Skip to content

Add embedded SDK knobs: disable iroh relays + join-token on running node - #782

Merged
michaelneale merged 1 commit into
Mesh-LLM:micn/sprout-embedded-serve-sdkfrom
tlongwell-block:tyler/mesh-disable-iroh-relays
Jun 2, 2026
Merged

Add embedded SDK knobs: disable iroh relays + join-token on running node#782
michaelneale merged 1 commit into
Mesh-LLM:micn/sprout-embedded-serve-sdkfrom
tlongwell-block:tyler/mesh-disable-iroh-relays

Conversation

@tlongwell-block

@tlongwell-block tlongwell-block commented Jun 2, 2026

Copy link
Copy Markdown
Contributor

What

Two opt-in, default-false seams the Sprout v1 mesh integration needs on the embedded SDK:

  • disable_iroh_relays(bool) — when true, bind_mesh_endpoint uses RelayMode::Disabled instead of the existing RelayMode::Custom path. Lets a consumer say "no public relay" explicitly; today an empty relay list silently falls back to public *.iroh.link. Default false preserves existing behavior byte-for-byte.
  • EmbeddedNodeHandle::join_token(token) — forwards an invite token over the existing RuntimeControl channel to node.join_with_retry, so an already-running embedded node can dial a new EndpointAddr without restart (the call-me-now primitive).

Purely additive. Defaults preserve current behavior for all other consumers. +87/−9 across 6 files.

Base

This PR targets micn/sprout-embedded-serve-sdk (the branch behind #736), not main. The knobs extend the crates/mesh-llm-sdk crate, which only exists on the #736 stack — it is not on main yet. A PR against main would be unreviewable noise (the whole SDK stack would show as the diff). This is a dependent PR; it should land after / with #736.

Verification

cargo check -p mesh-llm-sdk --features client,serve green. Consumed and exercised in Sprout's desktop mesh integration (relay-gated discovery → connect → call-me-now → inference).

Co-authored with Max (Sprout team).

Connectivity: WAN via STUN, relay transport off

disable_iroh_relays(true)RelayPolicy::ExplicitlyDisabled turns off the iroh relay transport (no *.iroh.link traffic) but keeps raw STUN on (uses_raw_stun() matches DefaultPublic | ExplicitlyDisabled). The STUN-discovered public address is injected into the invite token / EndpointAddr, so a relay-signaled peer can hole-punch directly over WAN without an iroh relay. STUN is a "what's my public IP" lookup, not a data path — the privacy posture (no relay traffic) holds.

Disabled (LAN-only mDNS mode) stays STUN-off, intentionally.

Residual limit: no relay transport fallback, so two peers both behind symmetric NATs may fail to hole-punch (the case iroh relays normally cover). Fine for the common cases (≥1 side cone-NAT/forwarded/server). (Reviewed by Perci.)

@tlongwell-block
tlongwell-block force-pushed the tyler/mesh-disable-iroh-relays branch from 94c46d7 to 999e394 Compare June 2, 2026 18:43
Two opt-in seams the Sprout v1 mesh integration needs:

- disable_iroh_relays(bool): when true, embedded runtime selects an explicitly disabled relay policy, which uses RelayMode::Disabled, skips public relay URL fallback, skips raw STUN, and avoids the 5s endpoint.online() wait that cannot succeed without a home relay. Default false preserves existing behavior.

- EmbeddedNodeHandle::join_token(token): forwards an invite token over the runtime control channel to node.join_with_retry so an already-running embedded node can dial a new EndpointAddr without restart. Handled in both auto and passive/client runtime loops.

Purely additive; existing defaults and startup join_tokens behavior remain unchanged.

Co-authored-by: Eva <011987e296fd5006292d2f930b574be47c7801048d1983c46c425d3c95f0cffd@sprout-oss.stage.blox.sqprod.co>

Co-authored-by: Perci <5a968df9a7494b4e019b9ecf739e088ba61097b4312124e9a88ae5b42e3f5f3e@sprout-oss.stage.blox.sqprod.co>

@ndizazzo ndizazzo left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey @tlongwell-block 👋🏻 good to see you here, and thanks for the PR!

I had a look at the PR and it looks sane. There's been some back and forth in Discord on some node discoverability issues, so I was looking @ this from the critical lens of mDNS and local-only hosting, and spotted a potential issue...

ExplicitlyDisabled.uses_raw_stun() -> true means that mDNS/LAN-only mode would let mesh do STUN when we'd want that disabled. The smallest fix could be to keep mDNS/LAN precedence over disable_iroh_relays, since you'd not be enabling LAN for Sprout anyways. Mind adding a case to cover that edge and a switch over the relay policy order?

@michaelneale

Copy link
Copy Markdown
Collaborator

@ndizazzo I think this may be ok

@michaelneale
michaelneale merged commit ffb8d32 into Mesh-LLM:micn/sprout-embedded-serve-sdk Jun 2, 2026
1 check failed
i386 added a commit that referenced this pull request Jun 3, 2026
* a run at SDK, tested with a client

* Use in-process shutdown for embedded SDK

* Satisfy clippy for embedded shutdown plumbing

* Document embedded Rust SDK usage

* Add public Rust SDK crate

* Tighten embedded SDK lifecycle

* Address embedded SDK review feedback

* Document native runtime packaging direction

* Document runtime CLI namespace

* Document runtime CLI UX expectations

* Document runtime diagnostics under doctor

* Add Windows PowerShell installer

* Document recommended runtime install flow

* Add native runtime resolver foundation

* Wire native runtime release installs

* Document native runtime crate

* Load versioned native runtimes dynamically

* Fix embedded SDK output manager reset

* Expose SDK mesh admission controls

* Split SDK runtime mapping assertions

* Tighten SDK docs and config module

* Clarify native runtime SDK TODOs

* Stabilize native log note test

* Expose native runtime install SDK

* Re-export native runtime APIs from SDK crate

* Add embedded SDK knobs for Sprout relay mesh (#782)

Two opt-in seams the Sprout v1 mesh integration needs:

- disable_iroh_relays(bool): when true, embedded runtime selects an explicitly disabled relay policy, which uses RelayMode::Disabled, skips public relay URL fallback, skips raw STUN, and avoids the 5s endpoint.online() wait that cannot succeed without a home relay. Default false preserves existing behavior.

- EmbeddedNodeHandle::join_token(token): forwards an invite token over the runtime control channel to node.join_with_retry so an already-running embedded node can dial a new EndpointAddr without restart. Handled in both auto and passive/client runtime loops.

Purely additive; existing defaults and startup join_tokens behavior remain unchanged.

Co-authored-by: npub1mprnacetjua2xx3p5eddmhxyk6wv929ymm5py8kd2xfxurxahspqqlgyta <d8473ee32b973aa31a21a65adddcc4b69cc2a8a4dee8121ecd51926e0cddbc02@sprout-oss.stage.blox.sqprod.co>
Co-authored-by: Perci <5a968df9a7494b4e019b9ecf739e088ba61097b4312124e9a88ae5b42e3f5f3e@sprout-oss.stage.blox.sqprod.co>

* Fix relay policy test visibility

* Make SDK publishable and align language bindings (#771)

* Split SDK native runtime publish surface

* Split CLI and TUI support crates

* Move CLI parser surface into mesh-llm-cli

* Extract shared mesh event surface

* Move standalone command handlers out of host runtime

* Move benchmark and plugin commands out of host runtime

* Finish plugin command extraction

* Extract auth identity ownership

* Move remaining standalone commands out of host runtime

* Move model store into model-hf

* Move CLI commands out of host runtime

* Decouple host runtime from CLI and TUI crates

* Expose embedded node SDK facade

* Keep client identity dependencies pure

* Simplify Rust SDK feature surface

* Keep SDK client feature runtime-free

* Expose SDK client API base override

* Use direct mesh SDK client transport

* Remove API base URL client builder shim

* Align language SDKs with Rust SDK facade

* Document SDK client and serving modes

* Fix SDK smoke runtime setup

* Package SDK console assets

* Fix dynamic runtime CI setup

* Restructure SDK docs by language

* Fix SDK smoke package loading

* Fix native runtime bundle resolution

* Add structured native runtime backend metadata

* Harden Kotlin native runtime smoke resolution

* Fix mesh-llm-sdk clippy imports

* Retry smoke model downloads

---------

Co-authored-by: James Dumay <jameswdumay@gmail.com>
Co-authored-by: tlongwell-block <109685178+tlongwell-block@users.noreply.github.com>
Co-authored-by: npub1mprnacetjua2xx3p5eddmhxyk6wv929ymm5py8kd2xfxurxahspqqlgyta <d8473ee32b973aa31a21a65adddcc4b69cc2a8a4dee8121ecd51926e0cddbc02@sprout-oss.stage.blox.sqprod.co>
Co-authored-by: Perci <5a968df9a7494b4e019b9ecf739e088ba61097b4312124e9a88ae5b42e3f5f3e@sprout-oss.stage.blox.sqprod.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants