Use this when check-hw succeeded and tx register auth failed the allowlist, or when you are moving a machine id that is already bound to your consensus key.
Take the machine id from check-hw (40 hex characters). To replace a machine, the old id must already be on the list and bound to the consensus key that the new quote will carry. Hardware is on SGX prerequisites.
Every platform, including Azure, needs the machine id on the enclave allowlist.
Add a new id
Do this before the first successful tx register auth. check-hw does not add the id. The enclave boots with a compiled-in allowlist. Governance can add ids after that.
Pass a proposal whose message is /secret.compute.v1beta1.MsgUpdateMachineWhitelistProposal, field machine_id, a comma-separated list of hex machine ids. Authority is the governance module account.
After status PROPOSAL_STATUS_PASSED, send a second transaction. Pass two arguments. machine_ids must equal the proposal string exactly.
secretd tx compute update-machine-whitelist <proposal-id> <machine_ids>The transaction fails if the proposal is not passed, does not contain exactly one message, or has the wrong type URL. On success the id is added.
Do not use --replace-machine-id for an id that has never been on the list.
Replace a listed machine
Stop the old process first. See Validator. Copy config/priv_validator_key.json from the old home to the new home before init-enclave, so the new quote’s owner field is that same key. Then run init-enclave, then:
secretd tx register auth /opt/secret/.sgx_secrets/attestation_combined.bin \
--replace-machine-id <40 hex chars of the old machine id> \
--from KEY --chain-id secret-4 \
--node https://rpc.secret.mainnet.secret3.devPass 40 hex characters. Anything else is treated as no replacement. The swap succeeds only when the old id is on the list, its stored owner equals this quote’s validator key, and the new id is not already present. Failures log Failed to replace MachineID - machine … not owned by validator key …, unknown machine, or machine … already exists, and the transaction is InvalidCert. The allowlist key is the quote’s PPID hash. --replace-machine-id is only the id you are removing. After a successful replace the old machine logs Self machine included: false.
Id already listed on this machine
Register with no --replace-machine-id to bind this machine to your validator key. An unknown machine fails with unknown machine. Produce the quote and seed on Register the node.
Upgrade
Replacing the deb on a machine that is already registered does not add or remove an id. A hardware change that changes the PPID does. Follow the replace steps above.