Finish SGX prerequisites first. Use Ubuntu 22.04 or 24.04, x86_64.
Download Secret3dev/SecretNetwork tag v1.27.2.
Install the deb
. /etc/os-release
case "$VERSION_ID" in
22.04|24.04) ;;
*) echo "Ubuntu 22.04 or 24.04"; exit 1 ;;
esac
uname -m # x86_64
deb="secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-${VERSION_ID}.deb"
curl -fL -o "/tmp/$deb" \
"https://github.com/Secret3dev/SecretNetwork/releases/download/v1.27.2/$deb"
case "$VERSION_ID" in
22.04) echo "ffcca0fe04422228ae92b0bb216808a0eafa1030a7073d1bf1ca347a0781fcbb /tmp/$deb" ;;
24.04) echo "f90e7104d6308d491c9cfdb691672302b17b3364c3b355962479adc46da3d903 /tmp/$deb" ;;
esac | sha256sum -c -
sudo dpkg -i "/tmp/$deb"
test "$(secretd version | head -1)" = 1.27.2
systemctl cat secret-nodeConfirm User= is the account that will own ~/.secretd. sudo dpkg -i from user ubuntu writes User=ubuntu and WorkingDirectory=/home/ubuntu. A root shell with empty SUDO_USER writes User=root and /root. Do not install from a root shell.
secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-22.04.deb
SHA-256 ffcca0fe04422228ae92b0bb216808a0eafa1030a7073d1bf1ca347a0781fcbb
secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-24.04.deb
SHA-256 f90e7104d6308d491c9cfdb691672302b17b3364c3b355962479adc46da3d903
Do not install a TRINITY deb on secret-4. Those packages are the testnet build.
Files the deb installs
/usr/local/bin/secretd/usr/local/bin/secretcli/usr/lib/libgo_cosmwasm.so/usr/lib/librandom_api.so/usr/lib/librust_cosmwasm_enclave.signed.so
The 22.04 package is secretnetwork 1.27.2 amd64 and depends only on libsnappy1v5. dpkg does not ship config.toml, app.toml, or check-hw.
The signed enclave .so in the two mainnet debs is the same file (sha256 bf11471011a5ec3cdc3f33ae9aea66e8c0638227a8cf3ee9af9a306c2a039316). secretd, secretcli, and libgo_cosmwasm.so differ between the debs. Mainnet measurement: f0d59dd2561b1c86de88ef27b8b9146bcc2c1b02875ba3c48db48a32bb20d90b.
Use Ubuntu 22.04 or 24.04 only. The filenames are amd64 and goleveldb only.
Unit the package writes
postinst writes this unit, then runs daemon-reload. It also creates /opt/secret/.sgx_secrets, /opt/secret/.secretd/.node, and ~$SUDO_USER/.sgx_secrets, changes owner of /opt/secret to SUDO_USER, and runs chmod -R 777 /opt/secret. /opt/secret/.sgx_secrets holds data.sealed, data-<mrenclave>.bin, and the quote.
[Unit]
Description=Secret node service
After=network.target
[Service]
Type=simple
Environment=SCRT_ENCLAVE_DIR=/usr/lib
WorkingDirectory=/home/<sudo-user>
ExecStart=/usr/local/bin/secretd start
User=<sudo-user>
Restart=on-failure
StartLimitInterval=0
RestartSec=3
LimitNOFILE=65535
LimitMEMLOCK=209715200
[Install]
WantedBy=multi-user.targetLimitMEMLOCK=209715200 is a 200 MiB memlock cap, not the RAM size. ExecStart does not pass --home. The process uses that user’s ~/.secretd. The unit does not set SCRT_SGX_STORAGE, so enclave files go to /opt/secret/.sgx_secrets. /opt/secret/.secretd/.node stays unused unless you later add --home /opt/secret/.secretd. postrm stops and disables secret-node, deletes the unit, and reloads systemd.
After each dpkg -i, set /opt/secret and /opt/secret/.sgx_secrets owned by the unit user and not world-writable:
unit="$(systemctl show -p User --value secret-node)"
sudo chown -R "$unit:$unit" /opt/secret /opt/secret/.sgx_secrets
sudo find /opt/secret /opt/secret/.sgx_secrets -type d -exec chmod 750 {} \;
sudo find /opt/secret /opt/secret/.sgx_secrets -type f -exec chmod 600 {} \;The next package install opens them again until postinst is changed.
On a fresh machine, keep the unit dpkg wrote. If you already customized the unit, copy it aside first and follow Upgrade a seeded node. Next, create the node home.