Skip to content

Security

How Meshive protects host machines — encryption, port surface, credential rotation, and hardware-change re-verification.

Every link in the system is encrypted:

  • Node-to-node traffic flows over Tailscale VPN (WireGuard).
  • Control-plane traffic (agent ↔ Meshive backend) is HTTPS.
  • Pod isolation prevents clients from reaching the host OS — they get their own namespace with the permissions they need, and nothing more.

The result: a client renting a pod on your machine cannot see your filesystem, your other clients, or anything outside of their sandbox.

Clients can also opt to have their storage volumes encrypted at rest on your disks. The agent manages this entirely — no setup or action on your side — and the encryption key is never stored on your machine, so an encrypted volume’s contents are unreadable outside its normal use.

Many platforms ask hosts to expose hundreds of ports. Meshive asks for four, full stop:

PortPurpose
22/tcpHost SSH (managed, monthly rotation)
2222/tcpPod SSH proxy
443/tcpAgent ↔ control plane
41641/udpTailscale VPN

Everything else is firewalled at the agent. Less surface → less risk.

  • SSH and IPMI passwords rotate every month, automatically. New credentials always appear on the Host dashboard.
  • Repeated failed login attempts trigger an automatic IP block.
  • If you prefer key auth, register your own public key in the dashboard alongside the rotating password.

Hardware reliability is the foundation of host trust, so any of the following automatically triggers a mini stress test (~30 minutes) before the machine returns to the pool:

  • GPU change — a GPU shows up that hasn’t passed a stress test on this machine: a card was added or replaced, even with the identical model. Every GPU is tracked by its unique GPU ID, read once the GPU driver is up after boot. Removing GPUs does not trigger a test.
  • Motherboard change — the platform treats this as a full system rebuild, since every component has to be re-seated.
  • CPU change — a different CPU model is detected.
  • Unexpected shutdown — the previous boot ended without a clean shutdown (power loss, crash, overheating, or a fatal GPU error).

You do not need to flag these changes manually; the machine is checked every time it boots. While the test runs, the machine is unlisted and pods running on it are paused — they restart automatically when the test passes.

In addition to the mini stress test above, every host runs:

  • A disk and internet speed test once every 7 days, to catch slow degradation early.

If a routine check reports a problem, the dashboard surfaces it before it becomes a client-visible incident.