A new Hetzner account is capped at 10 primary IPs (IPv4 and IPv6 both count), 20 shared vCPUs, 8 dedicated
vCPUs and no Arm, and a network cannot span zones. So: one private network per zone (10.20.<zone>.0/24),
the lowest-index node of each zone keeps a public IPv4 and is its gateway (NAT, MSS clamp, one DNAT port
27000+index per private node, persisted as igneum-nat.service), every other node has no public address.
nodes.tsv gains access, pub and port columns; lib resolves same-zone vs cross-zone dial addresses and jumps
ssh through the gateway for private nodes. All nodes.tsv loops read on fd 3 (a backgrounded ssh drained the
file). TYPE_BY_INDEX puts nodes 8 to 11 on ccx13; node 12 is the last shared one the account allows.
create.sh prints the plan's cost from the live API. provision.sh install takes node names and skips binaries
whose sha256 matches. Binaries copied from the seed's staged v4 build (same sources), no vCPU for a builder.
Results 2026-10-04: RTT matrix (hel1-fsn1 35 ms, ash-sin 289 ms) and a 10-minute propagation window of 644
blocks: p50 343 ms, p90 497 ms, p99 666 ms across 12 nodes in 5 locations.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/cross/build-linux.sh builds igneumd and igneum-miner for x86_64-unknown-linux-gnu.2.36 (Debian 12) with
cargo-zigbuild 0.23.4 and zig 0.17.0 into vendor/igneum-node/target-linux: rocksdb, lz4, blst, secp256k1 and the
execution layer all link through zig, no crate failed (Docker is absent here, so cross was not needed). Cold build
1,856 s at 4 jobs, nice 19, on a loaded Mac; the seed's own build took 55 min and the builder VM 10 to 25.
Verified on igneum-seed-1 in /root/xbuild-test: igneumd --version, igneum-miner --help, and a 60-s private
network with real proof of work where the cross-compiled miner found 7 blocks that the cross-compiled node
accepted (0 rejected). /opt/igneum/v4/bin untouched.
BIN_SOURCE=mac: provision.sh skips the builder VM and takes build/bin from the cross-compile; stage-v4.sh
cross-compiles, uploads to /root/v4/out and installs exactly as a VM build would.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
igneum-seed-1 (Hetzner cx23, fsn1, 188.245.5.161:26611): built on the VM in 1,530 s, synced to the live devnet
(12,204 blocks, same sink as the live node) through a non-mining relay igneumd on the Mac (the live node's addPeer
RPC is refused in safe mode); the live node and the Windows PC learned the seed's address by peer exchange and dialled
it. seeds.txt written. Hetzner prices corrected to USD (pricing API currency) in the plans, READMEs and scripts;
current-generation types per location (cx23 EU, cpx22 sin, cpx21 US) in the cloud-devnet config.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
infra/cloud-devnet: hcloud (doctl variant) create, builder-VM provision from a git-archive source tarball,
systemd units for igneumd --devnet-suffix with a sparse --addpeer mesh and a CPU trickle miner per node,
stdlib wRPC client, experiments (latency, partition, hop, collect, observer hookup), README with the command
sequence and the Hetzner API prices of 3 Oct 2026.
infra/gpu-bench: RunPod image recipes (CUDA 12.8, ROCm), bundle, run.sh (vectors gate, 10-min raw, sweep,
inline shortcut ratio, nvcc/NVRTC/OpenCL recompile timings, results row, intake upload), bench-log template.
infra/seed-nodes: create-seed (persistent IPv4, firewall), provision on the VM, health check, addPeer from the
Mac over grpcurl, seeds.txt; igneum-seed-1 created at 188.245.5.161 (Hetzner cx23, fsn1).
docs/plans/cloud-devnet.md and docs/plans/seed-nodes.md.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>