# A qriton mesh relay on Azure

The relay is a plain NATS server. qriton seals every payload end to end, so the relay sees only opaque bytes on opaque subjects: it cannot read, forge or replay messages, and it never holds a group key. It still sees client IP addresses, message sizes and timing.

On a trusted local network you can skip all of this and run `nats-server` on any machine; the mesh is end-to-end encrypted either way.

## 1. A small VM with a DNS name

```bash
az group create -n qriton-mesh -l westeurope
az vm create -g qriton-mesh -n relay --image Ubuntu2404 --size Standard_B1s \
  --admin-username azureuser --generate-ssh-keys --public-ip-address-dns-name <label>
az vm open-port -g qriton-mesh -n relay --port 4222 --priority 900
az vm open-port -g qriton-mesh -n relay --port 80 --priority 910   # only while issuing the certificate
```

The relay's name is `<label>.westeurope.cloudapp.azure.com`.

## 2. nats-server, pinned and verified

```bash
ssh azureuser@<label>.westeurope.cloudapp.azure.com
curl -fsSL -o nats.tar.gz https://github.com/nats-io/nats-server/releases/download/v2.15.0/nats-server-v2.15.0-linux-amd64.tar.gz
echo "5d2c51caca950333aba84911df7d377f826f3a59ec36061c6539105084f65c92  nats.tar.gz" | sha256sum -c -
tar -xzf nats.tar.gz && sudo install -m 755 nats-server-v2.15.0-linux-amd64/nats-server /usr/local/bin/
sudo useradd --system --no-create-home --shell /usr/sbin/nologin nats
```

## 3. A TLS certificate

```bash
sudo apt-get install -y certbot
sudo certbot certonly --standalone -d <label>.westeurope.cloudapp.azure.com
sudo install -d -o root -g nats -m 750 /etc/nats/tls
sudo cp /etc/letsencrypt/live/<label>.westeurope.cloudapp.azure.com/{fullchain,privkey}.pem /etc/nats/tls/
sudo chgrp nats /etc/nats/tls/*.pem && sudo chmod 640 /etc/nats/tls/*.pem
```

Then close port 80 again (`az network nsg rule delete ...`, or open it only for renewals) and add a renewal hook that copies the new files and runs `systemctl reload nats-server`.

## 4. Configuration and machine keys

Copy `nats-server.service` from this folder to `/etc/systemd/system/nats-server.service`. For the configuration, collect each machine's **NATS user key** (`qriton mesh status` on it) and let qriton write the file, with your own machine's key included:

```bash
qriton mesh server tls /etc/nats/tls/fullchain.pem /etc/nats/tls/privkey.pem UD4K2P7Q... > nats-server.conf
```

Copy it to `/etc/nats/nats-server.conf`. Or start from `nats-server.conf` in this folder and add a line per machine to the `users` list:

```
users = [
  { nkey: "UCCBXLED...", permissions: $QRITON }   # laptop
  { nkey: "UD4K2P7Q...", permissions: $QRITON }   # windows server
]
```

```bash
sudo nats-server -c /etc/nats/nats-server.conf -t       # check the file
sudo systemctl daemon-reload && sudo systemctl enable --now nats-server
```

To remove a machine, delete its line and `sudo systemctl reload nats-server`. The server stores public keys only.

## 5. The group

```bash
qriton mesh init tls://<label>.westeurope.cloudapp.azure.com:4222   # on the first machine; prints an invite code
qriton mesh join <code>                                             # on each other machine
```

The invite code contains the group secret: pass it only over a channel you trust, never through the relay. Then set `"mesh": { "enabled": true }` in each machine's `~/.qriton/config.json`. `/peers` shows every machine's fingerprint; compare fingerprints out of band once.

If a machine is lost or no longer trusted, remove its NATS key from the server and create a new group (`mesh leave`, `mesh init`, fresh invites) so the old group secret stops working.
