Skip to main content

Decision

All staked nodes form a flat mesh with no routing hierarchy. Node discovery reads the on-chain registry’s active set. Content discovery uses a Kademlia-subset DHT, with the on-chain origin directory as the deterministic last-resort fallback. A probe confirms live availability and measures latency before any paid pull.

Node discovery

The on-chain registry’s active set is the sole membership source. A node reads it at startup and keeps it fresh by subscribing to registration, address-update, deregistration and auto-ejection events; sub-second L2 block times keep the staleness window small. Clients do the same and re-read periodically, falling back to a cached peer list — with its age surfaced — when the RPC endpoint is unreachable. The same active set seeds the DHT routing table, so a freshly started node participates in lookups immediately. A node dials any peer by its network identity, which resolves to reachable transport addresses on its own — there is no separate address-exchange layer, and no metadata broadcast.

Content discovery

A cache miss issues a DHT lookup for the hash, which returns candidate holders along with a coarse coverage bitmap per holder — so a requester can prune candidates that do not hold the range it wants. Candidates are then probed in parallel to confirm live availability, fresh coverage, latency and price. Collection stops as soon as enough blob-holding candidates answer to fill the failover budget, and otherwise at a 500 ms ceiling that accommodates inter-continental round trips. When a lookup returns no providers for a request that names a namespace, the namespace’s on-chain origin set is the deterministic fallback. A request naming no namespace has no directory to fall back to — it has no authorized origins — so a miss there simply fails. Either way, if nothing answers, the blob is not available in the network.

Selection

Clients and nodes rank candidates differently.
  • Clients take candidates from their own peer store or the registry, not the DHT, and rank them by measured round-trip time alone. Price is not a rank key: the client pays the rate the node signs and can refuse a quote above a ceiling of its own. A client keeps no reputation score; it only sets aside, for a few minutes, a node that just failed it.
  • Nodes pulling on a cache miss rank holders by a unified score combining advertised price, observed latency, and their local reputation score, with a quadratic reputation penalty. Lower is better.

On-chain registration

Nodes register through an on-chain staking registry that binds a network identity to an Ethereum address. Registration requires proof of control of both keys — preventing identity squatting and ensuring every staked node is slashable. Registration also carries acceptance of the DAO-canonical operator terms hash, signed into the registration message and enforced on-chain; the terms hash is governance-swappable, so the accepted version is recorded at registration. Key rotation remains available post-registration.

Regions

A node declares its region — an ISO 3166-1 alpha-2 country code — on-chain at registration, and the registry watcher resolves the active set into a region map. The claim is self-attested and accepted at face value; a pulling node applies a reputation penalty when observed latency contradicts it, and region-scoped takedown obligations follow it (takedown). A stability window after a region change stops a node shedding blacklist scope by flipping regions reactively. Regions inform selection rather than partition the mesh: a client in Frankfurt uses its region only to shortlist which candidates to probe, and prefers nearby ones because they answer faster, not because it sees a different peer set.

NAT traversal

The transport handles hole-punching automatically; nodes update their registered addresses when their public-facing address changes. When direct P2P fails, traffic routes through a stateless, content-blind QUIC relay. Relays are not protocol participants — they cannot inspect, cache, or modify content — and they are not an incentivized network role: paying relays per byte would create a perverse incentive to prevent direct connections. Deployments self-host them as operational infrastructure, funded from the protocol treasury or from node staking fees.