Operators and roles
The roles an operator can run on Tenzro Network 1, from a home GPU to a data centre, and how one stake covers all of them.
Anyone can run hardware on Tenzro Network 1 and earn TNZO for it. A home PC with a GPU, a homelab, an independent data centre, a neo-cloud or an existing data-centre operator distributing its compute or models: each joins the same way, with the same binary, and picks the roles that fit its hardware.
A node is one identity. Its keys are rooted in the machine's TPM 2.0 or Secure Enclave, or in the operator's passkey. It can take on any set of roles, and one stake covers every role it runs.
The roles
| Role | What you provide | Node role (--roles) | Bond type (--provider-type) |
|---|---|---|---|
| Validator | Orders and finalises blocks in Tenzro DAG Consensus | validator | validator |
| RPC provider | Public JSON-RPC and API access; issues tenant API keys | any serving node | rpc |
| AI (model) provider | Serves inference for open models | ai | model |
| Compute provider | Rents GPU and CPU capacity by the epoch | compute | compute |
| Data and storage provider | Content-addressed storage, databases, hosted functions | storage, database, cloud | storage, cloud |
| Security (TEE) provider | Confidential compute with verified attestation | tee | tee |
| Training provider | Runs training rounds and synchronises them | ai with training enabled | trainer, syncer |
A node that bonds nothing can still sync and relay, and a light node can verify finality certificates without storing the full chain, but neither carries weight in consensus or earns for serving.
One stake, every role
A node stakes once. Each role it takes on registers its obligations against that single stake, and --provider-type tells the network which role a deposit backs:
# Back a validator and a model provider from the same account
tenzro stake deposit <amount> --provider-type validator
tenzro stake deposit <amount> --provider-type model
# Pledge capacity for compute and storage roles
tenzro stake deposit <amount> --provider-type compute --accelerator consumer
tenzro stake deposit <amount> --provider-type storage --terabytes 4
tenzro stake infoIf the stake can no longer cover everything the node has promised, after a withdrawal or a slash, the node sheds obligations until the rest fits. Bond requirements for each role are set by governance. Withdrawals go through a 7-day unbonding period, and slashing burns the offender's bond. See Slashing.
Install and join
Install the CLI with Homebrew, or build tenzro-node and tenzro from source:
brew tap tenzro/tap
brew install tenzro
# or from source
cargo build --release -p tenzro-node -p tenzro-cliNodes run on Linux and macOS. Pick the accelerator backend that matches your machine when you build (cuda, rocm, metal, vulkan and others; no feature means CPU). Check what the machine offers:
tenzro hardwareThe guided setup asks what you want to do and writes the node configuration:
tenzro setup --path network --roles validator,ai,storage--operator self means a human holds the passkey that controls the node. --operator autonomous means the machine answers for itself through its TPM 2.0 or Secure Enclave. --access sets how you sell capacity: on-demand, subscription or rental.
Per role
Validator
Any TPM 2.0 machine can run a validator. Signing keys are derived from the TPM on demand, used in memory and wiped; votes are signed with a session key the hardware certifies once per epoch.
tenzro-node --roles validator --data-dir ./data --genesis genesis.tomlThe node joins as a non-voting peer, registers as a candidate and becomes active at the next epoch boundary. See Validator lifecycle.
RPC provider
Any serving node can offer public RPC. Bond with --provider-type rpc, then issue scoped API keys to your tenants; they send them in the X-Tenzro-Api-Key header. See Run an RPC provider and API keys.
AI (model) provider
tenzro-node --roles ai
tenzro join --providertenzro join --provider detects your hardware, posts the bond, registers you, sets default pricing and serves the largest catalogue model that fits. To choose yourself, use tenzro model download <id>, tenzro model serve <id> and tenzro provider pricing set. Weights are fetched from several origins and verified by hash. Models too large for one machine can be served across a LAN cluster or as distributed experts. See Model serving.
Compute provider
Take the compute role and pledge accelerator classes (integrated, consumer, workstation, datacentre). Rentals are booked per epoch and billed on the chain's verdict from SLA attestation; your prices are published into the compute price index. See Compute rental and Compute claims and price index.
Data and storage provider
Offer free disk as content-addressed storage with the storage role, and databases or hosted functions with database and cloud. Storage is billed per byte and epoch against a passing proof of retrievability, under a bonded SLA. See Decentralized storage and Databases.
Security (TEE) provider
tenzro tee detect
tenzro tee attest --provider autoSupported platforms are Intel TDX, AMD SEV-SNP, AWS Nitro and NVIDIA confidential GPUs. Attestation is verified per vendor and is evidence that a workload ran confidentially; it does not hold keys. See TEE.
Training provider
Install the trainer, enable training in the node configuration and enrol:
[training]
enabled = truetenzro train list-runs
tenzro train enroll-trainer --task-id <task> --trainer-did <your machine DID>Trainers bond as trainer; nodes that synchronise rounds bond as syncer. See Tenzro Train.
Policies and trust
Every operator publishes a signed policy describing what it offers and how. You are slashed only for a provable breach of your own policy. Buyers pick operators using certification and ratings from issuers they trust. See Operator policies.
Help onboarding
The Tenzro Foundation publishes the software and documentation. Partners, including Tenzro Labs, help operators of any background onboard, from a single GPU to a full data centre. See Partners and Operators.