Example: Edge Fleet¶
This example shows Genesis Mesh across several physical locations. The Network Authority owns admission and revocation, while edge nodes communicate directly after trust is established.
flowchart LR
na["Network Authority"]
ops["Operations Team"]
factory_a["Factory A<br/>Edge Node"]
factory_b["Factory B<br/>Edge Node"]
factory_c["Factory C<br/>Edge Node"]
ops -->|signed admin actions| na
na -->|cert, policy, CRL| factory_a
na -->|cert, policy, CRL| factory_b
na -->|cert, policy, CRL| factory_c
factory_a <-->|Noise XX| factory_b
factory_b <-->|Noise XX| factory_c
factory_a -. routed DATA .-> factory_c
Deployment Steps¶
Create a genesis block for the fleet.
Start the Network Authority in a reachable control location.
Issue invites for each site or device role.
Enroll each edge node and store its certificate locally.
Configure peer bootstrap anchors for the expected topology.
Certificates Issued¶
Each site receives a certificate tied to its node key and role, for example:
Site |
Role |
|---|---|
Factory A |
|
Factory B |
|
Factory C |
|
The operator can use different roles for anchors, gateways, sensors, or maintenance nodes.
Routes Established¶
Direct neighbors are created only after authenticated handshakes. Non-neighbor routes are learned through route announcements and can be withdrawn when a peer leaves or is revoked.
Revocation Drill¶
If Factory B is decommissioned:
Revoke Factory B’s certificate with reason
cessation_of_operation.Publish and gossip the new CRL.
Factory A and Factory C reject Factory B as a peer.
Routes learned through Factory B are withdrawn.
If the site returns later, issue a new invite and enroll it again.
Generating and Federating a Fleet¶
The shipped CLI manages a fleet of independent sovereigns directly. Each NA is
described by its own genesis-mesh.toml; a fleet.toml manifest lists which
NAs are in the fleet.
# Scaffold keys, signed genesis, and configs for 4 sovereigns + a manifest
genesis-mesh fleet generate --output ./fleet --count 4 --prefix edge --base-port 8443
# Start each NA (one per host in production; here for illustration)
genesis-mesh na start --config ./fleet/edge-1/genesis-mesh.toml
# Federate the whole fleet and confirm it
genesis-mesh fleet mesh --config ./fleet/fleet.toml # treaties across all pairs
genesis-mesh fleet verify --config ./fleet/fleet.toml # confirm trust paths
genesis-mesh fleet status --config ./fleet/fleet.toml # healthz/readyz per NA
fleet mesh is idempotent — re-running it skips pairs that already have an
active treaty. See the CLI reference for full options.
Note
genesis-mesh fleet is deterministic and API-driven; it does not start or stop
processes. Production NAs run one-per-host under systemd or Kubernetes — see the
Deployment runbooks and the systemd unit
files in infrastructure/systemd/.