Is it safe to rent out my DGX Spark?
Renting out a DGX Spark through GPUwerk Platform opens nothing on your network. The Spark dials out to GPUwerk through an encrypted WireGuard tunnel, drops connections from your local network, and sends renters' traffic out through GPUwerk's network instead of your IP address. What you hand over is control of the machine itself: it's wiped, you get no login, and GPUwerk administers it remotely while it's listed. This page describes what the installed software does, and where its limits are.
In short
- Open ports on your router
- None; the Spark connects out
- Your devices to the Spark
- Dropped by its firewall, IPv4 and IPv6
- Renters to your network
- Blocked, and tested during burn-in
- Renters' internet traffic
- Leaves from GPUwerk's address, not yours
- Your access to the Spark
- None while listed: no desktop, shell or account
- GPUwerk's access
- Remote administration as root, over the tunnel
- Renter identity and data
- Never shown to you
Your network
The Spark needs no public IP address and no port forwarding. Once installed, its firewall accepts only DHCP, IPv6 neighbour discovery and replies to its own connections on your network. Other devices on your network can't reach it, including SSH and the DGX dashboard that stock DGX OS opens; GPUwerk's tests cover this for IPv4 and IPv6.
Renters run in containers on a separate network inside the Spark. Their traffic goes through the tunnel and reaches the internet from GPUwerk's address, so anything a renter does online isn't traced to your IP. Their containers are refused private address ranges and the local network the Spark detects itself on. If the tunnel goes down, renters lose internet access rather than falling back to your line. One of the burn-in tests starts a container, tries to reach your router from it, and passes only if that fails and the container's public address differs from yours.
Some traffic does use your line directly: the tunnel itself, and the Spark's own housekeeping, such as software updates, downloading models and container images, DNS and time. Renter traffic travels over your line too, inside the tunnel, so it counts against your bandwidth.
Our suggestion: if your router can put the Spark on a guest network or its own VLAN, do it. The rules above keep renters off your network. GPUwerk has root on the Spark, and a separate network keeps the machine itself apart from your other devices, which doesn't depend on trusting us.
Your machine
The install erases the Spark's drive and writes a fresh DGX OS with GPUwerk's setup. No account is created for you. The setup locks every interactive account, turns off the local console logins and the desktop, and allows SSH only on the tunnel address, only for GPUwerk's operators, and only with short-lived certificates (30 minutes by default, an hour at most). The screen stays on and shows the status and "No local login; managed by GPUwerk."
The Spark's TPM proves its boot state to GPUwerk at registration and on every boot. The machine's secrets, such as its tunnel key, live on an encrypted volume that only opens after that check passes. If the boot measurements change, the Spark is suspended and GPUwerk investigates.
Pairing is tied to the machine in front of you. The six-letter code appears on the Spark's own screen, and the console shows the serial number and a TPM fingerprint to compare before you confirm. Ten wrong codes within an hour lock pairing for an hour.
The hardware stays yours, and so does the risk of damage or failure. To get it back for your own use, give 14 days' notice in the console; once no renter is on it, it's unlisted, and you restore the stock system with NVIDIA's recovery USB.
Renters and their data
One renter at a time gets the whole machine, and it's wiped between renters. You never learn who the renter is and can't see their workload or data; the console shows you only that the Spark is rented, since when, the hours and your earnings. Renters are told before they rent that a Partner Spark is an independent partner's machine at the partner's premises, without an SLA or uptime guarantee, and GPUwerk asks them to use only public or synthetic data on Partner capacity.
The lock against the owner has a limit, and we'd rather say it: whoever holds a machine controls its firmware and its install media. The TPM measurements cover the boot chain, not everything that runs afterwards. So the locked system deters casual access; it can't stop a determined owner. The partner agreement forbids tampering with the Spark or inspecting renter workloads, and a breach lets GPUwerk suspend the machine at once.
What GPUwerk can see
- Your application: legal name, address, VAT ID if any, identity documents for individuals, and the payout account.
- The machine: model, serial number, TPM fingerprint, the public address it connects from, its heartbeats, and the burn-in and network test results.
- Everything on the Spark itself, since GPUwerk administers it as root while it's listed. You have nothing of your own on it after the wipe.
GPUwerk installs nothing on your other devices. Beyond what any networked machine does, such as getting an address and usually DNS from your router, the Spark's software doesn't connect to them; the one deliberate exception is the burn-in check above, which makes sure a renter container can't reach your router. A machine with root access inside your network could technically reach the rest of it, which is the reason for the guest network suggestion.
What the programme pays and costs is on how to earn money with your DGX Spark; the hardware and network checklist is on requirements and setup.