Skip to content

Publish a service

Publishing turns something already listening on 127.0.0.1 into a named service on your private mesh. Nothing about the local process changes, and no public port is opened — the service becomes reachable only to machines on your network that hold a valid capability.

Terminal window
fabric serve http://127.0.0.1:11434/v1 --name my-model --kind llm

That is the whole operation. The rest of this page is what the parts mean and what to do when the defaults do not fit.

The machine has to be on the network already:

Terminal window
fabric status

If it reports that this machine is not joined, run sudo -E fabric up first — the tunnel needs administrator rights.

--kind tells the mesh what protocol lives behind the address, which is what lets a caller resolve it correctly and what determines the default action a capability grants.

kindfordefault action
llmAn OpenAI-compatible model server — Ollama, vLLM, llama.cpp, LM Studioinvoke
mcpAn MCP tool serverread
a2aAn agent-to-agent endpointdelegate
routerA gateway in front of several modelsinvoke
endpointAny other HTTP APIinvoke
tcpA raw TCP port — a database, an SSH hostconnect

If you are unsure, endpoint is the honest choice for an HTTP API and tcp for anything that is not HTTP.

The name is what teammates type, so name the capability rather than the host:

Terminal window
# reads well at the call site
fabric serve http://127.0.0.1:11434/v1 --name codegen-llm --kind llm
# does not
fabric serve http://127.0.0.1:11434/v1 --name ollama-2 --kind llm

Names are per-network. Publishing a second service with an existing name on the same network replaces the first.

Terminal window
fabric service list
fabric service inspect codegen-llm

fabric service test performs a real request against the local address, which distinguishes “published but the process is down” from “not published”:

Terminal window
fabric service test codegen-llm

By default any machine on the network can be granted access. --scope requires a caller’s capability to carry a matching scope, which is how you keep a service reachable by only part of the network:

Terminal window
fabric serve http://127.0.0.1:8080 --name payroll-api --kind endpoint --scope finance

Scopes are a filter on capabilities, not a replacement for them — a caller still needs a token. See Grant scoped access.

The control plane records the service’s name, kind and the node it is on, so it can broker reachability and enforce capabilities. It does not receive the local address, and it never sees a request, a prompt or a response — those go machine to machine over the encrypted mesh.

Terminal window
fabric service remove codegen-llm

Removal is immediate: existing capability tokens for the service stop resolving.