INSIDE KODACHI
Your ISO is the client layer. Behind it, Kodachi coordinates authentication, signed card assignment, DNS protection, protocol routing, worker fleets, external-provider configs, and on-device emergency defenses. Two racks power on below: the on-device rack you boot, and the kodachi.cloud master rack it talks to over a WAN uplink. Watch the flows move: auth handshakes travel up, signed cards ship down, traffic leaves through the exits.
Five steps from power-on to a guarded tunnel
Every booted Kodachi device walks the same path. The rack above is this flow, stacked.
Boot
The ISO comes up. integrity-check verifies the signed Rust components before anything else runs.
Authenticate
The client requests a 64-char challenge from the master node, solves it locally, returns the solution, gets a hardware-bound session token.
Card assigned
Master matches your tier to a fresh card from the matching pool. The card contains every protocol config you need.
Tunnel up
routing-switch brings the selected protocol online. dns-leak verifies the resolver is inside the tunnel.
Guarded
Heartbeat every 15 minutes, security score recomputed live, health-control watchdog ready to fire panic at any tier.
Protocol routing and DNS protection
Each card carries every daemon. The client drives which one goes live.
Tunnels
WireGuard tunnel client-a (Free) to its current NORMAL worker, kernel-level, mint-cyan.
V2Ray tunnel client-b (Premium) to its current low-density worker, VMess obfuscated.
Shadowsocks tunnel client-c (Custom) to its current isolated single-tenant worker, censorship-resistant.
Multi-Tor + HAProxy client-d (Free) to a Tor relay, 3-hop anonymous. Worker Tor SOCKS is VPN-only: it binds to the OpenVPN/WireGuard subnets, never a public IP, so the remote Tor route layers on an active VPN tunnel and is never an open proxy.
The full internal stack
Kodachi's own protocols, all 14 of them, ship inside every signed card. These are the internal counterpart to the 12 external providers below: nothing to paste, nothing to configure, routing-switch just brings the selected one up.
Obfuscated variants AmneziaWG and OpenVPN over Cloak are the same two native VPNs with their signatures removed. AmneziaWG keeps WireGuard's ChaCha20-Poly1305 crypto and UDP data path but sends junk packets ahead of the handshake and randomizes its header fields, so it comes up on awg0 rather than wg0 and needs the amneziawg kernel module. Cloak wraps OpenVPN in a TCP transport that presents as a browser HTTPS session to a real decoy site, with ck-client holding the outer connection while OpenVPN peers only to 127.0.0.1. Because ck-client owns no TUN device, anything that spots a tunnel by TUN ownership or by a wg or tun name prefix misses both, which is why the client uses shared interface-family helpers instead. Both cost throughput and are the wrong choice on any network that is not fingerprinting VPN traffic, and neither replaces Tor.
DNS layer
700+ resolvers across DNSCrypt, DoH/DoT, Pi-hole filtering, and DNS-over-Tor, all shipping in every card and driven on the client by dns-switch.
each card = { vps_info, services{ openvpn, wireguard, amneziawg, openvpn-cloak, shadowsocks, v2ray, xray, hysteria2, mita, dante, tor, dns } } · signed JSON
Master keeps three privilege tiers
Matched by tier on auth and replenished by scheduled, inventory-aware generation. Current inventory: -- signed JSON cards across the pools, loaded from the master API.
Shared, high-density VPS. Every protocol included. Cards regenerated on cron when the pool dips below the threshold. Personal-use tier, same OS and binaries as the paid plans. Current node assignments come from the master API.
Low-density shared VPS for consistent performance. Prioritized exits, lower contention, faster card rotation. Same protocol surface. Commercial usage rights included. Current node assignments come from the master API.
Fully isolated VPS per customer. Bespoke configs per holder. Dedicated worker mapping. Intended for organisations and serious operational use. Current allocation: -- dedicated seats across -- customers.
External providers and on-device defenses
The Kodachi fleet is the turnkey path, not the only path.
External VPN Providers
Separate from the 14 internal protocols above, which are Kodachi's own and are already inside every signed card, the same dashboard's External VPN Providers tab catalogs 12 third-party providers plus a custom pseudo-provider that auto-detects pasted .ovpn / WireGuard / Shadowsocks / V2Ray / Hysteria2 configs and vmess:// / vless:// / trojan:// / ss:// / hysteria2:// / tuic:// URI schemes plus Clash YAML / sing-box JSON subscriptions.
On-device defenses + AI
3-tier PANIC (Soft / Medium / Hard), Kill Switch, separately armed Destroy action, Threat Watchdog, Security Score, MAC randomize, RAM/Browser/Logs wipe, and -- workflow profiles. The Kodachi AI workspace adds 8 AI binaries and 9 named engine paths: TF-IDF, ONNX intent classifier, ONNX semantic, Mistral.rs, GenAI/Ollama, legacy local LLM, Claude Code CLI, Codex CLI, and OpenCode. Local engines run on-device; configured external providers can receive prompts and context.
The rack in numbers
Loading current rack totals from /apps/stats_api.php…