Meshes

A mesh is a named private network across several of your hosts. MIOSA assigns each member an address in the mesh’s /24 and distributes WireGuard keys, so members reach each other directly without exposing anything on the public internet.

Use a mesh when services on one host need to talk to services on another: a database on one box, an application on a second, a GPU worker on a third.

Create a mesh

FieldTypeRequiredDescription
namestringYes1 to 80 lowercase alphanumeric or hyphen characters
host_idsstring[]NoHosts to add at creation; default []

A mesh carries a cidr in the form 10.x.x.0/24, a state, and a listen_port_base that defaults to 51820. Mesh states are provisioning, active, failed, and torn_down.

Manage membership

miosa host mesh add-host lab <host>
miosa host mesh remove-host lab <host> --yes
miosa host mesh rm lab --yes
ActionREST
Add a hostPOST /opencomputers/meshes/{id}/hosts/{host_id}
Remove a hostDELETE /opencomputers/meshes/{id}/hosts/{host_id}
Delete the meshDELETE /opencomputers/meshes/{id}

Adding a host returns the new peer. Removing a host leaves the host itself in place; deleting the mesh tears down the WireGuard configuration before the record is removed.

Inspect peers

miosa host mesh get <mesh> and GET /opencomputers/meshes/{id} return the mesh with its current peer list.

Peer fieldMeaning
idPeer record ID
host_idThe host this peer represents
assigned_ipAddress in the mesh’s 10.x.x.x range
pubkeyThe peer’s WireGuard public key
endpointLast seen endpoint
latest_handshakeWhen the tunnel last completed a handshake
rx_bytes, tx_bytesTraffic counters
statepending_key, configured, active, or failed

Peer states are the fastest way to answer “is this host actually reachable over the mesh”: an active peer with a recent latest_handshake is, and a pending_key peer never joined.

Events

Security notes

  • Mesh traffic is encrypted and stays inside the mesh. It does not become reachable from the internet because a host is a member.
  • MIOSA distributes the WireGuard keys. An operator with control-plane access can add a host to a mesh, so treat mesh membership as a privileged change and review it in the audit log.
  • A mesh does not grant a host access to anything else on another host beyond the ports that host’s firewall and services allow.
Was this page helpful?