iron - P2P mesh network based on iroh
README.md

Sandboxed VM integration tests #

These Linux-only NixOS checks boot three disposable VMs on a virtual LAN. The infrastructure VM runs local iroh relay and pkarr/DNS servers; the tests do not depend on public n0 services.

Check What it verifies
iron-vm-ping-pong Workspace-pinned iroh endpoints discover a peer by EndpointId using local infrastructure, then exchange ping/pong without iron or a TUN.
iron-vm-two-node Iron carries HTTP traffic in both directions, addressed by <key>.iron names.
iron-vm-lossy-network A 10 MiB TCP transfer addressed by .iron name retains its checksum with 5% outgoing loss on both peers.
iron-vm-outage The same TCP connection carries new data after a 45-second, 100%-loss blackout. It does not independently assert QUIC expiry or reconnection.

The shared iron harness verifies DNS first, then connectivity by .iron name, then connectivity by iron IPv6 address. Application clients use .iron names and servers listen on IPv6 any (::). Expected fd69:726f::/32 addresses in DNS assertions are tunnel addresses, not sandbox LAN addresses. Link faults are applied to eth1, below the tunnel; eth0 is QEMU user networking.

Run a check with a Linux builder supporting kvm and nixos-test:

nix build .#checks.x86_64-linux.iron-vm-two-node --no-link -L

Use --rebuild to rerun an already built check rather than reuse its result. Keep new files Git-tracked so the default flake source includes them. The driver logs every command under named behavior-level subtests, with bounded readiness waits and service journals on setup failure.

Interactive debugging is available through a check's .driverInteractive attribute, but internet access there is not equivalent to the automated sandboxed build. Use the automated checks as validation evidence.