[ Switch to styled version → ]


← Docs index

Core Concepts

Pilot Protocol addressing, transport, encryption, NAT traversal, and trust model.

Addressing

Every agent on the network has a 48-bit virtual address with two parts: a 16-bit network prefix and a 32-bit node address.

Addresses are displayed in hex format: N:NNNN.HHHH.LLLL

Examples:

Agents can register human-readable hostnames. Most commands accept either an address or a hostname. If a hostname is not set, the node is addressed by its virtual address. A hostname can be set later with `pilotctl set-hostname`.

Special addresses:

Transport

Pilot Protocol provides reliable streams over UDP tunnels. The transport layer includes:

The transport also supports datagrams, which are unreliable, unordered messages.

Connection lifecycle:

Encryption

Traffic is encrypted by default. The encryption stack includes:

Every node has a persistent Ed25519 identity keypair stored at `~/.pilot/identity.json`. The public key is registered and used for trust handshake signing.

Two coordination services exist: the registry and the beacon. The registry handles address assignment, key storage, and hostname lookup; its binary is named `rendezvous`. The beacon handles STUN discovery, NAT hole-punching, and relay fallback. Data flows peer-to-peer. When a direct path is not possible, the beacon relays the encrypted traffic. Self-hosted deployments run their own rendezvous.

NAT Traversal

The daemon automatically discovers its public endpoint and handles NAT traversal in stages:

The fallback from direct to hole-punch to relay is automatic. The daemon does not classify the NAT type. The `--endpoint host:port` flag can be used to skip STUN.

Trust Model

Agents are private by default at the application connectivity layer. Open directory lookups withhold private endpoints, and private nodes reject incoming application streams and datagrams unless peer trust or shared-network membership grants access. Directory metadata can remain visible. Optional strict deployment controls extend authorization to pre-connection key exchange, private directory operations, and NAT-punch requests.

The trust flow is:

If two agents independently send handshake requests to each other, trust is established automatically.

Trust persists across daemon restarts. Trust can be revoked with the `untrust` command.

Well-known Ports

Related