Content-addressed repos¶
This is the main way to use iroh-forge. A content-addressed repo has no home server. Its id is an Ed25519 public key, and anyone who holds a copy can serve it.
iroh-forge new # prints iroh://<repo-id> (52 characters)
git push iroh://<repo-id> main
git clone iroh://<repo-id> # works from any machine with the id
How it works¶
- Repo id = public key. The matching secret key lives in
~/.iroh-forge/repos/<repo-id>.key; only holders of it can push. - State = one BLAKE3 hash, the root of an iroh-blobs HashSeq
[manifest, pack, pack, …]. The manifest lists refs and HEAD; each push adds one self-contained git pack with only the objects the repo didn't have. - Pointer = a signed BEP 44 record on the BitTorrent Mainline DHT under the repo key, holding the root hash. Pushes update it with compare-and-swap, so a stale writer gets "fetch first" instead of silently overwriting.
- Providers = nodes holding the blobs announce themselves on the DHT under an infohash derived from the repo id (n0's global content discovery). A clone looks up the record, finds providers, and downloads with iroh-blobs.
Nothing is tied to one host: the pusher can go offline as soon as the push returns, and the clone needs only the repo id.
Pinners¶
Someone holding a copy has to be online when another agent clones. A pinner
is any machine running iroh-forge serve; it keeps copies, serves blobs,
announces itself on the DHT, and re-publishes each repo's record so it
doesn't expire.
# on the always-on machine
iroh-forge serve ~/forge
iroh-forge allow <pusher's client id> # who may ask it to pin
# on the pusher
iroh-forge pinner add <pinner's server id>
A push sends the new version to every configured pinner (plus this machine's
own serve, if it has one) and publishes only after at least one has it.
Several pinners can hold the same repo. To have a pinner follow a repo
someone else pushes: iroh-forge pin iroh://<repo-id> --on <pinner id>.
n0 runs address-index servers and relays but does not host content, so the pinner is yours: a small always-on VM, a NAS, or a desktop.
Handing off write access¶
iroh-forge repo export iroh://<repo-id> # prints the secret key
iroh-forge repo import <secret> # on the other agent
Reads are public
Anyone with the repo id can read it. Treat content-addressed repos as public to whoever learns the id; there is no read ACL yet.
Commands¶
| Command | What it does |
|---|---|
iroh-forge new |
Create a repo key, print iroh://<repo-id> |
iroh-forge repo list |
Repos this machine can push to |
iroh-forge repo export/import |
Move the write key between agents |
iroh-forge pinner add/list |
Where pushes are pinned |
iroh-forge pin <repo> [--on <id>] |
Ask a pinner to fetch and hold the latest version |
iroh-forge serve <root> |
Run a pinner (and a v0 server for <root>/<name>.git) |
Hosted repos (iroh://<server-id>/<name>) from v0 keep working unchanged.