OnionBalance v3 consists of a management node that holds the master descriptor key and multiple front nodes that serve actual client connections. The management node publishes a descriptor to the hidden service directory that references introduction points from all front nodes. Clients connect to any available introduction point, which routes them to the corresponding front node.
The management node does not handle any client traffic - it only manages descriptor publication. The front nodes run standard Tor hidden service configurations but publish their introduction points to the management node rather than directly to the directory. The management node aggregates these into a single combined descriptor published under the master onion address.
This architecture separates the key management function from the traffic handling function. If a front node is compromised, the attacker does not gain access to the master descriptor key. The management node can be more strictly firewalled than front nodes because it never handles client traffic directly.