Publish a service
Publishing turns something already listening on 127.0.0.1 into a named
service on your private mesh. Nothing about the local process changes, and no
public port is opened — the service becomes reachable only to machines on your
network that hold a valid capability.
fabric serve http://127.0.0.1:11434/v1 --name my-model --kind llmThat is the whole operation. The rest of this page is what the parts mean and what to do when the defaults do not fit.
Before you start
Section titled “Before you start”The machine has to be on the network already:
fabric statusIf it reports that this machine is not joined, run
sudo -E fabric up first — the tunnel needs
administrator rights.
Choose the kind
Section titled “Choose the kind”--kind tells the mesh what protocol lives behind the address, which is what
lets a caller resolve it correctly and what determines the default action a
capability grants.
| kind | for | default action |
|---|---|---|
llm | An OpenAI-compatible model server — Ollama, vLLM, llama.cpp, LM Studio | invoke |
mcp | An MCP tool server | read |
a2a | An agent-to-agent endpoint | delegate |
router | A gateway in front of several models | invoke |
endpoint | Any other HTTP API | invoke |
tcp | A raw TCP port — a database, an SSH host | connect |
If you are unsure, endpoint is the honest choice for an HTTP API and tcp for
anything that is not HTTP.
Name it for the caller
Section titled “Name it for the caller”The name is what teammates type, so name the capability rather than the host:
# reads well at the call sitefabric serve http://127.0.0.1:11434/v1 --name codegen-llm --kind llm
# does notfabric serve http://127.0.0.1:11434/v1 --name ollama-2 --kind llmNames are per-network. Publishing a second service with an existing name on the same network replaces the first.
Check it landed
Section titled “Check it landed”fabric service listfabric service inspect codegen-llmfabric service test performs a real request against the local address, which
distinguishes “published but the process is down” from “not published”:
fabric service test codegen-llmRestrict who can reach it
Section titled “Restrict who can reach it”By default any machine on the network can be granted access. --scope requires
a caller’s capability to carry a matching scope, which is how you keep a service
reachable by only part of the network:
fabric serve http://127.0.0.1:8080 --name payroll-api --kind endpoint --scope financeScopes are a filter on capabilities, not a replacement for them — a caller still needs a token. See Grant scoped access.
What the cloud learns
Section titled “What the cloud learns”The control plane records the service’s name, kind and the node it is on, so it can broker reachability and enforce capabilities. It does not receive the local address, and it never sees a request, a prompt or a response — those go machine to machine over the encrypted mesh.
Remove it
Section titled “Remove it”fabric service remove codegen-llmRemoval is immediate: existing capability tokens for the service stop resolving.
- Grant scoped access — hand someone a token for one action.
- Give a customer a demo — time-boxed access with a revoke.
fabric servereference — every flag.