src/main.rs\ file containing the basic QUIC-based echo client and server implementation has been deleted. This removes the ability to run the simple round-trip latency test and echo service that was previously accessible via command-line arguments \client\ and \server\.
src · high confidence
Behavioural changes
Actor-based signed packet store with write batching and eviction
The signed packet storage in iroh-dns-server has been refactored to use an asynchronous actor model. Incoming packet operations are now batched into write transactions based on configurable limits (up to 64k packets or 1 second of accumulation), reducing database contention. The store also includes a background eviction task that automatically removes packets older than 7 days, ensuring storage does not grow indefinitely. This change improves write performance and resource management for DNS packet storage.
iroh-dns-server/src/store · high confidence
New DoH request extractors and JSON response serialization
The DNS-over-HTTPS handler now uses dedicated extractors to parse incoming requests, supporting both binary DNS messages and JSON-formatted queries via the Accept header or query parameters. Incoming JSON queries are validated and converted into standard DNS requests, while responses are serialized into the Google Public DNS JSON format, including status codes, flags (TC, RD, RA, AD, CD), questions, and answers.
iroh-dns-server/src/http/doh · high confidence
New WebSocket-based relay client with proxy and TLS support
The relay client now uses WebSocket connections instead of the legacy path, enabling browser compatibility and proxy support. This change introduces a new client connection module that handles WebSocket handshakes, supports HTTP/HTTPS proxies with authentication, and manages TLS connections. The client now uses a new handshake protocol and frame types, with error handling using AnyError instead of concrete websocket and postcard errors. The implementation includes happy eyeballs for concurrent IPv4/IPv6 connection attempts and rate-limiting for client connections.
iroh-relay/src/client · high confidence
New path observation API with live statistics and event streams
The socket layer now exposes a redesigned path observation API that allows users to monitor network paths to remote endpoints in real time. A new \PathEvent\ stream provides lifecycle notifications for when paths are opened, closed, or selected for data transmission, while a snapshot API (\Connection::paths\) offers current statistics for active paths. The underlying state management has been refactored to track path usability (open, inactive, unusable) and retain statistics for closed paths, giving applications better visibility into connection health and address usage.
_iroh/src/socket/remote\_map/remote\state · high confidence
New remote connection state management actor
Introduces the \RemoteStateActor\ in \iroh/src/socket/remote\_map/remote\_state.rs\ to manage the lifecycle and path selection for connections to a single remote endpoint. This actor tracks all connections to a remote, monitors path events and address lookups, and selects the optimal transport path (e.g., direct vs. relay) based on latency and status. It handles holepunching attempts, manages path idle timeouts, and ensures the actor remains responsive during initial sends and address resolution, replacing previous ad-hoc state handling with a dedicated, configurable path selection mechanism.
_iroh/src/socket/remote\map · high confidence
Relay connection management refactored into dedicated actor model
The relay transport layer has been restructured to use a dedicated \RelayActor\ and \ActiveRelayActor\ architecture. The \RelayActor\ now centrally manages all connections to relay servers, spawning an \ActiveRelayActor\ for each server, which handles the individual connection lifecycle, including exponential backoff for reconnections and idle cleanup for non-home relays. This change introduces a prioritized message inbox (\prio\_inbox\) to ensure critical messages are processed immediately without blocking on data transmission, and optimizes the receive path by bypassing the main actor to send received datagrams directly to the UDP socket interface. Additionally, the implementation now uses \n0\_future::MaybeFuture\ and \JoinSet\ for more robust task management and future handling.
iroh/src/socket/transports/relay · high confidence
Relay protocol updated to v2 with new authentication and health status frames
The iroh-relay protocol has been upgraded to version 2, introducing a new handshake mechanism that supports both challenge-response and TLS keying-material-based authentication. The protocol now includes a new \Status\ frame to replace the deprecated \Health\ frame, allowing clients to receive detailed connection health states such as rate-limiting or duplicate endpoint detection. Additionally, the protocol defines new frame types for datagram batching and peer disconnection signals, ensuring more robust and secure relay communication.
iroh-relay/src/protos · high confidence
Relay server refactored into embeddable components with new client connection management
The relay server implementation has been restructured to support embedding into existing HTTP services. The new architecture introduces a \RelayedStream\ abstraction for handling WebSocket connections, a \Clients\ registry to manage active and inactive client states (allowing multiple connections per endpoint), and a \RelayService\ trait for HTTP-level integration. The server now supports certificate reloading via a background task, exposes detailed metrics for connection and packet tracking, and includes a dedicated QUIC address discovery (QAD) server for endpoint resolution.
iroh-relay/src/server · high confidence
Reworked network report generation with configurable probes and metrics
The network report module has been restructured to support configurable probe types (HTTPS, QUIC Address Discovery for IPv4/IPv6), customizable timeouts, and proxy support for HTTP(S) probes. A new metrics system tracks report execution counts and port mapping attempts, while the report structure now explicitly captures global IP addresses, mapping variance, and captive portal status. This change also gates the net-report API behind an unstable feature flag and moves the module back into the main iroh crate.
_iroh/src/net\report · high confidence
Reworked networking core with new Endpoint API and address lookup system
The iroh networking library has been restructured, introducing a new \Endpoint\ API that replaces the previous \Node\ abstraction. This change includes a new \address\_lookup\ module for automated peer discovery (supporting DNS, Pkarr, and memory-based lookups), a \net\_report\ component for network condition checking, and a \protocol::Router\ for handling incoming connections. The \Endpoint\ builder now configures these components, including relay maps, TLS settings, and path selection, providing a more modular and configurable foundation for establishing direct QUIC connections.
iroh/src · high confidence
TLS authentication now uses raw Ed25519 public keys instead of X.509 certificates
The TLS layer no longer relies on X.509 certificates for peer authentication. Instead, endpoints identify each other using raw Ed25519 public keys embedded in self-signed certificates. The server name (SNI) is no longer sent over the wire; it is now encoded locally as a Base32 string within the \.iroh.invalid\ domain to support 0-RTT session ticket bucketing. Verification is handled by custom \ServerCertificateVerifier\ and \ClientCertificateVerifier\ implementations that validate these raw keys directly, removing the dependency on the deprecated \x509\ libp2p TLS authentication.
iroh/src/tls · high confidence
iroh library documentation and build configuration updates
The iroh crate now includes a DEVELOPMENT.md guide explaining its structured event system (using the \iroh::\_events::\ target) and instructions for building documentation with nightly Rust. A new LICENSE-BSD3 file acknowledges code derived from Tailscale. The build script (build.rs) now defines \cfg\ aliases for WASM browser targets and crypto provider features, supporting the library's new capability to compile to \wasm32-unknown-unknown\ and use pluggable crypto backends. The README has been updated to reflect the current API, including the \Endpoint\ and \presets::N0\ usage, and links to related projects like iroh-blobs and iroh-gossip.
iroh · high confidence
iroh-dns-server: new modular architecture with mainline DHT fallback and configurable rate limiting
The iroh-dns-server source has been restructured into a modular, configuration-driven server that combines a DNS listener (UDP/TCP) with an HTTP/HTTPS relay. Users can now enable a mainline DHT fallback to resolve signed packets missing from the local store, configure HTTP rate limits for \PUT /pkarr\ requests, and customize the signed-packet zone store (including eviction policies and write batching). The server exposes Prometheus-compatible metrics for DNS, HTTP, and store activity, and supports both IPv4 and IPv6 binding with TCP keepalive enabled on HTTP listeners.
iroh-dns-server/src · high confidence
Test coverage
Added DNS write benchmark; Added integration and patchbay network simulation tests; Added integration tests for dual-stack DNS server binding; Added integration tests for relay embedding, multi-hostname TLS, and runtime access control; Added patchbay integration tests for NAT, relay, and link degradation.
Dependencies
Iroh workspace restructured to version 1.3.0 with Rust 2024 edition
The Iroh project has been reorganized into a multi-crate workspace (iroh, iroh-base, iroh-dns, iroh-dns-server, iroh-relay, and iroh/bench), all bumped to version 1.3.0 and targeting the Rust 2024 edition with a minimum supported Rust version (MSRV) of 1.91. This update upgrades core networking dependencies to noq 1.3.0 and rustls 0.23.33, and modernizes the HTTP stack by adopting hyper 1.x and axum 0.8. The workspace also introduces new feature flags for TLS backends (ring, aws-lc-rs) and platform-specific optimizations like fast-apple-datapath, while removing the legacy 'sendme' package in favor of the new modular structure.
(dependencies) · high confidence
Housekeeping
Initial repository scaffolding and documentation
The repository is initialized with foundational configuration and documentation files, including a \.dockerignore\ to exclude build artifacts, \.gitattributes\ to enforce LF line endings for CI stability, and a \.pinact.yaml\ to manage GitHub Action pinning rules. A \CHANGELOG.md\ is added to track version history, and a \CONTRIBUTING.md\ file provides guidelines for developers on how to submit issues, pull requests, and follow code standards.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 71 → 72 (+0.4)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 90 → 90 (+0.0)
- Architecture 99 → 92 (-6.7)
- Maturity 67 → 67 (+0.0)
- Readiness 85 → 69 (-15.9)
- Security 63 → 69 (+6.1)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)
Resolved (8)
- Documentation: no installation or build instructions (README.md)
- Documentation: no licence statement (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: iroh/src/net_report.rs (iroh/src/net_report.rs)
- Hotspot: iroh/src/socket.rs (iroh/src/socket.rs)
- Hotspot: iroh/src/socket/remote_map/remote_state.rs (iroh/src/socket/remote_map/remote_state.rs)
- Hotspot: iroh/src/socket/transports/relay/actor.rs (iroh/src/socket/transports/relay/actor.rs)
- Off-boarding risk: anonymized user #1
New (17)
- Ambiguous naming. closed() typically implies a state check (boolean) or a future/stream of closure events. close_reason() implies getting the reason for closure. Returning the same type ConnectionError from both suggests they might be accessing the same internal state, but the names suggest different intents (state vs. reason).
- Consistent but confusing pattern across multiple types. The presence of n0_dns() alongside builder() in both Publisher and Resolver suggests a library-specific convention ('n0') that is not self-explanatory. It creates cognitive load to determine which factory method to use.
- Duplicate method name with different return types. This is a signature collision in the API surface (overloading by return type is not supported in Rust, so these must be on different types or one is a typo in the provided list, or they are methods on different traits/impls not shown as distinct types). Assuming they are on the same Connection type, this is a compilation error. If they are on different types (e.g., Connection vs Incoming), the naming is inconsistent. Looking at the list, Incoming has remote_addr etc., but Connection has two alpn methods listed. This is likely a data error or a severe API design flaw if they are on the same type.
- Inconsistent naming and return types for similar operations. from_endpoint_info is a constructor-like static method. set_endpoint_info returns EndpointData (likely the stored data), while add_endpoint_info returns Self (unit/void). The distinction between 'set' and 'add' is not immediately obvious from the signature alone (does set overwrite? does add append?).
- Off the main sequence: iroh-base
- Off-boarding risk: anonymized user #1
- Orphaned files with no living knowledge
- Outdated: hyper-util
- Outdated: lru
- Outdated: rustls-platform-verifier
- Outdated: smallvec
- Outdated: tokio-rustls
- Outdated: wasm-bindgen-futures
- Projects may be oversized for their cohesion
- Redundant factory methods with unclear distinction. Both return a builder, but it is unclear if n0_dns is a specialized version of builder or if they produce different default configurations. In other types (e.g., PkarrPublisher), n0_dns is also present alongside builder, suggesting a pattern, but the naming is confusing for users who don't know the internal 'n0' convention.
- Standard Rust naming convention violation or confusion. to_ usually implies borrowing/converting without consuming, while into_ implies consuming the source. However, both return the same type EndpointAddr. If to_endpoint_addr borrows internally, it should return a reference or a copy. If it consumes, it should be into_. Having both suggests one might be a legacy alias or they perform different internal operations (e.g., one clones, one moves) which is confusing.
- TooManyMethods: Connection (iroh/src/endpoint/connection.rs)
Changes since last survey
- 11 commits — 6 feature/other, 5 fixes
By area
- iroh/src — 6 commits
- (root) — 3 commits
- .github/workflows — 1 commit
- iroh-dns/src — 1 commit
Notable commits
- fix: Revert "feat(metrics): lookup/resolver stats" (#4542)
- fix: chore: fix qlog feature gate error (#4556)
- fix: deps: bump rustls for RUSTSEC-2026-0285 & fix android CI (#4535)
- fix: fix(ci): run release builds on ephemeral instances (#4559)
- fix: fix(iroh): Preserve protocol ordering in the router (#4533)
- change: chore: fix typo (#4560)
- change: chore: release
- change: docs: update changelog for v1.3.0
- change: feat(iroh)!: expose batch datagram send/recv APIs (#4547)
- change: feat(metrics): lookup/resolver stats (#4543)
- change: refactor(iroh): simplify datagram send code and test setup (#4525)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
n0-computer/iroh was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 187f59e80afdae6bd9866002b33d3365c00b06d8 — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-70910855e4b4.