Skip to content

Install secretd

Install the v1.27.2 MAINNET deb on Ubuntu 22.04 or 24.04. Do not start the unit yet.

Updated from v1.27.2 notes, View as Markdown

Finish SGX prerequisites first. Use Ubuntu 22.04 or 24.04, x86_64.

Download Secret3dev/SecretNetwork tag v1.27.2.

Install the deb

. /etc/os-release
case "$VERSION_ID" in
  22.04|24.04) ;;
  *) echo "Ubuntu 22.04 or 24.04"; exit 1 ;;
esac
uname -m   # x86_64

deb="secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-${VERSION_ID}.deb"
curl -fL -o "/tmp/$deb" \
  "https://github.com/Secret3dev/SecretNetwork/releases/download/v1.27.2/$deb"
case "$VERSION_ID" in
  22.04) echo "ffcca0fe04422228ae92b0bb216808a0eafa1030a7073d1bf1ca347a0781fcbb  /tmp/$deb" ;;
  24.04) echo "f90e7104d6308d491c9cfdb691672302b17b3364c3b355962479adc46da3d903  /tmp/$deb" ;;
esac | sha256sum -c -
sudo dpkg -i "/tmp/$deb"
test "$(secretd version | head -1)" = 1.27.2
systemctl cat secret-node

Confirm User= is the account that will own ~/.secretd. sudo dpkg -i from user ubuntu writes User=ubuntu and WorkingDirectory=/home/ubuntu. A root shell with empty SUDO_USER writes User=root and /root. Do not install from a root shell.

secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-22.04.deb

SHA-256 ffcca0fe04422228ae92b0bb216808a0eafa1030a7073d1bf1ca347a0781fcbb

secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-24.04.deb

SHA-256 f90e7104d6308d491c9cfdb691672302b17b3364c3b355962479adc46da3d903

Do not install a TRINITY deb on secret-4. Those packages are the testnet build.

Files the deb installs

  • /usr/local/bin/secretd
  • /usr/local/bin/secretcli
  • /usr/lib/libgo_cosmwasm.so
  • /usr/lib/librandom_api.so
  • /usr/lib/librust_cosmwasm_enclave.signed.so

The 22.04 package is secretnetwork 1.27.2 amd64 and depends only on libsnappy1v5. dpkg does not ship config.toml, app.toml, or check-hw.

The signed enclave .so in the two mainnet debs is the same file (sha256 bf11471011a5ec3cdc3f33ae9aea66e8c0638227a8cf3ee9af9a306c2a039316). secretd, secretcli, and libgo_cosmwasm.so differ between the debs. Mainnet measurement: f0d59dd2561b1c86de88ef27b8b9146bcc2c1b02875ba3c48db48a32bb20d90b.

Use Ubuntu 22.04 or 24.04 only. The filenames are amd64 and goleveldb only.

Unit the package writes

postinst writes this unit, then runs daemon-reload. It also creates /opt/secret/.sgx_secrets, /opt/secret/.secretd/.node, and ~$SUDO_USER/.sgx_secrets, changes owner of /opt/secret to SUDO_USER, and runs chmod -R 777 /opt/secret. /opt/secret/.sgx_secrets holds data.sealed, data-<mrenclave>.bin, and the quote.

[Unit]
Description=Secret node service
After=network.target

[Service]
Type=simple
Environment=SCRT_ENCLAVE_DIR=/usr/lib
WorkingDirectory=/home/<sudo-user>
ExecStart=/usr/local/bin/secretd start
User=<sudo-user>
Restart=on-failure
StartLimitInterval=0
RestartSec=3
LimitNOFILE=65535
LimitMEMLOCK=209715200

[Install]
WantedBy=multi-user.target

LimitMEMLOCK=209715200 is a 200 MiB memlock cap, not the RAM size. ExecStart does not pass --home. The process uses that user’s ~/.secretd. The unit does not set SCRT_SGX_STORAGE, so enclave files go to /opt/secret/.sgx_secrets. /opt/secret/.secretd/.node stays unused unless you later add --home /opt/secret/.secretd. postrm stops and disables secret-node, deletes the unit, and reloads systemd.

After each dpkg -i, set /opt/secret and /opt/secret/.sgx_secrets owned by the unit user and not world-writable:

unit="$(systemctl show -p User --value secret-node)"
sudo chown -R "$unit:$unit" /opt/secret /opt/secret/.sgx_secrets
sudo find /opt/secret /opt/secret/.sgx_secrets -type d -exec chmod 750 {} \;
sudo find /opt/secret /opt/secret/.sgx_secrets -type f -exec chmod 600 {} \;

The next package install opens them again until postinst is changed.

On a fresh machine, keep the unit dpkg wrote. If you already customized the unit, copy it aside first and follow Upgrade a seeded node. Next, create the node home.

↑
Navigation

Type to search…

↑↓ navigate↵ selectEsc close