Config: relay_url for a self-hosted iroh relay (RelayMode::Custom)

The sovereign hole-punch hook redoal's ADR-0021 milestone 3 needs: when
relay_url is set (VARDE_RELAY_URL or the config file), the endpoint
coordinates NAT traversal through the operator's own iroh relay instead
of n0's or none — takes precedence over wan_upload's n0 defaults. None
keeps the existing LAN-only / n0 behaviour, so nothing changes by default.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Bendik Aagaard Lynghaug
2026-09-09 23:15:28 +02:00
co-authored by Claude Fable 5
parent 0449742618
commit f031f2f4ba
3 changed files with 25 additions and 4 deletions
+1
View File
@@ -1,2 +1,3 @@
target/
.claude/
.DS_Store
+11
View File
@@ -24,6 +24,12 @@ pub struct Config {
/// Whether any WAN (non-link-local) upload is permitted. Default off:
/// LAN-only posture with zero WAN upload.
pub wan_upload: bool,
/// A self-hosted iroh relay URL for NAT traversal. When set, the
/// endpoint uses this relay (`RelayMode::Custom`) instead of n0's
/// or none — the sovereign hole-punch coordinator an embedder runs
/// on its own infrastructure. Takes precedence over `wan_upload`'s
/// n0 defaults. `None` keeps the LAN-only / n0 behaviour.
pub relay_url: Option<String>,
/// Interval of the store's built-in garbage collector in seconds.
/// Since iroh-blobs 0.103 there is no on-demand gc; unpinned blobs
/// are swept by this loop.
@@ -41,6 +47,7 @@ struct FileConfig {
max_download_bytes_per_sec: Option<u64>,
discovery: Option<bool>,
wan_upload: Option<bool>,
relay_url: Option<String>,
gc_interval_secs: Option<u64>,
}
@@ -176,6 +183,10 @@ impl Config {
wan_upload: env_bool("VARDE_WAN_UPLOAD")?
.or(file.wan_upload)
.unwrap_or(false),
relay_url: std::env::var("VARDE_RELAY_URL")
.ok()
.filter(|s| !s.is_empty())
.or(file.relay_url),
gc_interval_secs: env_u64("VARDE_GC_INTERVAL")?
.or(file.gc_interval_secs)
.unwrap_or(300),
+13 -4
View File
@@ -62,10 +62,19 @@ impl Transfer {
metered: MeteredState,
) -> Result<Transfer> {
let secret = load_or_create_secret(&config.store_dir.join("secret.key"))?;
// With wan_upload the n0 defaults apply (their relays and DNS
// lookup, matching the pre-1.0 default relay mode); otherwise the
// endpoint gets no external services at all.
let builder = if config.wan_upload {
// A self-hosted relay (relay_url) is the sovereign hole-punch
// path and takes precedence: the endpoint coordinates through
// the operator's own iroh relay, never n0's. Failing that,
// wan_upload opts into n0's relays + DNS; otherwise the endpoint
// gets no external services at all (LAN-only).
let builder = if let Some(url) = &config.relay_url {
let relay_url: iroh::RelayUrl = url
.parse()
.with_context(|| format!("parsing relay_url {url:?}"))?;
let relay_map = iroh::RelayMap::from(relay_url);
Endpoint::builder(iroh::endpoint::presets::Minimal)
.relay_mode(RelayMode::Custom(relay_map))
} else if config.wan_upload {
Endpoint::builder(iroh::endpoint::presets::N0)
} else {
Endpoint::builder(iroh::endpoint::presets::Minimal).relay_mode(RelayMode::Disabled)