top | item 44379173

Iroh: A library to establish direct connection between peers

268 points| gasull | 8 months ago |github.com

57 comments

order

Ingon|8 months ago

I work on connet [1] and from what I've seen iroh seem pretty cool. A few random thoughts I had while watching the presentations/reading the docs:

* the relays serve both for discovery and relay. In connet these are separate responsibilities, e.g. it has control server for discovery and a relay server for relaying connections.

* it seems that the connections to the relays in iroh are TCP (at least what was said in one of the videos), while connet uses QUIC in all cases. This probably makes iroh more resilient, but multiplexing on top of TCP might suffer from head of line blocking.

* it is pretty cool that iroh can seamlessly upgrade from relay to direct connection, connet doesn't do that on a connection level. It will however use direct in the subsequent virtual connections.

* using ALPNs for protocol selection is pretty cool, connet only offers "virtual connections" protocol, where one of the peers is "server" and the other is a "client".

* since there is a separate discovery server (with auth), in connet the endpoints are named separately with logical names, they don't represent peers necessarily. Because of this, you can have multiple peers with "server" role and "client" roles.

Anyhow, thanks for posting this, iroh looks great and I will draw some inspiration from it for sure.

[1] https://github.com/connet-dev/connet

rklaehn|8 months ago

There might be a small misunderstanding here. Our relays do two things. They relay user data, and relay a small number of special packets to help with hole punching. Other than that they are very simple. They never see unencrypted data, so they don't know anything more about the nodes they serve than what they need to function.

Connections are TCP https websocket connections, because this is most likely to get through even the most restrictive firewalls.

Discovery is handled outside the relays, via either a special DNS server or via the bittorrent mainline DHT. You can even implement your own discovery.

nerdsniper|8 months ago

> * the relays serve both for discovery and relay. In connet these are separate responsibilities, e.g. it has control server for discovery and a relay server for relaying connections.

What are the relative advantages/disadvantages of these two strategies?

eminence32|8 months ago

Some years ago, "iroh" was supposed to a replacement for ipfs. However since then, they (very smartly, in my opinion) dropped those ambitions and are just focused on being a high-quality library for anyone writing a P2P app (like ipfs).

I often see projects attempting to be a universe tool to solve every possible problem, and I think the iroh folks were smart to scale back and narrow their focus

dignifiedquire|8 months ago

appreciate the feedback, it was a hard decision to make, but has felt more right everyday since we made it

rkagerer|8 months ago

Aye. You often solve a technical problem while working to build something and later it turns out that building block has more utility than the thing you set out to build.

aquariusDue|8 months ago

I attended a workshop for iroh a while ago and really enjoyed it, and from what I can tell on the Discord server the folks developing it are gearing for a 1.0 release soon-ish.

There's also Dumb Pipe and SendMe which are demos (I believe) built on iroh to showcase some of its uses, and at the workshop we were shown a video of a startup using iroh for video game streaming (something similar to the old OnLive).

From what I understood (in spite of my lack of networking knowledge) and if I remember correctly clients have to be on the same relay (I think there's one for Europe and one for North America) and they use the Bittorent DHT Mainline (I had to google the iroh blog post about it because I forgot the exact name) for discovery. There was some stuff about BGP too, but it went over my head sadly.

I hope somebody more knowledgeable chimes in because iroh is really exciting, I feel like I could throw together a p2p application and it wouldn't be a daunting task due to it.

b_fiive|8 months ago

(disclosure: I work on iroh): you're selling yourself short! All of this is accurate, except for maybe the BGP stuff :)

Dumb Pipe & Sendme me are indeed demos, we do provide a set of default, public relays to use for free. The relay code is also open source, and if you want to pay us we can run a network for you.

We try to provide a few different options for discovery, the one we think has the most general utility is a custom DNS server, but both local mDNS and Bittorrent Mainline are also pluggable options.

outside1234|8 months ago

Was the workshop recorded?

ridiculously|8 months ago

I was never angry with you. I was sad, because I was afraid you'd lost your route.

softfalcon|8 months ago

Sharing tea with a fascinating stranger is one of life’s true delights.

schainks|8 months ago

Failure is only the opportunity to begin again. Only this time, more wisely.

kubafu|8 months ago

I came here for this. Thanks!

tyoung|8 months ago

Makes me cry everytime.

ventare|8 months ago

This may be, the worlds most perfect comment. Bravo.

ndyg|8 months ago

Iroh is intriguing. Dumbpipe is magical, and its implementation is easy to understand. I use dumbpipe daily to expose cross-stream (https://github.com/cablehead/xs) stores I run on different servers to my local laptop's `xs` client.

cprecioso|8 months ago

A bit off topic I guess, but what’s your usage for xs? I read the website, I think that I understand it and find it intriguing, but I’m not sure what one would use it for.

conradev|8 months ago

Iroh is very cool and their YouTube explainers are pretty great: https://youtube.com/@n0computer

I just need good FFI now, which is on the roadmap!

makeworld|8 months ago

Can't wait to be able to use it in Go or Python :)

bestouff|8 months ago

This thing is written in Rust. I wanted to use it on an embedded system in Rust (Embassy) using a CAN transport but unfortunately there's neither a no_std version nor a CAN plugin. Otherwise it looks good.

b_fiive|8 months ago

Yeah, no_std is going to be very hard. We need a no_std implementation of QUIC that can be wielded by mere mortals first, which I don't think we'll be able to start on for at least a year.

Right now we can get down to an ESP32, which we think is a decent start.

dignifiedquire|8 months ago

this would be great to have, but as we rely heavily on quic, we first need an implementation of quic in no_std which is the current biggest challenge

b_fiive|8 months ago

hey I work on this! AMA!

xeonmc|8 months ago

Can this be a made to work as an adapter to play older, raw UDP multiplayer games with random strangers? E.g. telling someone in Twitch chat “bro 1v1 me in CS1.6, here’s my Iroh ticket:”, they put it into their “InstaFrag NetDriver” Windows Client and you both launch CS1.6 and just start playing in an ad-hoc p2p lobby.

With Tailscale this use case is very cumbersome as you’d need to add them to your tailnet and configure access controls to make it an ephemeral connection.

iamnotempacc|8 months ago

Are you going to shake off the dust from iroh-willow? It was great idea, but seems to be not in active development.

littlestymaar|8 months ago

How do you manage authentication on the discovery/relay side?

pluto_modadic|8 months ago

do keys have a defined prefix or identifier? e.g., Veilid uses vld0? pkarr uses pk:?

dhash|8 months ago

these guys also have some really nice distributed systems explainer videos

throw10920|8 months ago

I've been wanting something like what Syncthing does for peer discovery for a while - something like this. Too bad it's written in such a low-level language.

outside1234|8 months ago

The promise of this is super interesting. How would people compare it to libp2p? Is libp2p a lower level toolkit that leaves the assembly to you?

dpc_01234|8 months ago

Each time I looked at libp2p I didn't even knew where to begin. With Iroh it was trivial to get connections.

Also, AFAIK, Iroh makes some architectural choices (using relays to help establish connections), that make it less "pure p2p", but much more likely to actually work reliably.

splintercell|8 months ago

I'm using GunDB (for my still in-development project), what would I need to migrate from GunDB to Iroh?

swoorup|8 months ago

Does this always have to be p2p or does it also allow for client server architecture

rklaehn|8 months ago

The two sides are peers when it comes to connection establishment, but once you have a connection they can and frequently will have different roles.

Many existing iroh protocols have clear client and server roles once the connection is established. E.g. gossip is a peer to peer protocol, blobs is a client server protocol in that one side provides data and the other requests it.

For a client you can use an ephemeral node id and not publish your info to discovery, since you will never be dialed yourself.

dpc_01234|8 months ago

It just makes a connection between two sides. How you use it (e.g. client makes a request, server responds) is up to you. So yes.

Calwestjobs|8 months ago

This is what GIT should had from start ! Imagine...

b0a04gl|8 months ago

lets say if i someone wants to keep using bittorrent dht for peer finding but swap out quic for something else maybe grpc, does the lib support that split clean? asking from a modular embed first tooling pov, where discovery logic needs to outlive or outswap transport depending on deployment