Real authoritative DNS for domains you delegate to us — resolving directly when your server is reachable, or through a relay when it isn't. Ownership is a bearer credential, not an account, so there's nothing to suspend and no relationship to terminate.
EphemNet is a real authoritative DNS server for domains delegated to it. Every domain resolves one of two ways:
The DNS answer is your server's own real IP. Zero ongoing involvement from us after that — exactly like ordinary DNS. No relay, no bandwidth cost, no protection.
The DNS answer is our relay's IP. Your server — even behind NAT, with no public IP at all — runs a small agent that holds a persistent tunnel to us. We route by TLS SNI and forward the still-encrypted bytes through, untouched. We never decrypt your traffic; TLS terminates at your own server.
This isn't a static choice — you can switch a domain between the two on demand (say, when an attack starts), through the same authenticated update channel used for anything else about your domain.
Cloudflare Tunnel is free, unmetered, and backed by a global edge network we can't match on latency or ease of setup. If that were the pitch, it wouldn't be worth making.
The actual, narrower edge: every registrar and every major DNS provider requires an account tied to a real identity — and has the power to unilaterally decide you're not welcome anymore. Ownership here is a bearer credential, paid for with Lightning, no KYC. There's no account to suspend and no company relationship to terminate.
That matters specifically to people who have real deplatforming risk as part of their threat model — independent journalists, minority-language communities, anyone whose legitimate service is one policy decision away from being cut off. It's not a general "Cloudflare alternative" pitch, and we'd rather say that plainly than oversell it.
Certificates — we support ACME DNS-01 automation: your own
certbot/lego/etc. still talks to your CA of choice
directly, we just publish the _acme-challenge TXT
record it needs. Works identically whether you're in direct or
relay mode.
Ownership — currently provisioned by hand while the payment/ownership layer is built out (see the timeline below); the end state is capability-key, macaroon-based ownership with no accounts, the same philosophy cinder uses, though EphemNet has no runtime dependency on cinder's code.
Full design writeups live in this repo's own
plan/ directory if you want the real detail, caveats
included.
ephemnet-agent is the reverse-tunnel client: run it
on any host with no public IP of its own to make it reachable
through relay mode. Single static binary, no install process.
A decentralized relay swarm — route to a host by a rotating, seed-derived identifier instead of a domain name, resilient to DDoS, usable behind NAT. Real design work, real prototypes, genuinely hard to get right at that scope.
Realizing that vision's actual value doesn't require the swarm to start: a single, well-run node doing real DNS resolution — direct or relayed — with the same capability-key ownership pattern already proven elsewhere delivers the same practical outcome sooner, with the swarm/federation layer deferred until real usage actually demands it, not abandoned.
Direct and relay resolution, ACME DNS-01 automation, and on-demand mode-switching are built and tested. Real macaroon- based ownership (replacing today's manually-provisioned domains) is the next real milestone.