One brain · every machine you own

The brain stays home.
You do not have to.

Your memory lives on a machine in your house, on a disk you own. Your laptop reaches it from a client site, a cafe or a phone tether and this road asks for no inbound port, no VPN and nothing of yours published to the internet. The phone road trades that last one for a name your tailnet holds.

The problem it solves #

Most developers have more than one machine and are still one person. A desktop that never sleeps, a laptop that leaves the house, maybe a build box. Everything you have taught one of them is on that one and the others start from nothing.

Some of the obvious answers are somebody else's product. Sync your database file through a folder and two writers corrupt it. Put the store on a cloud you rent and your memory is now their asset.

A mesh VPN is a real answer and we use one ourselves. If you already run a tailnet, or you are willing to, that is the shorter road and it is what the phone connector is built on. What follows is for the case where you are not: no TUN device on every machine, no elevated privileges, nothing from a second company. The brain does it itself, in one command and the machine that holds your memory is a machine you own.

How a machine reaches home #

The problem with reaching a machine at home is that it has no address anybody can dial. It sits behind NAT on a router you did not configure and the laptop trying to reach it is behind a different one, often behind carrier NAT with no public address at all. Neither can accept a connection. Both can make one.

That is the whole trick. Every leg dials out to a relay you run on a cheap VPS. The machine holding the brain keeps one connection open to it. Your laptop dials the same relay and asks for that machine by name and the relay splices the two connections together and copies bytes between them.

   laptop  --- dials out -->  relay  <-- dials out ---  the brain, at home
              |                                            |
              └──── TLS, end to end, the relay holds no key ────┘

Because the relay never terminates that TLS, it copies traffic it cannot read. It has no key that would let it and it cannot mint one. Whoever runs the relay, including you, sees ciphertext and connection timing and nothing else.

That session is TLS 1.3, pinned at both ends against your own private authority rather than the public one, so a certificate from a public CA cannot stand in for one of your machines. This is the leg that crosses networks you do not own and it is the leg that gets it. On your own LAN, or between two processes on one machine, there is nothing here worth encrypting and the brain does not pretend otherwise.

No inbound port is opened on your home network. No router is reconfigured. Nothing to install that you have not already installed: it is the same static binary, with a subcommand. That is the trade this leg makes against a tailnet, which asks you to run one more thing on every machine and gives you a name for each of them in return.

Getting a machine on it #

One command and the private key never leaves the machine it belongs to. Only a certificate request travels.

$ ns-brain axon enrol --email you@example.com --relay relay.example.com:7800
password:
joined the brain at wcwn3yv36v3fb6falfzzmiyj5y
  machine   laptop.wcwn3yv36v3fb6falfzzmiyj5y.axon.internal

An email the server has not seen registers a new brain. One it knows adds this machine to the brain you already have. From then on every ordinary command works exactly as it did: recall, remember, brief and the session hooks you already wired. Nothing above the transport knows a relay exists.

A machine enrolled with a password is temporary and that is deliberate rather than a limitation. A password works from a machine you will never see again, so what it buys is a device that expires on its own, thirty days later, whatever its certificate says. For a machine you keep, approve it from one you already hold:

$ ns-brain axon enrol --relay relay.example.com:7800   # on the new machine

    FV7F-QVD2

$ ns-brain hive approve-machine FV7F-QVD2            # on a machine already on the brain
admitted permbox..., permanently.

The code is short because you read it off one screen and type it on another. It can afford to be short because it admits nobody by itself: it names a request that is waiting and the authority is the credential of whoever approves it.

What the relay can see #

Machines are named <machine>.<org>.axon.internal and a client verifies the name it asked for, not merely a certificate chain that validates. That distinction is the one that matters. Every machine of yours holds a certificate from the same private authority, so a chain always verifies; a client that checked the chain and stopped there could be spliced to a different machine in its own org by a relay that had been taken over. Checking the name closes that.

Those names are never resolved in DNS. There is nothing to publish, no record to look up and no list of your machines anywhere for somebody to enumerate. The org id is generated rather than chosen, so it cannot be guessed at or squatted and it is an address rather than a credential: holding it admits nobody.

The relay admits machines from a list that is a projection of the brain's own register, pushed on every change and again every minute. There is deliberately no second register that somebody could revoke a machine in and forget the other.

Losing a laptop #

The question worth asking of any of this is what happens on the day a machine is stolen. Deleting a credential on a machine you no longer hold is theatre, so revocation happens on the brain and you do it from a machine you still have.

$ ns-brain hive machines                                  # what is enrolled
$ ns-brain hive logout --server <url> --machine laptop     # revoke there, forget here

The revoked machine is refused at the relay within a minute and any session it is holding open is dropped immediately rather than being left to finish. Its name is then retired for good: admission is by name and the certificate it holds stays cryptographically valid until it expires, so letting the name come back would let the certificate come back with it.

Revoking a machine that is not the one you are sitting at leaves the one you are sitting at signed in, because logging out a laptop you no longer hold is done from a machine you still do.

What it does not do #

This is not replication. The memories live on the machine that holds them, so a machine that cannot reach it has no brain: the session opens with the brief it cached and then refuses, rather than answering confidently out of a stale local copy. That refusal is the design. A brain that quietly answers from a file nobody has written to in a month is worse than one that says it cannot reach the server.

It is also not free of a network round trip. On a home LAN a command is a few milliseconds; through a relay in another country it is closer to four hundred and on mobile data closer to six hundred. Fast enough that a session brief fits inside its budget, slow enough that you would notice it in a tight loop.

Certificates last ninety days on a machine that may renew. Renewal is a command and a timer and it proves who it is with the certificate it is replacing; a temporary machine is refused, because renewing one would turn a device meant to expire into a permanent one.

What it costs #

Nothing. All of it is in the free edition, however many machines you add. The paid line is drawn on a second person, never a second machine: one developer running a brain on their own desktop and a relay on their own VPS, with a laptop and a build box attached, is the free edition and stays there.

The relay is the only piece that needs a public address and the cheapest VPS you can find is enough, because it copies bytes and stores nothing. How to set one up.