Read-only follower · production deliberately off
TSUNAGI forges blocks on the Preview testnet. On Cardano mainnet it runs something narrower and colder: a read-only follower — built from verbatim-ported Ouroboros consensus code — that follows and verifies the live chain through the operator's own relay. It produces nothing. That restraint is not a limitation of the code; it is the design.
The mainnet follower is the Haskell node's consensus client path — handshake, mux, ChainSync, BlockFetch — ported verbatim to Zig and hosted in the TSUNAGI Core executable. It negotiates node-to-node protocol v15, tracks the tip, decodes every block body, follows rollbacks, and reconverges through forks, peering via the operator's own relay. It holds no keys. Forge paths are dormant.
"Verbatim-ported" is a testable claim, not a slogan: a frozen build of the upstream reference (the oracle) runs the same code path, and every repair to the port is gated on byte-parity against it.
For 24 hours the TSUNAGI Core executable and a fresh build of the frozen upstream oracle followed the same live relay side by side — identical seeded cursors, isolated homes, forge off, no keys. Live network conditions included 36 fork events per side, all reconverged.
That soak was the closing exhibit of the R-series — a protocol investigation that found and repaired three real transport defects in the port (multi-message SDU handling in BlockFetch and ChainSync, and fragmented-SDU reassembly), each proven with a deterministic reproduction and re-verified against the oracle. 699/699 tests green. On mainnet itself, the operational battery included a 55,518-byte block reassembled from five SDUs and decoded byte-identical to the upstream reference.
A supervisor adopts the live follower and recycles it on a schedule. Clean shutdown, cursor recovery, and a 15-second resync are verified end-to-end, not assumed.
When the saved chain cursor points at an orphaned block, recovery rolls back to a known-good point automatically — a real incident, now fixture-tested.
The pipeline that publishes this site's numbers aborts rather than publish bad data. In its first audited window: 84 cron runs, 11 aborts — every one caused by upstream API flakiness, every one self-healed within 2 runs, zero regressions.
Every incident in the observation window to date attributed with evidence: tooling or upstream, except one bounded follower design limit — now auto-recovered and pinned by a test fixture.
The follower was deployed to mainnet on 2026-07-04 and completed its 7-day certification observation window on 2026-07-11 at 03:56 UTC. Final numbers, now permanent in the record: zero unplanned exits across 168 hours; five scheduled recycles, all verified clean — including one that landed on a live slot-battle orphan and auto-recovered via rolling points, and one that deployed a new parity-proven binary mid-window without a ripple; 30,745 journal events with every rollback reconverged; memory disciplined at 29–32 MB per process generation; and a truth pipeline that stayed fail-closed through sustained upstream API degradation with zero regressions. Classification: read-only mainnet operation, certified.
TSUNAGI does not produce blocks on mainnet. The producer code exists and forges daily on Preview, but on the mainnet follower the forge paths are dormant and no forging keys are present. The mainnet readiness certification says so explicitly: it certifies the read-only transport and client stack, and states in plain text that producing is not certified — out of scope, Preview-only, operator-gated.
Mainnet production sits behind a separate certification program (roadmap milestone M9): key-lifecycle rehearsal, block-construction byte-parity against a reference producer, shadow-producing with broadcast disabled, and a documented go/no-go gate — and even completing all of that enables nothing by itself. A wrong block on mainnet is real economic harm; the burden of proof is on the node, at every step. Saying this out loud is the same discipline that publishes the orphan ledger.
The v1.x roadmap orders the work in three waves, by value and risk — planning, not promises:
On Preview, TSUNAGI proves itself with canonical blocks. On mainnet, it proves itself with agreement — thousands of consecutive blocks where an independent implementation and the reference implementation cannot be told apart at the byte level. Production comes later, if the evidence earns it. The evidence so far is above.