ArcNet
ArcNet is the encrypted tunnel layer of the EmberNet fabric: the point-to-point IP tunnels between the central platform and every remote site, giving nodes plain Layer 3 reachability to each other for agent check-ins and storage replication.
Where Flux is an identity-based application overlay, ArcNet is a straightforward encrypted IP tunnel.
Flux is the primary path, and ArcNet is the one that needs the network's permission. ArcNet is UDP and wants a reachable port, which is the first thing an industrial network filters; Flux rides outbound TCP/443, which is the egress those sites allow. An endpoint that reports ArcNet as its active path has lost Flux and is degraded, not optimized.
At sites where Flux is the only thing that gets out, ArcNet does not stop working. It is carried over Flux, so the site still gets its Layer 3 tunnel without needing UDP to traverse the plant firewall. That is the normal configuration, not a fallback.
Where it sits
The fabric uses different layers for different jobs:
| Layer | Carried by | What rides on it |
|---|---|---|
| Layer 3 (IP routing) | ArcNet | Node-to-node IP reachability and storage replication between nodes |
| Layer 4+ (application overlay) | Flux | The cluster API, cross-site app interfaces, device proxying, remote access |
| Layer 2 (Ethernet bridging) | Weld | Legacy protocols that need a broadcast domain, such as EtherNet/IP and PROFINET discovery |
Most deployments only use the first two. Weld is operator-toggled and exists for equipment that cannot work any other way.
The cluster API is on Flux, not ArcNet. Nodes reach their own cluster API through a Flux service address rather than a node IP, which is what lets a site keep a working control plane when its ArcNet tunnel is down or was never permitted. Do not design around the assumption that losing ArcNet costs you the control plane; it does not.
Addressing
ArcNet is a hub-and-spoke topology built on RFC 6598 carrier-grade NAT space,
100.64.0.0/10, with the hub at 100.64.0.1. Each organization gets its own
/24 inside that block, and its peers are addressed from it.
| Property | Value |
|---|---|
| Transport | UDP |
| Address space | 100.64.0.0/10 (RFC 6598) |
| Topology | Hub-and-spoke |
| Per organization | One /24 |
| Available addresses | 4,194,304 |
RFC 6598 rather than RFC 1918 is a deliberate choice. Factory networks are full
of 10.x and 192.168.x addressing, and a management tunnel that collides with
plant addressing is a management tunnel you cannot use during an incident. The
100.64.0.0/10 block is non-routable on the public internet, distinct from
RFC 1918 space, and large enough that no deployment will exhaust it.
Tunnel status and peers
ArcNet is managed by Fireball platform staff from the ArcNet tab of the Flux Console in Global Command. From there they create, rename, enable, disable, and delete peers, assign each peer to an organization, and hand out its configuration or enrollment QR code.
A peer counts as connected when its last handshake completed within the last two minutes. A handshake older than that does not always mean the tunnel is broken. ArcNet is quiet when there is nothing to send, so a genuinely idle peer can drift out of connected and recover the moment traffic resumes.
Tenant users do not manage ArcNet peers. A peer is tied to an organization by the tag platform staff give it, so a peer with no tag belongs to no organization.
Relationship to the rest of the platform
- Flux is the primary path and carries application traffic and the cluster API; ArcNet gives nodes Layer 3 IP reachability to each other. They are complementary, not alternatives, and on most sites ArcNet is carried over Flux rather than running beside it.
- Network Devices reaches managed network equipment over ArcNet tunnels.
- Ops deploys to clusters that are reachable over ArcNet.
- Cinder replicates storage between nodes across it.
Next steps
- Zero-Trust Networking: the security model
- Connectivity: how sites and devices connect
- EmberNet Endpoint: the client that uses these transports