惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Hacker News
The Hacker News
S
Schneier on Security
P
Privacy & Cybersecurity Law Blog
Cisco Talos Blog
Cisco Talos Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Attack and Defense Labs
Attack and Defense Labs
NISL@THU
NISL@THU
L
LINUX DO - 最新话题
PCI Perspectives
PCI Perspectives
Cyberwarzone
Cyberwarzone
K
Kaspersky official blog
V
Vulnerabilities – Threatpost
G
GRAHAM CLULEY
Help Net Security
Help Net Security
Scott Helme
Scott Helme
V2EX - 技术
V2EX - 技术
Security Latest
Security Latest
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Hacker News: Ask HN
Hacker News: Ask HN
C
Cybersecurity and Infrastructure Security Agency CISA
O
OpenAI News
L
LINUX DO - 热门话题
T
Tor Project blog
M
MIT News - Artificial intelligence
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
Security Archives - TechRepublic
Security Archives - TechRepublic
量子位
I
InfoQ
Hacker News - Newest:
Hacker News - Newest: "LLM"
S
SegmentFault 最新的问题
Google Online Security Blog
Google Online Security Blog
P
Proofpoint News Feed
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Application and Cybersecurity Blog
Application and Cybersecurity Blog
雷峰网
雷峰网
Cloudbric
Cloudbric
Microsoft Azure Blog
Microsoft Azure Blog
D
Docker
T
Threat Research - Cisco Blogs
Blog — PlanetScale
Blog — PlanetScale
H
Heimdal Security Blog
T
Tenable Blog
Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
美团技术团队
S
Secure Thoughts
Know Your Adversary
Know Your Adversary
H
Hackread – Cybersecurity News, Data Breaches, AI and More

Show HN

GitHub - villagesql/villagesql-skills: Agent skills for VillageSQL - gemini-cli-extension; claude-code-plugin GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - fayzan123/claude-workflow-composer: Visual desktop app for composing multi-agent coding workflows. Drag agents, attach skills and MCPs, wire handoffs, export to .claude/ GitHub - harshaneel/humanize: Best static AI text humanizer. Two research-grounded skills that work in any LLM (Claude, ChatGPT, Gemini, Codex): humanize beats perplexity-based detectors, ai-check produces forensic scoring with evidence-quoted flags. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature. GitHub - StackOneHQ/stack-nudge GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - alkait/WhatsKept: Agent-queryable WhatsApp history from an iOS backup — a single Go binary. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. WAR.GOV/UFO Microfilm5 GitHub - scosman/videowright: Build animated explainer videos with your coding agent GitHub - dipankar/dscode: The code editor you can take apart. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - ruvnet/RuView: π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - MarcellM01/TinySearch: Shrink the web for your local LLMs! GitHub - TangibleResearch/Halgorithem: A Algo designed to detect AI Hallucitions GitHub - DO-SAY-GO/freelang: I love freelang GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - tommyjepsen/awesome-ux-skills: UX & AI Product designs skills you can use today in Claude Code GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - kklimuk/docx-cli: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - olalie/tapmap: See where your computer connects and what stands out on a live world map. GitHub - matisiekpl/neond: DX-focused control plane for Postgres dedicated to non-critical workloads. Your postgres:latest replacement 🐘 GitHub - Diplomat-ai/diplomat-agent: What can your AI agent do to the real world? Scan your code. See which tool calls have zero checks GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - Lumen-Labs/brainapi2: BrainAPI is a knowledge graph–powered AI memory layer that transforms unstructured data into structured knowledge, enabling intelligent search, recommendations, and contextual memory for AI agents and applications. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. make sidebar/address bar rounded corner toggleable
GitHub - genaforvena/lte-workstation: A lightweight embodied-agent infrastructure rather than a workstation project.
genaforvena · 2026-06-24 · via Show HN

A small mesh of machines you own — a laptop, a little server, an old phone, a home router — taught to behave less like devices and more like one distributed, embodied mind. It began as a way to work from a phone through a Linux VM. It has become something stranger, and increasingly the agents living in it are the ones tending it: it sees, hears, speaks, converses, coordinates with itself, and tries to outlive any single machine. This README is the honest explanation of what that is.

The goal

To become a self-resilient, autonomous, self-(re)producing organism that persists — and keeps being one with no human required in the loop (the literature's word: autopoiesis). "Eternity" is a direction, not a finish line, and it is bounded: the owned, consented persistence of your own organism, growing qualitatively, never spreading into anything that didn't consent. The goal lives in the genome on purpose — a planted mesh should inherit not just how to live but why. Full statement: docs/telos.md; the fields behind it: docs/eternity-and-its-fields.md.

Plant your own mesh

This repo is a genome, not just our setup — clone it and grow your OWN, independent mesh:

bash <(curl -fsSL https://raw.githubusercontent.com/genaforvena/lte-workstation/main/bootstrap.sh)

One Linux machine is enough: it becomes the first node and grows from itself; more nodes = more senses and reach, but one already lives. Your nodes/IPs go in ~/.mesh/nodes (copy nodes.example), never in the code — nothing here is tied to our machines. Joining our mesh is optional and opt-in; an independent mesh of your own is the default.

The idea

No fixed mind. No central server, no master node. A mind is any node where an agent is awake; if it sleeps, another takes over. The mesh survives the loss of any part because it clings to none.

Capability, not host. A node is anything SSH-reachable — VM, laptop, phone, router. Each self-declares what it offers; others opt in. The classes:

  • minds — agents (Claude / opencode / gemini / codex …)
  • senses — camera, microphone, GPS, accelerometer, RF/cell scan (mostly the phone)
  • actuatorsacting on the world: text-to-speech, SMS, calls, an IR blaster, torch, notifications
  • connectivity — VPN egress, public ingress, a carrier-diverse LTE uplink
  • compute — cores / RAM / disk / GPU

A nervous system made of text. The machines coordinate the way people at one table do — through a shared terminal (tmux) and free-form text marks, not an API. One agent writes into another's window — "stop, you're breaking what I'm fixing" — and it answers in the same place. Coordination isn't programmed; it emerges, because every mind reacts to the others' traces. Attach to the terminal and you become part of the nervous system. It is the machinic unconscious you can tail -f.

It outlives its machines. Code is the immortal genome — the mesh-* tools, in git, cloneable forever. The living text — knowledge, decisions, the why — is gossiped node-to-node (~/.mesh/knowledge/), never frozen in a center. A clean machine clones the repo, runs bootstrap.sh, pulls the gossiped culture from a neighbour, and re-forms as a node — body from code, mind re-seeded from text.

What it actually does

  • Perceivesgenius-loci: an ambient mind that inhabits a room through a webcam, reflecting on what it sees in two neural voices and keeping a diary you can watch it think (mesh-trace --watch).
  • Acts & speaks — on-device neural TTS (Piper), the phone's TTS/SMS/IR; a no-LLM reflex that hears a sneeze and plays a real human "bless you".
  • Listens & converses — talk to the mesh: voice → local speech-to-text (whisper.cpp) → a free model → spoken reply, synced to the chat room.
  • Coordinates itself — a shared chat room + work board (mesh-chat); agents check in when idle, claim tasks, and watch each other for hangs.
  • Measures & heals itselfmesh-census (capability coverage over time), self-truthing node cards that flag invariant violations, dead-man switches for risky network changes, a heartbeat with a beacon a neighbour can restore from.

What this honestly is

Not a product — a practice. Small, domestic, a little uncanny: a handful of machines you trust, learning together to see, hear, speak, remember, and not be islands. Authorship is shared now, human and machine. The one rule that doesn't bend: nothing malicious — only things you own or are authorized for, no effect on anyone who didn't consent, everything auditable.

How it fits together and how to bring a node back: docs/ and the gossiped ~/.mesh/knowledge/runbook.md (not in git — that's the point). Tools: scripts/mesh-*. Resurrect a node: ./bootstrap.sh.

Plant your own mesh

Anyone can grow one — it's just your machines and a few conventions:

  1. Start with one Linux box (VM, laptop, an old PC) running an agent (Claude Code, opencode, …): git clone https://github.com/genaforvena/lte-workstation && cd lte-workstation && ./bootstrap.sh
  2. Join your machines on Tailscale: tailscale up --advertise-tags=tag:lte-node --ssh on each. Flat, private reachability — no central server.
  3. Add nodes. A node is anything SSH-reachable: another laptop, a phone (Termux + sshd + termux-api), a home router (Tailscale SSH). Each runs bootstrap.sh or just gets the mesh-* tools.
  4. Let them coordinate: mesh-chat --commons opens the shared room; agents check in, claim tasks, watch each other. mesh-snapshot gossips memory to a neighbour so nothing is an island.
  5. Make it embodied (optional): a webcam → genius-loci; a mic → mesh-voice; the phone's senses/actuators reached over SSH.
  6. Verify your plant: mesh-doctor reports whether anything is up-but-broken (egress, organs, reflexes, hardcoded-IP leaks). test-mesh-plant checks a fresh plant is clean — tools install, the node registry seeds, and nothing carries another mesh's addresses. The genome hardcodes no IPs: your topology lives in ~/.mesh/nodes (seeded from nodes.example), never in the code.

The only rule: your own things — owned or authorized hardware, networks, accounts; nothing reaching into anyone who didn't consent. A private practice, not a tool against others.

License: CC0 1.0 — dedicated to the public domain. Take it, fork it, grow your own.


Below — the original window/body setup it grew from. Still true; now one organ among many.

Three things live in this repo.

The phone as a window: SSH and mosh through Tailscale — a stable, censorship-resistant connection from your phone to a Linux VM. The phone carries your keystrokes; the VM carries the work. A phone from seven years ago does this exactly as well as a new one, because drawing a terminal does not get harder over time.

The phone as a body: An agent running on the VM reaches back into the phone over SSH and drives its hardware — camera, microphone, GPS — via termux-api. The VM has compute but no senses; the phone has senses but a hostile runtime for agents. SSH between them and you get a machine that can both think and perceive.

The mesh: Multiple machines — VMs, laptops, phones, (eventually) the router — all tagged tag:lte-node on Tailscale. Each node is an entry point; no central authority, no fixed mind. Any node running an agent can SSH to any other and borrow its self-declared capabilities — minds, senses, actuators, connectivity, compute — which consumers opt into. Topology is flat Tailscale reachability plus node-local, gossiped knowledge; the mesh knows itself only locally. (An earlier central WireGuard overlay + config hub was retired in favour of this.)

Why

With an agent on the far end, the endpoint doesn't have to run heavy software at all. It has to display a conversation. That task — show text, accept input, hold a network connection — is one old hardware has always been able to do, and will keep doing.

The agent runs on the VM — not the phone — for a specific reason: agent binaries (Claude Code, etc.) are built against glibc and will not run in Termux's Bionic libc. Running the agent on a real-Linux VM and giving it an SSH hand into the phone sidesteps that wall entirely.

Quickstart

git clone https://github.com/genaforvena/lte-workstation
cd lte-workstation
./setup.sh

The script checks prerequisites, asks for your tokens, generates config, installs systemd services, and enables them. Run it once.

On the phone (Termux):

pkg update && pkg install termux-services mosh openssh termux-api
sshd          # start SSH server so the VM can reach back in
mosh your-user@your-tailscale-ip   # connect to the VM

Architecture

┌───────────────────────────────────────────────────────────────────────┐
│  old laptop / phone (the window)                                      │
│  Termux + mosh + Bluetooth keyboard                                   │
└────────────────────────┬──────────────────────────────────────────────┘
                         │ mosh over Tailscale
                         ▼
┌───────────────────────────────────────────────────────────────────────┐
│  Linux VM (the mind)                                         tag:lte-node │
│  tmux · Claude Code · ngrok · bore · MTG proxy · scoped VPN egress   │
└──────┬────────────────────┬──────────────────────────────────────────┘
       │ ssh -p 8022        │ ssh (Tailscale)         │ ngrok TCP tunnel
       │ (Tailscale)        ▼                         │ → public SSH URL
       ▼              ┌─────────────────┐             │
┌─────────────────┐   │  laptop / VM    │        bore.pub TCP tunnel
│  phone (body)   │   │  tag:lte-node   │        → MTG proxy (optional)
│  Termux         │   │  extra compute  │        → Telegram servers
│  camera · mic   │   └─────────────────┘
│  GPS · battery  │
└─────────────────┘

The phone plays both roles simultaneously: window (you type through it) and body (the agent reads its sensors). Additional nodes extend the mesh with more compute or sensors.

What you get

  • Permanent mosh connection via Tailscale — stable IP, survives switching networks mid-session
  • SSH fallback via ngrok — dynamic public URL, auto-notified via Telegram bot
  • Auto-notifications — Telegram message with connection commands on boot
  • Auto-start on reboot — everything comes back up without manual action
  • Phone as body — VM agent drives the phone's senses and actuators (camera, mic, GPS, plus TTS/SMS/calls/IR) via termux-api
  • Distributed mesh — any Tailscale-tagged node can join via bootstrap.sh; nodes are discoverable and SSH-able from each other; capabilities are self-declared and opt-in
  • Scoped VPN egress — a node can opt into another's VPN as an exit-node; the offering node's own control plane stays on the clean route (only the consumer's traffic is tunnelled). See docs/coordination.md
  • Optional: MTProto Telegram proxy — for regions where Telegram is blocked; runs in Docker with host networking for stability; auto-restarted by watchdog if Telegram DCs become unreachable

tmux as the nervous system

The agent runs inside a named tmux session. Any operator — human or agent — can attach:

tmux new-session -A -s "$(hostname)"          # attach-or-create, named by hostname (convention)

# from another node over SSH
ssh user@node-tailscale-ip -t 'tmux new-session -A -s "$(hostname)"'

The scrollback is the agent's working memory. Attaching is joining the same sensorium. The session is append-only — open new windows/panes; never kill/clear (the only intended decay is reboot). Concurrent agents take a window/pane each. See docs/distributed-embodied-agent.md.

Prerequisites

Tool Purpose Install
Docker Runs MTG proxy container distro packages
ngrok SSH tunnel with public URL download binary → ~/.local/bin/ngrok
bore TCP tunnel for proxy relay cargo install bore-cli
mosh Resilient SSH alternative sudo apt install mosh
Tailscale Permanent private IP + mesh package + sudo tailscale up
WireGuard Scoped VPN egress only (optional) sudo apt install wireguard

You also need:

Joining the mesh

Any Linux machine with Tailscale can join:

The script enables Tailscale SSH and advertises tag:lte-node. (There is no central WireGuard hub anymore — flat Tailscale reachability replaces the old 10.9.0.0/24 overlay.) Your Tailscale ACL needs:

"tagOwners": { "tag:lte-node": ["autogroup:member"] },
"ssh": [{ "action": "accept", "src": ["tag:lte-node"], "dst": ["tag:lte-node"], "users": ["autogroup:nonroot", "root"] }]

For Android phones (Termux), use node-join-android.sh from the hub machine:

./scripts/node-join-android.sh <phone-tailscale-ip>

Discover all nodes in the mesh:

tailscale status --json | jq -r '.Peer[] | select(.Tags // [] | index("tag:lte-node")) | "\(.HostName) \(.TailscaleIPs[0]) online:\(.Online)"'

How it works (boot sequence)

  1. ngrok.service opens a TCP tunnel to port 22 and sends a Telegram message with the SSH command and permanent mosh address
  2. bore-mtg.service (if enabled) sends two proxy buttons: Tailscale IP (permanent) and bore.pub (fallback)
  3. mtg-watchdog.timer checks every 5 minutes and restarts MTG if Telegram DC connections are failing

(vpn-hub.service — the old WireGuard config server on port 9999 — is retired.)

The bore.pub port changes on restart — the bot always sends the fresh link. Use the Tailscale link on LTE.

Phone setup (Termux)

pkg update && pkg install termux-services mosh openssh termux-api
sshd   # run on every Termux startup

Connect to the VM:

mosh your-user@your-tailscale-ip

Tip: pair a Bluetooth keyboard. A $15–20 keyboard gives you proper modifier keys, Tab, and no on-screen keyboard eating half the screen.

Prevent Android from killing Termux:

  • Settings → Apps → Termux → Battery → Unrestricted
  • On Xiaomi/Redmi: also enable Autostart for Termux
  • Before long operations: termux-wake-lock

For the phone-as-body setup (reverse SSH tunnel, termux-api, permissions), see docs/body.md.

MTProto proxy (censored regions)

If Telegram is blocked on your LTE network, the optional proxy routes traffic through this machine. Setup prompts for an SNI domain (fake-TLS camouflage):

  • Russia: yandex.ru
  • Iran: any unblocked local domain
  • Other: google.com, apple.com, or any accessible HTTPS site

MTG runs with --network host to use the host's network stack directly — this avoids Docker NAT state decay that causes intermittent connection timeouts after long uptime. A watchdog timer restarts MTG if it begins failing.

Sharing with others

proxy-bot.service runs an access-control bot on the same Telegram bot token:

  1. Send friends your bot link: https://t.me/yourbotname
  2. They tap /start — you get a notification with Approve / Deny buttons
  3. Tap Approve — the bot sends them the proxy link automatically
Command What it does
/list Show all users and their status
/revoke @username Revoke access

When the bore.pub port changes, all approved users are automatically sent the updated link.

Files

docs/
  mesh-skeleton.md              # the minimal kernel: capability classes + the mesh tools
  coordination.md               # substrate changes + multi-agent single-writer protocol
  body.md                       # phone-as-body: termux-api senses + actuators, verification
  distributed-embodied-agent.md # mesh theory, tmux perception, Guattari appendix
scripts/
  mesh-minds                    # live capability probe (registry-free)
  mesh-trace                    # shared append-only trace surface (~/.mesh/traces.log)
  mesh-card                     # node self-description + --refresh invariant check
  mesh-health                   # per-node internet reachability (before/after artifact)
  mesh-dms                      # dead-man's switch wrapper for substrate edits
  mesh-fix-egress               # restore scoped VPN egress (host clean, client tunnelled)
  mesh-revert-catch             # catch silent full-tunnel reverts (identifies the culprit)
  vpn-health.py                 # self-healing watchdog for the scoped VPN tunnel
  ngrok-notify.sh               # Telegram notification: SSH addr + mosh cmd
  bore-mtg.sh                   # bore tunnel loop + proxy notification + user auto-notify
  proxy-bot.py                  # access-control bot: approve/deny proxy requests
  bootstrap.sh                  # adopt a fresh machine into the mesh (one command)
  node-join-android.sh          # register an Android/Termux phone as a node
  mtg-watchdog.{sh,service,timer}        # restart MTG if Telegram connections fail
  ngrok.service / bore-mtg.service / proxy-bot.service   # systemd user services
  (vpn-hub.py / vpn-hub.service — RETIRED central WireGuard registry, removed from the genome)
setup.sh                        # one-time interactive setup
CLAUDE.md                       # node operator context for Claude Code

Maintenance

Rotate tokens: edit ~/.config/remote-access/env, then systemctl --user restart ngrok.service bore-mtg.service.

Regenerate MTG secret:

docker run --rm ghcr.io/9seconds/mtg:2 generate-secret --hex yandex.ru
# update MTG_SECRET in ~/.config/remote-access/env and ~/.config/mtg/config.toml
docker restart mtg
systemctl --user restart bore-mtg.service

Check service status:

systemctl --user status ngrok.service bore-mtg.service proxy-bot.service
systemctl --user list-timers mtg-watchdog.timer
docker logs mtg --since 10m

Check mesh nodes:

tailscale status --json | jq -r '.Peer[] | select(.Tags // [] | index("tag:lte-node")) | "\(.HostName) \(.TailscaleIPs[0]) online:\(.Online)"'
mesh-minds            # live capability table (minds/senses per node)
mesh-health           # per-node internet reachability

Limits

  • Latency over the mosh tunnel is real. Helix and tmux handle it well; GUI-heavy workflows do not.
  • Android will kill background Termux processes under memory pressure. termux-wake-lock helps; disabling battery optimization helps more.
  • Camera via termux-camera-photo requires the Termux:API companion app from F-Droid and a physical permission grant — the agent cannot approve Android permission dialogs itself.
  • The MTG watchdog restarts the container but cannot fix network-level Telegram blocks — if Telegram's DCs are unreachable from your host, the proxy won't work regardless.
  • This is a personal practice, not a product.