5 ms·
If you're new to Iroh, my mental model is roughly "Tailscale at the application layer instead of the network layer". If your question is, "why not just use Tai
by apitman 4mo ago
If you're new to Iroh, my mental model is roughly "Tailscale at the application layer instead of the network layer".
If your question is, "why not just use Tailscale?", look at it from an app developer's perspective. If you want to release an app and have instances of your app be able to easily connect to each other, you could theoretically embeded Tailscale functionality into your app, but then the users of your app need Tailscale accounts, and your app is dependent on Tailscale.
Iroh lets you embed this functionality directly, and provides public fallback relays. If your app gets too big for the public relays, using your own relays is the flip of a switch.
- bicepjai 4mo agoI understood more about what iroh does with this post then the video :) thanks for the mental model. Now how does iroh accomplish this. Great idea by the way.
- thejazzman 4mo agothis is how: https://docs.iroh.computer/concepts/relays https://docs.iroh.computer/concepts/relays
- gz5 4mo agothe closest comparison is openziti: + iroh and openziti can both be app-embedded + so the app developer embedding in their service is a good use case for both + openziti is used for services in which scale and security are critical + whereas iroh allows participation from parties which don't have any prior relationships - which can be very convenient
- embedding-shape 4mo ago> the closest comparison is openziti: Except without all the ceremony about setting up daemons, servers, controllers, "networks" and what not that openziti seems to have. Iroh is more "define protocol and hook two clients together" with everything in one binary. Unless I understand https://github.com/openziti/sdk-golang/blob/a6e5f1697a9dc34a41c1ed398d667b349f2b04b4/example/chat-p2p/setup.go https://github.com/openziti/sdk-golang/blob/a6e5f1697a9dc34a... wrong, it seems to require a "controller-url", is that controller embeddable as well?
- gz5 4mo agoyes, openziti includes a full mesh, programmable overlay. agree not all apps need that.
- embedding-shape 4mo ago> agree not all apps need that It's less that "not all apps need that" and more that "openziti can be app-embedded" is actually completely false.
- dovholuknf 4mo agoOpenZiti has numerous SDKs. If you are a developer and you can integrate an SDK into your application, it 100% is application-embedded. It is incorrect stating that it can't be app-embedded... (i am a maintainer on the project). Perhaps I just don't understand the response?
- embedding-shape 4mo agoOh, hi :) Thanks for responding! This: https://github.com/openziti/sdk-golang/blob/a6e5f1697a9dc34a41c1ed398d667b349f2b04b4/example/chat-p2p/setup.go https://github.com/openziti/sdk-golang/blob/a6e5f1697a9dc34a... mentions a "controller url", I'm assuming it's just the particular example then and in reality you could build and ship one golang binary that doesn't require any other external processes to connect the two processes together via OpenZiti?
- PLG88 4mo agoI’d separate “app-embedded” from “no external coordination.” OpenZiti SDKs are app-embedded: the app can directly dial/bind Ziti services without a local tunnel daemon. Ziti also supports tunnelers and non-embedded options where app modification is not practical. But yes, the app is still participating in a Ziti network with controllers, routers, services and policies. Iroh is definitely lighter-weight and developer-first, but it is not always “two binaries and nothing else” either (at least from what I have read). Once you need arbitrary peers across NATs/firewalls, you may need relays, address lookup, relay URLs/tickets, and for production likely dedicated/authenticated relays. So to me the distinction is not “embedded vs not embedded”; both can be embedded. It is “P2P connectivity substrate” vs “governed zero-trust service overlay.” Iroh optimises for low-friction key-based peer connectivity. OpenZiti optimises for centrally governed, least-privilege service reachability, including identity lifecycle, revocation and policy control at fleet scale. Note, I also work for NetFoundry, which develops and maintains OpenZiti.
- michaelsalim 4mo agoThis is exactly it. I'm pretty sure I found Iroh after thinking: can we ship Tailscale with our app? For environments where you want people to access your local instance, I believe Iroh will be a game changer. For us, it's to allow control over our software through phones and other devices easily. Previously, you might have to make sure they're in the same LAN network. But with Iroh, anything works.
- holmesworcester 4mo ago[dead]
- evnc 4mo agoOh, okay, I get the value prop now. Thank you. They should hire you to write their marketing copy, you did a better job than the landing page.
- thejazzman 4mo agoalso to follow on the "why not use tailscale" should be because they're a business who seeks to make money and we are fools to keep concentrating distributed technology to a handful of centralized owners (!) especially when iroh makes it so easy and awesome to do it right.
- rmunn 4mo agoSo instead of paying a subscription fee to Tailscale to support your distributed application, you pay a subscription fee to Iroh to support your distributed application. (https://www.iroh.computer/pricing https://www.iroh.computer/pricing says $19/month for what most people will want to use it for). Either one will allow you to stop "concentrating distributed technology to a handful of centralized owners", but the "why not use tailscale" part of what you're trying to say is not at all evident from your comment.
- flub 4mo agoiroh is fully open source though, you can run your own relay server and not have any dependencies on number0
- telotortium 4mo agoHeadscale exists, not sure what the difference is in practice.
- rklaehn 4mo agoThis might not be a giant difference in practice. But headscale is a community project. The iroh relay code is by number0 just like iroh itself and lives in the same MIT and Apache2 licensed repository. You can even embed it into your webserver if you have a special use case - it is very modular.
- sethops1 4mo agothat landing page is confusing, they should delete their text and replace it with yours
- Bnjoroge 4mo agoThey should basically replace any Why Iroh vs Tailscale with this. Thank you
- deleted 4mo ago[deleted]
- evilturnip 4mo agoOk, stupid question, but what applications is something like tailscale/iroh used for? I've never worked with this type of tech so curious where it is valuable.
- inapis 4mo agoWith tailscale, you can establish a private LAN over the internet. Iroh embeds this directly into the app itself.
- brudlekukk 4mo agoNot a stupid question - I was wondering about the same thing, and this gave me easy access to the answer because someone replied to your comment. Thank you for asking :)
- embedding-shape 4mo agoSay you want to build a Peer to Peer application; chat, file sharing, music sync or whatever, then something needs to be built to communicate between this application running in two different places. While you still need to build the actual protocol yourself ("Users can send messages" etc), how the two instances are connected is handled by Iroh mostly.
- waynesonfire 4mo agowhy isn't your mental model to use DNS?
- cwillu 4mo agoDNS is piece of the required kit, and not the only hard part of the task.
- mkl 4mo agoHow will that help your computer behind your NAT communicate with my computer behind my NAT? (I think you're still stuck on the blog post's very confusing opening, which does indeed make it sound like a terrible alternative to DNS, but it's actually something entirely different, for a very different purpose.)
- samrus 4mo agoIts amazing to me how people can make a great a product. And then completely bury the lead because they are so deep into the guts of the system You explained the value proposition so well. The website just didnt get to the "why?" At all
- waynesonfire 4mo agoWhy? Because if you need to serve ads that are being blacklisted by DNS, you need something like this.
- samrus 4mo agoOh come on. I guess it can be abused that way but its so cynical. First, i heavily doubt thats the intention here, and secondly, mmost ads are blocked at the rendering stage, rather than DNS. Especially since youtube broke DNS adblocking by serving ads and contect from the same domain
- colinmarc 4mo agoIt's primarily an open source library, not a product. I don't understand why HN seems so concerned about nailing down its "value proposition".
- meowkit 4mo agoI mean this kindly, but this is so “engineer brained” Maybe the game has changed with LLMs, but its been a running joke that engineers will build a startup/product/library/thing only to then realize they can’t get any users and that marketing and sales are hard. Attention and mind share are more valuable than ever. If you can’t answer “Why should I care about X?” then you are fighting an uphill battle.
- colinmarc 4mo ago> Maybe the game has changed with LLMs, but its been a running joke that engineers will build a startup/product/library/thing only to then realize they can’t get any users and that marketing and sales are hard. I agree with your premise, but you're still viewing this technology through the lens of "a successful product" versus "a successful piece of technology". Plenty of open source projects stay open source and are popular without ever making any sales whatsoever. I'm not trying to project my own motivations on the Iroh team; they may want to build a product out of it. For me, though, the project has a lot of appeal already, because it exactly and excellently fulfills a technological need, not because they brought me in with a "it's x but for y" narrative.
- metaketa 4mo agoI think it's more similar to the idea of IPFS than Tailscale. It's excellent for example for decentralized networks where there is missing trust; file sharing, bittorrent, blockchain networks etc, where you don't want to manage the complexity of dropping IP addresses at the application layer. I initially found it for parture.org for example.
- grumbel 4mo agoThat explanation still seems overly complicated. Iroh isn't a VPN. Iroh just lets apps connect to each other, just like plain old TCP, but without the shackles of NAT, DNS and dynamic IP addresses that made that impossible. It's restoring simple P2P connectivity to the Internet.
- worldsayshi 4mo agoAlso, all connections in iroh are end-to-end encrypted.
- HappMacDonald 4mo agoThat.. makes it sound to me a lot like a VPN though
- tecleandor 4mo agoThat would make SSH look like a VPN ;)
- Perepiska 4mo agoAnd bypass all the firewalls if secret key of target machine is known?
- rklaehn 4mo agoYou only need to know the public key of the target endpoint. It will work even on very restrictive firewalls. Even if they outright ban UDP packets, we will fall back to the relay connection which is https/websocket. Note that here is not a single keypair per machine, but per endpoint. You can have multiple endpoints on one machine.
- piokoch 4mo agoStill I am not sure why I should use their paid service instead of using publicly available infrastructure. If they go out of business, get sold what's then? DNS and friends are not going to disappear and send me "it was great journey" e-mail. Maybe for some specific applications, like P2P chats, this makes sens, but how many of such applications are needed? I've looked at the usecases page, obviously there is an AI stunt (which I don't buy at all), for POS applications, well, there are better and less risky (see above) ways to do this, so the only thing that seems to make sense is this real-time sync, if someone is in the restricted environment (but, the point is, that in the restricted environment iroh is going to be blocked anyway by firewalls, z-scaler, etc.).
- gf000 4mo agoThey host a relay server that is available to everyone, but you are expected/recommended to use your own for most use cases, so you will have only depend on open-source code and your own infra.
- angry_octet 4mo agoHow do I add firewalls and proxies and logging to iroh connections? How do I revoke and re-issue iroh keys? Can I host iroh relays/gateways on my intranet? Until these questions are answered iroh will remain blocked.
- nvme0n1p1 4mo agohttps://docs.iroh.computer/ https://docs.iroh.computer/
- rklaehn 4mo agoYou don't have to use it. But here are some answers: Re-issuing keys is as simple as generating a new Ed25519 keypair. let secret_key = SecretKey::generate(); // takes less than a millisecond Iroh as of now has no fleet management. So the concept of revoking a key is something you would have to add yourself. We have extensive logging for iroh. You can enable trace logging and even enable qlog for detailed connection logs. You can view the logs in any qlog viewer. We have written one, but there are others. It is an open standard for QUIC logs. https://datatracker.ietf.org/doc/draft-ietf-quic-qlog-main-schema/ https://datatracker.ietf.org/doc/draft-ietf-quic-qlog-main-s... https://github.com/n0-computer/qlog-viewer https://github.com/n0-computer/qlog-viewer The iroh relay library and binary are open source just like everything else in the core. You can of course run a relay in your intranet, but the exact details depend on the use case. Get in touch if you have a demanding use case and want us to help.
- angry_octet 4mo agoThanks for responding. By logging I mean a gateway/proxy which logs connection metadata, not client side logging. Possibly this is something that could be added to a private relay. With a network of private relays you could form admission controlled virtual overlay networks for each application. For key revocation, it is necessary to be able to invalidate a server accepting a key, without necessarily having the key. E.g. maybe you have a pre-generated proof enabling revocation. Observability is super important for organisations. Especially with LLM servers and MCP interfaces popping up everywhere.
- jupin 4mo agoI found this interesting to learn how Tailscale works: https://tailscale.com/blog/how-tailscale-works https://tailscale.com/blog/how-tailscale-works
- tecleandor 4mo agoWell, Iroh is more P2P (direct connections) and less VPN (subnet routing). If anyone really wants to use Tailscale (or I think Headscale should work too) at application layer, you can use tsnet [0] -- 0: https://tailscale.com/docs/features/tsnet
- vinceguidry 4mo agoA much better answer to the question "why not just use Tailscale?" is that critical functionality only is available with cloud hosting, self-hosted headscale just doesn't offer a usable solution. > If you want to release an app and have instances of your app be able to easily connect to each other, you could theoretically embeded Tailscale functionality into your app, but then the users of your app need Tailscale accounts, and your app is dependent on Tailscale. Just use Wireguard directly like everyone else.