GOpenCNR network participation agreement
What you promise the other members for every router you connect to GOpenCNR, from running only the generated configuration and a current agent to keeping closed prefixes closed and helping when something leaks.
This agreement
This agreement is between Gelhaus Solutions, as Tier 0 of GOpenCNR, and you as a member, for each router you connect. Every router on GOpenCNR carries the other members' trust: what it announces, forwards and keeps secret decides what they can rely on. This agreement is what you promise them, through us.
It applies to every router you enrol: a router running the GOpenCNR agent, in managed or include mode, and a router running a configuration GOpenCNR generates for it. It applies to your hosted router as the section on hosted routers says. You accept it when you enrol a router, for that router, and when your hosted router is created. GOpenCSR records the version you accepted, by its identifier in the document archive. It applies in addition to the GOpenCNR terms and the acceptable use policy.
How each kind of router is protected
- A router running the agent (Debian and Ubuntu, Alpine, a container, OpenWrt, OPNsense or pfSense): end to end. Traffic to another agent travels inside an inner WireGuard layer that only the two ends can read.
- Your hosted router, on Tier 0's hub or a certified hub: encrypted to the hub operator, end to end from there.
- A device on a router running the agent or on a hosted router: end to end from that router.
- A router with a generated configuration (MikroTik RouterOS, VyOS, FRR, or plain WireGuard and BIRD), and a machine without BGP: hop by hop, and marked so. It never receives closed routes or inner keys.
Every router and every device shows its protection as it is.
The nine rules
1. Run the generated configuration, and nothing that contradicts it
Everything GOpenCNR needs on your router (tunnels, BGP sessions, filters, and the firewall rules for GOpenCNR traffic) is generated from the registry and delivered as a signed bundle. In managed mode the agent applies it. In include mode the agent writes WireGuard, BGP and firewall snippets, and you include them complete and unchanged. A generated configuration is used as generated.
Configure nothing by hand that contradicts the bundle: no announcements beyond it, no changed filters or sessions, no wider WireGuard AllowedIPs, and no firewall rule that lets GOpenCNR traffic reach an undeclared service. What you want changed, you change in the registry, signed, and the next bundle carries it, usually within about a minute.
2. Keep the agent current
The agent comes as signed releases, and it checks the signature of every update before installing it. Automatic updates are yours to switch on; they roll out in stages and roll back on failure.
- Install a release marked as a security release within 14 days of its publication.
- Otherwise, stay within the supported window: an agent keeps working for 12 months after a newer bundle schema ships, so update within that time.
- Run only signed releases, unmodified.
3. Keep the firewall default
Traffic from GOpenCNR is denied unless a service is declared. You open a service by declaring it in the registry, with its address, port and audience, and the declaration drives the firewall. In managed mode the agent installs the default deny; in include mode your rules must reference the agent's chain; on a router with a generated configuration you keep the same default yourself. Open GOpenCNR traffic in no other way.
4. Keep the MTU
The tunnels to the hubs run with an MTU of 1420, and the inner layer between agents with 1340. Raise neither, keep the MSS clamping the bundle sets, and let the agent probe the path MTU.
5. Announce only what you hold, as the registry says
- Announce only space allocated or delegated to you, and only prefixes that have a route object.
- Announce each prefix only from the origin ASN its route object names.
- Every route must be RPKI-valid and ASPA-valid. The agent keeps your ASPA provider list in step with the hubs you use.
- No default route, and nothing more specific than a route object: ROAs name exact prefixes, so a more-specific needs a route object of its own.
- At most 8 prefixes by default (max-prefix), raised on request.
- Only GOpenCNR's ranges and named interconnects.
The hubs filter straight from the registry and refuse everything else. Every refusal is reported to you with the rule and the fix, and a refusal is not a sanction. A session that flaps 6 times in 15 minutes is held down for 15 minutes, and you are told why. Each hub limits you to 100 Mbit/s sustained, with bursts capped at 200 Mbit/s, raised on request. Steer the hubs only with the published community scheme, and blackhole only your own prefixes.
6. Let risky changes confirm themselves
Every bundle is applied atomically, checked for health and rolled back if it fails. A change that can cut a router off, such as a change to the WAN, the VLANs, the firewall on the uplink or the firmware, applies commit-confirmed: it rolls back unless the router reports healthy within 5 minutes. Do not disable, shorten or work around the rollback.
7. Send only from your own space
Send traffic into GOpenCNR only from addresses inside your registered space. The hub accepts only such sources on your tunnel, and the inner layer checks them again; do not try to get past either.
8. Keep closed prefixes closed
- Only audience members hold each other's inner keys. Keep inner keys on the router that holds them. Do not copy, export or share them, or a configuration that carries them.
- Closed routes reach you only through Tier 0's hubs and certified hubs, never through community hubs, transit members or direct sessions. Pass on no closed route to anybody. The agent strips closed routes from direct sessions; do not stop it.
- To receive closed routes, run the agent or use your hosted router.
- Pass no traffic between a closed prefix and anybody outside its audience.
9. Help when something leaks
A hub that sees a closed route outside its audience drops the leaking member's closed routes and sessions at once, on its own, without anybody confirming it. A case opens, and the holder of the closed prefix is told.
If the leak came from your router, find and fix the cause, tell the case what happened and what you changed, and answer within the times of the acceptable use policy: a live leak counts as an active attack, so you have 12 hours. What follows is decided in the case.
What the agent does on your router
- Privileges. The agent runs with network capabilities, not as root, and does its privileged steps in a small separate helper.
- Your choice of mode. In include mode it writes only its WireGuard, BGP and firewall snippets and changes nothing else. In managed mode it manages WireGuard, BGP and GOpenCNR's firewall chain, and the managed networking areas you switch on: subnets, DHCP and router advertisements from your space; firewall zones; port forwards and NAT; routing and BGP, including your internal peers; your devices; and the whole router, meaning WAN and ISP settings, VLANs, Wi-Fi, local DNS and firmware. It changes nothing in an area you have not switched on.
- Address preference. On hosts it manages, it adds a rule so that GOpenCNR's IPv6 addresses win over IPv4 for GOpenCNR's ranges.
- LAN conflicts. At install and on every change it checks your local routes and interfaces against every GOpenCNR pool. On a collision it offers another pool, advice on renumbering, or a managed 1:1 NETMAP, and it applies a NETMAP only if you choose it.
- What it reports. Session state, latency to the hubs, the MTU it measured, drops by reason, its version, and every bundle it applies or rolls back. It sends no traffic contents and no flow records. Reports are kept for 12 months, as the privacy notice says.
Keys and enrolment
- Enrolment tokens work once and are valid for 24 hours. Keep a token secret until it is used.
- Keys are born on the host. The agent makes its Ed25519 identity key and the router's WireGuard keys on the router, seals them in its TPM where the router has one, and sends only the public halves to the registry. The private keys never leave the router; do not copy them anywhere else.
- Every request the agent makes is signed with its key. Each signature covers the request body and expires within 60 seconds. No bearer tokens are used.
- Every bundle is signed by GOpenCNR. The agent checks it against the key pinned in its release and refuses a bundle with a lower serial than the one it runs.
- Generated configurations and devices. The private key is made on the machine itself, or in your browser for a configuration that is shown once, for 15 minutes, and never stored. Revoke a lost device, and rotate a key you doubt, in the portal.
- If a key may be exposed, revoke it at once in the portal and tell us at contact@gplatform.org.
The agent licence
We grant you a free, non-exclusive, non-transferable licence to install and run the GOpenCNR agent, and the configuration it renders, on systems you control, for as long as a router you enrolled runs it, and only to connect to GOpenCNR. The agent is proprietary. Do not modify it, redistribute it or reverse engineer it beyond what Sections 69d and 69e of the German Copyright Act allow. The licence for a router ends when the router is unenrolled.
Hosted routers
Your hosted router is a virtual router GOpenCNR runs for you on Tier 0's hub or on a certified hub. You pick the hub, and the nearest is the default. Phones, laptops and servers that cannot run the agent connect to it with plain WireGuard. It gives them addresses from a subnet of your space, which the hub announces for you, names under your gnet name, and a firewall that denies traffic from GOpenCNR unless you declare a service. It counts as a router running the agent, so you may use closed prefixes through it.
It is encrypted to the hub operator, and end to end from there. The hub operator terminates your devices' tunnels and holds the hosted router's inner keys. The hub operator agreement makes a certified operator our processor for what it does with your data, binds it to inspect nothing and to keep only counters, and, for an operator outside the EU or EEA and outside a country with an adequacy decision, includes the EU standard contractual clauses. The network map shows each hub's country. On Tier 0's hub, the hosted router's keys are kept in Tier 0's key store, so a rebuild or a move of the hub keeps your device configurations valid. On a certified hub they are born on that hub, and your device configurations are issued again when the hosted router is rebuilt or moved.
On your hosted router, the hub operator runs the software, applies the bundles and keeps the router current; the rules about the router itself are its business. Yours are these: keep your devices' configurations secret, revoke a device you lose, declare only the services you mean to open, and keep closed prefixes closed. You may move the hosted router to another hub or switch it off at any time, and your space stays yours.
Direct peering
Two members who accept each other get a direct session, which their agents set up through the registry with a generated configuration like any other. Your endpoint goes only to the peers you accept, and theirs only to you. Use a peer's endpoint only for the session, and never publish it or pass it on. Closed routes never cross a direct session.
Your router is yours
You own and run your router, and you answer for it: for its security, for the network behind it and for what it sends into GOpenCNR. The agent and the bundles act on your router only as this agreement describes. Keep your own copy of your router's configuration before you hand any of it to managed mode, as the general terms require for all data. If your router records anything about the people who use your network, you are the controller for it.
Ending
You may unenrol a router at any time in the portal. When a router is unenrolled, or your membership ends, its agent identity and its WireGuard keys are revoked, its sessions end, the next bundles leave it out, and the licence for it ends; uninstall the agent then. A router can also lose its sessions through the steps of the sanctions ladder or an emergency suspension, as the GOpenCNR terms describe.
Everything else
Connecting a router is free of charge. No warranty and no service level apply, and liability is as the general terms of service set it out: for what is given away, it is limited to intent and gross negligence (Section 521 BGB). This agreement changes only as the general terms set out under "New versions of these terms": a material change is emailed to your address at least six weeks before it takes effect, and at your next sign-in you are asked to accept the new version, which is shown to you in full and linked in the document archive, without a list of what changed. A new version applies to you only once you accept it. What applies if you have not accepted it when the six weeks are over is set out in the GOpenCNR terms, under "Your content, your account and these clauses"; the restriction does not itself stop your routers. Every version stays in the document archive.