Skip to content
Tenzro
Documentation menu
Start here

Operators and roles

The roles an operator can run on Tenzro Network 1, from a home GPU to a data centre, and how one stake covers all of them.

Anyone can run hardware on Tenzro Network 1 and earn TNZO for it. A home PC with a GPU, a homelab, an independent data centre, a neo-cloud or an existing data-centre operator distributing its compute or models: each joins the same way, with the same binary, and picks the roles that fit its hardware.

A node is one identity. Its keys are rooted in the machine's TPM 2.0 or Secure Enclave, or in the operator's passkey. It can take on any set of roles, and one stake covers every role it runs.

The roles

RoleWhat you provideNode role (--roles)Bond type (--provider-type)
ValidatorOrders and finalises blocks in Tenzro DAG Consensusvalidatorvalidator
RPC providerPublic JSON-RPC and API access; issues tenant API keysany serving noderpc
AI (model) providerServes inference for open modelsaimodel
Compute providerRents GPU and CPU capacity by the epochcomputecompute
Data and storage providerContent-addressed storage, databases, hosted functionsstorage, database, cloudstorage, cloud
Security (TEE) providerConfidential compute with verified attestationteetee
Training providerRuns training rounds and synchronises themai with training enabledtrainer, syncer

A node that bonds nothing can still sync and relay, and a light node can verify finality certificates without storing the full chain, but neither carries weight in consensus or earns for serving.

One stake, every role

A node stakes once. Each role it takes on registers its obligations against that single stake, and --provider-type tells the network which role a deposit backs:

bash
# Back a validator and a model provider from the same account
tenzro stake deposit <amount> --provider-type validator
tenzro stake deposit <amount> --provider-type model

# Pledge capacity for compute and storage roles
tenzro stake deposit <amount> --provider-type compute --accelerator consumer
tenzro stake deposit <amount> --provider-type storage --terabytes 4

tenzro stake info

If the stake can no longer cover everything the node has promised, after a withdrawal or a slash, the node sheds obligations until the rest fits. Bond requirements for each role are set by governance. Withdrawals go through a 7-day unbonding period, and slashing burns the offender's bond. See Slashing.

Install and join

Install the CLI with Homebrew, or build tenzro-node and tenzro from source:

bash
brew tap tenzro/tap
brew install tenzro

# or from source
cargo build --release -p tenzro-node -p tenzro-cli

Nodes run on Linux and macOS. Pick the accelerator backend that matches your machine when you build (cuda, rocm, metal, vulkan and others; no feature means CPU). Check what the machine offers:

bash
tenzro hardware

The guided setup asks what you want to do and writes the node configuration:

bash
tenzro setup --path network --roles validator,ai,storage

--operator self means a human holds the passkey that controls the node. --operator autonomous means the machine answers for itself through its TPM 2.0 or Secure Enclave. --access sets how you sell capacity: on-demand, subscription or rental.

Per role

Validator

Any TPM 2.0 machine can run a validator. Signing keys are derived from the TPM on demand, used in memory and wiped; votes are signed with a session key the hardware certifies once per epoch.

bash
tenzro-node --roles validator --data-dir ./data --genesis genesis.toml

The node joins as a non-voting peer, registers as a candidate and becomes active at the next epoch boundary. See Validator lifecycle.

RPC provider

Any serving node can offer public RPC. Bond with --provider-type rpc, then issue scoped API keys to your tenants; they send them in the X-Tenzro-Api-Key header. See Run an RPC provider and API keys.

AI (model) provider

bash
tenzro-node --roles ai
tenzro join --provider

tenzro join --provider detects your hardware, posts the bond, registers you, sets default pricing and serves the largest catalogue model that fits. To choose yourself, use tenzro model download <id>, tenzro model serve <id> and tenzro provider pricing set. Weights are fetched from several origins and verified by hash. Models too large for one machine can be served across a LAN cluster or as distributed experts. See Model serving.

Compute provider

Take the compute role and pledge accelerator classes (integrated, consumer, workstation, datacentre). Rentals are booked per epoch and billed on the chain's verdict from SLA attestation; your prices are published into the compute price index. See Compute rental and Compute claims and price index.

Data and storage provider

Offer free disk as content-addressed storage with the storage role, and databases or hosted functions with database and cloud. Storage is billed per byte and epoch against a passing proof of retrievability, under a bonded SLA. See Decentralized storage and Databases.

Security (TEE) provider

bash
tenzro tee detect
tenzro tee attest --provider auto

Supported platforms are Intel TDX, AMD SEV-SNP, AWS Nitro and NVIDIA confidential GPUs. Attestation is verified per vendor and is evidence that a workload ran confidentially; it does not hold keys. See TEE.

Training provider

Install the trainer, enable training in the node configuration and enrol:

toml
[training]
enabled = true
bash
tenzro train list-runs
tenzro train enroll-trainer --task-id <task> --trainer-did <your machine DID>

Trainers bond as trainer; nodes that synchronise rounds bond as syncer. See Tenzro Train.

Policies and trust

Every operator publishes a signed policy describing what it offers and how. You are slashed only for a provable breach of your own policy. Buyers pick operators using certification and ratings from issuers they trust. See Operator policies.

Help onboarding

The Tenzro Foundation publishes the software and documentation. Partners, including Tenzro Labs, help operators of any background onboard, from a single GPU to a full data centre. See Partners and Operators.