Overview
How a mesh is shaped, and why the server is not in the path.
Every device holds an encrypted WireGuard tunnel to every other device. Separately, each device keeps a thin TLS connection to the coordination server, which tells it who else exists and how to reach them. Those are the only two kinds of connection in the system.
What the server does
- Enrollment — Admits a device to the network against a setup key.
- Address allocation — Hands each device its tunnel address.
- Peer lists — Tells each device which other devices it may see, filtered by access policy.
- ICE signalling — Relays sealed candidate payloads between peers so they can find each other through NAT.
- NAT reflector — Reports back the source address a packet arrived from, which is how a device learns its own public endpoint.
What it cannot do
- It holds no private keys — Nothing it stores can decrypt peer traffic.
- It cannot read signalling — ICE payloads are sealed with X25519 against the peers' own WireGuard keys before they reach it.
- It carries no data — Bandwidth cost stays near zero however much the mesh moves — except on the relay path, below.
When peers cannot punch through
If both ends sit behind symmetric NAT, hole punching fails. Rather than leaving the pair unable to talk, traffic falls back to an authenticated relay. That is the one case where bytes cross infrastructure you run.