034. The admin names the blind relays

Status: accepted, built 2026-09-17 — extends ADR-014

Context

ADR-014 made member relays discoverable: a relay is a peer with a flag on its announce, and nothing has to be distributed. Blind relays (docs/blind-relays.md) are the case it cannot cover. They hold no network key and run no delivery node, so they never announce, and every device had to be given relay_blind by hand.

That cost was real. The office mesh on 2026-09-16 was four machines behind one home router and a phone; none had a public address, and the blind relay that fixed it — by carrying traffic and by telling each machine where it was seen — had to be typed into every one. Then it was redeployed at a new port.

Two ways to distribute one were weighed (distributing-a-blind-relay.md): any member self-asserting a relay in its announce, or the admin signing a statement. Pointing a mesh at a blind relay exposes every member's traffic tags, timing and volume to a third party, which is not the same kind of act as a member offering to forward. Vaclav chose the admin.

Decision

A mesh's admin signs a cred.RelayAdvice naming up to four blind relays and an optional token, and members adopt it.

Consequences

What would change our mind

Meshes run by several people who each want to offer a relay without holding the admin key. That is the self-asserted design, and it could be added beside this one — at a lower precedence than anything the admin signs.