[{"data":1,"prerenderedAt":414},["ShallowReactive",2],{"navigation_docs":3,"-concepts-transport":144,"-concepts-transport-surround":409},[4,35,84,109,124,134,139],{"title":5,"path":6,"stem":7,"children":8,"page":34},"Get Started","\u002Fget-started","1.get-started",[9,14,19,24,29],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fget-started\u002Fintroduction","1.get-started\u002F1.introduction","i-lucide-house",{"title":15,"path":16,"stem":17,"icon":18},"Installation","\u002Fget-started\u002Finstallation","1.get-started\u002F2.installation","i-lucide-download",{"title":20,"path":21,"stem":22,"icon":23},"Quick start","\u002Fget-started\u002Fquickstart","1.get-started\u002F3.quickstart","i-lucide-rocket",{"title":25,"path":26,"stem":27,"icon":28},"Project structure","\u002Fget-started\u002Fproject-structure","1.get-started\u002F4.project-structure","i-lucide-folder-tree",{"title":30,"path":31,"stem":32,"icon":33},"Dashboard","\u002Fget-started\u002Fdashboard","1.get-started\u002F5.dashboard","i-lucide-layout-dashboard",false,{"title":36,"path":37,"stem":38,"children":39,"page":34},"Concepts","\u002Fconcepts","2.concepts",[40,45,50,55,60,65,69,74,79],{"title":41,"path":42,"stem":43,"icon":44},"Architecture","\u002Fconcepts\u002Farchitecture","2.concepts\u002F1.architecture","i-lucide-layers",{"title":46,"path":47,"stem":48,"icon":49},"Machines","\u002Fconcepts\u002Fmachines","2.concepts\u002F2.machines","i-lucide-server",{"title":51,"path":52,"stem":53,"icon":54},"Colony & users","\u002Fconcepts\u002Fcolony","2.concepts\u002F3.colony","i-lucide-users",{"title":56,"path":57,"stem":58,"icon":59},"Transport","\u002Fconcepts\u002Ftransport","2.concepts\u002F4.transport","i-lucide-network",{"title":61,"path":62,"stem":63,"icon":64},"Configuration","\u002Fconcepts\u002Fconfiguration","2.concepts\u002F5.configuration","i-lucide-settings",{"title":66,"path":67,"stem":68,"icon":23},"Deploy","\u002Fconcepts\u002Fdeploy","2.concepts\u002F6.deploy",{"title":70,"path":71,"stem":72,"icon":73},"Groups","\u002Fconcepts\u002Fgroups","2.concepts\u002F7.groups","i-lucide-boxes",{"title":75,"path":76,"stem":77,"icon":78},"Templates","\u002Fconcepts\u002Ftemplates","2.concepts\u002F8.templates","i-lucide-package-plus",{"title":80,"path":81,"stem":82,"icon":83},"Existing projects","\u002Fconcepts\u002Fexisting-projects","2.concepts\u002F9.existing-projects","i-lucide-folder-open",{"title":85,"path":86,"stem":87,"children":88,"page":34},"Remote","\u002Fremote","3.remote",[89,94,99,104],{"title":90,"path":91,"stem":92,"icon":93},"Remote machines","\u002Fremote\u002Foverview","3.remote\u002F1.overview","i-lucide-cloud",{"title":95,"path":96,"stem":97,"icon":98},"Remote deploy","\u002Fremote\u002Fdeploy","3.remote\u002F2.deploy","i-lucide-send",{"title":100,"path":101,"stem":102,"icon":103},"CI","\u002Fremote\u002Fci","3.remote\u002F3.ci","i-lucide-workflow",{"title":105,"path":106,"stem":107,"icon":108},"Tunnels","\u002Fremote\u002Ftunnel","3.remote\u002F4.tunnel","i-lucide-cable",{"title":110,"path":111,"stem":112,"children":113,"page":34},"Security","\u002Fsecurity","4.security",[114,119],{"title":115,"path":116,"stem":117,"icon":118},"Security model","\u002Fsecurity\u002Fmodel","4.security\u002F1.model","i-lucide-shield",{"title":120,"path":121,"stem":122,"icon":123},"Known issues","\u002Fsecurity\u002Fknown-issues","4.security\u002F2.known-issues","i-lucide-triangle-alert",{"title":125,"path":126,"stem":127,"children":128,"page":34},"Reference","\u002Freference","5.reference",[129],{"title":130,"path":131,"stem":132,"icon":133},"CLI reference","\u002Freference\u002Fcli","5.reference\u002F1.cli","i-lucide-terminal",{"title":135,"path":136,"stem":137,"icon":138},"Changelog","\u002Fchangelog","changelog","i-lucide-history",{"title":140,"path":141,"stem":142,"icon":143},"Communities","\u002Fcommunities","communities","i-lucide-heart-handshake",{"id":145,"title":56,"body":146,"description":401,"extension":402,"links":403,"meta":404,"navigation":405,"path":57,"seo":406,"stem":58,"__hash__":408},"docs\u002F2.concepts\u002F4.transport.md",{"type":147,"value":148,"toc":394},"minimark",[149,158,163,185,189,192,287,298,301,320,326,330,353,376,380,390],[150,151,152,153,157],"p",{},"Remote work travels over ",[154,155,156],"strong",{},"iroh",": QUIC + TLS 1.3 with mutual authentication.",[159,160,162],"h2",{"id":161},"what-it-gives-you","What it gives you",[164,165,166,173,179],"ul",{},[167,168,169,172],"li",{},[154,170,171],{},"Dial by NodeID."," No open inbound ports, no host certificates to manage.",[167,174,175,178],{},[154,176,177],{},"Mutual authentication."," Both sides prove possession of their key; the\ntransport verifies the bound endpoint id equals the NodeID, so a peer cannot\npresent a key it does not hold.",[167,180,181,184],{},[154,182,183],{},"A relay only forwards bytes."," When a self-hosted relay is configured, it\nnever sees plaintext.",[159,186,188],{"id":187},"rpc-and-blobs","RPC and blobs",[150,190,191],{},"The transport carries two things:",[193,194,195,208],"table",{},[196,197,198],"thead",{},[199,200,201,205],"tr",{},[202,203,204],"th",{},"Kind",[202,206,207],{},"Used for",[209,210,211,248,273],"tbody",{},[199,212,213,219],{},[214,215,216],"td",{},[154,217,218],{},"RPC",[214,220,221,225,226,225,229,225,232,225,235,225,238,225,241,225,244,247],{},[222,223,224],"code",{},"ping",", ",[222,227,228],{},"whoami",[222,230,231],{},"users.*",[222,233,234],{},"invites.redeem",[222,236,237],{},"deploy.run",[222,239,240],{},"build.run",[222,242,243],{},"compose.apply",[222,245,246],{},"route.apply",", …",[199,249,250,255],{},[214,251,252],{},[154,253,254],{},"Blob streaming",[214,256,257,258,261,262,265,266,268,269,272],{},"Image tarballs (",[222,259,260],{},"image.load",", a ",[222,263,264],{},"docker save"," stream) and build contexts (",[222,267,240],{},", a gzipped tar with ",[222,270,271],{},".dockerignore"," applied)",[199,274,275,280],{},[214,276,277],{},[154,278,279],{},"Tunnel",[214,281,282,283,286],{},"Raw TCP bytes to a container port (",[222,284,285],{},"ant nest tunnel","), on a separate ALPN",[150,288,289,290,293,294,297],{},"A request frame is capped at ",[154,291,292],{},"2 MiB"," (response frames at 8 MiB; larger\npayloads stream as blobs). The resolved compose file travels inside one request\nframe, so a compose file larger than 2 MiB fails today (see\n",[295,296,120],"a",{"href":121},").",[159,299,105],{"id":300},"tunnels",[150,302,303,304,307,308,311,312,315,316,319],{},"A tunnel is a raw byte pipe to a ",[154,305,306],{},"published container port on a machine",",\nopened on its own ALPN (",[222,309,310],{},"ant-tunnel\u002F1",") so it never shares the framing of an\nRPC. The worker resolves the requested ",[222,313,314],{},"container:port"," only to a loopback port\nant published for a container ant manages; a tunnel can never reach the docker\nsocket, Caddy's admin API, or another local listener. Tunneling needs the\n",[222,317,318],{},"deploy"," capability, the same trust as running a container on the machine.",[150,321,322,323,325],{},"Direction, usage (CLI and dashboard), limits, and troubleshooting are covered\nin ",[295,324,105],{"href":106},".",[159,327,329],{"id":328},"build-tags","Build tags",[150,331,332,333,336,337,340,341,344,345,348,349,352],{},"The transport is compiled only for ",[154,334,335],{},"Linux with CGO"," enabled (",[222,338,339],{},"\u002F\u002Fgo:build linux && cgo","); the vendored iroh library ships for ",[154,342,343],{},"amd64"," and ",[154,346,347],{},"arm64",". On any\nother build it is stubbed out: local-first works, and ",[222,350,351],{},"ant nest ping"," reports\nthat iroh is unavailable.",[354,355,360],"pre",{"className":356,"code":357,"language":358,"meta":359,"style":359},"language-sh shiki shiki-themes material-theme-lighter github-light github-dark","CGO_ENABLED=1 go build .\u002F...   # with transport\nCGO_ENABLED=0 go build .\u002F...   # local-only, transport excluded\n","sh","",[222,361,362,370],{"__ignoreMap":359},[363,364,367],"span",{"class":365,"line":366},"line",1,[363,368,369],{},"CGO_ENABLED=1 go build .\u002F...   # with transport\n",[363,371,373],{"class":365,"line":372},2,[363,374,375],{},"CGO_ENABLED=0 go build .\u002F...   # local-only, transport excluded\n",[159,377,379],{"id":378},"authorization","Authorization",[150,381,382,383,387,388,325],{},"The transport authenticates the ",[384,385,386],"em",{},"channel",". It does not decide what a caller may\ndo; the daemon authorizes each RPC against its roster. See\n",[295,389,115],{"href":116},[391,392,393],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":359,"searchDepth":372,"depth":372,"links":395},[396,397,398,399,400],{"id":161,"depth":372,"text":162},{"id":187,"depth":372,"text":188},{"id":300,"depth":372,"text":105},{"id":328,"depth":372,"text":329},{"id":378,"depth":372,"text":379},"How the CLI talks to a remote machine: iroh, RPC, and blob streaming.","md",null,{},{"icon":59},{"title":56,"description":407},"The iroh transport carries RPC calls and image blobs between the CLI and a machine daemon over mutual TLS.","zLxk1PVYdh_Sw26g1_co1Sx6F0wSWnVyppvWfqlflKM",[410,412],{"title":51,"path":52,"stem":53,"description":411,"icon":54,"children":-1},"Your portable identity, the users on a machine, roles, and invites.",{"title":61,"path":62,"stem":63,"description":413,"icon":64,"children":-1},"ant.yaml for a project, and ~\u002F.ant\u002Fconfig.json for the machine.",1791494556097]