fabric experimental
fabric
fabric connects your machines into a private mesh, and hides the network behind plain local sockets. A tool that wants a service on another machine asks fabric for a local socket, then speaks its own protocol over it. On top of that, fabric offers a resumable remote shell, remote exec, one-shot file send and folder sync.
Experimental. fabric is an early prototype. Its commands, configuration and on-disk formats will change, and there are no stability or security guarantees yet.
What it's built on
fabric uses iroh: QUIC connections that go peer to peer when they can, and through a relay when they can't. Machines reach each other directly, across a LAN or the internet. There are no accounts and no central service.
The mental model
Every machine runs one fabric daemon, with its own identity and its own list of whom it trusts, and for what.
- A tool asks its local daemon for a connection to a service on a peer.
- The daemon finds the peer, picks a direct or relayed path, authenticates it, and reconnects when the network changes.
- The far daemon checks its grants before it touches anything.
- The tool gets a local socket, and never learns about node ids, relays or allow-lists.
Sync, shell, exec and file send are all services on that same trusted, resumable transport.
Partitions are normal
When a peer is unreachable, each machine keeps working from its last instructions. An offline peer isn't "unhealthy": laptops sleep and servers reboot. Whether a missing peer matters is up to the work that uses it, not a fleet-wide health check, and one broken path never spills into unrelated local work.
Where it's used
- smalltalk replicates its graph between machines over fabric.
- pty reaches sessions on other machines through fabric.
- Anything else you want to reach across machines: expose and dial any local service.
Getting connected
# on each machine: print its node id
fabric id
# on machine A (and the reverse on machine B)
fabric add <machine-b-node-id> machine-b
fabric up
# prints pong, the latency, and whether the path is direct or relayed
fabric ping machine-b
Read trust and grants before you connect machines.