---
title: "Install secretd"
description: "Install the v1.27.2 MAINNET deb on Ubuntu 22.04 or 24.04. Do not start the unit yet."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs-redux.pages.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Install secretd

Finish [SGX prerequisites](/operators/sgx) first. Use Ubuntu 22.04 or 24.04, `x86_64`.

:::caution
Do not start `secret-node` yet. `secretd start` panics without a seed file. Do not build the public git tag and run it as mainnet. Install the deb.
:::

Download [Secret3dev/SecretNetwork](https://github.com/Secret3dev/SecretNetwork/releases/tag/v1.27.2) tag `v1.27.2`.

## Install the deb

```bash
. /etc/os-release
case "$VERSION_ID" in
  22.04|24.04) ;;
  *) echo "Ubuntu 22.04 or 24.04"; exit 1 ;;
esac
uname -m   # x86_64

deb="secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-${VERSION_ID}.deb"
curl -fL -o "/tmp/$deb" \
  "https://github.com/Secret3dev/SecretNetwork/releases/download/v1.27.2/$deb"
case "$VERSION_ID" in
  22.04) echo "ffcca0fe04422228ae92b0bb216808a0eafa1030a7073d1bf1ca347a0781fcbb  /tmp/$deb" ;;
  24.04) echo "f90e7104d6308d491c9cfdb691672302b17b3364c3b355962479adc46da3d903  /tmp/$deb" ;;
esac | sha256sum -c -
sudo dpkg -i "/tmp/$deb"
test "$(secretd version | head -1)" = 1.27.2
systemctl cat secret-node
```

Confirm `User=` is the account that will own `~/.secretd`. `sudo dpkg -i` from user `ubuntu` writes `User=ubuntu` and `WorkingDirectory=/home/ubuntu`. A root shell with empty `SUDO_USER` writes `User=root` and `/root`. Do not install from a root shell.

### Ubuntu 22.04

`secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-22.04.deb`

SHA-256 `ffcca0fe04422228ae92b0bb216808a0eafa1030a7073d1bf1ca347a0781fcbb`
### Ubuntu 24.04

`secretnetwork_1.27.2_MAINNET_goleveldb_amd64_ubuntu-24.04.deb`

SHA-256 `f90e7104d6308d491c9cfdb691672302b17b3364c3b355962479adc46da3d903`

Do not install a `TRINITY` deb on `secret-4`. Those packages are the testnet build.

## Files the deb installs

- `/usr/local/bin/secretd`
- `/usr/local/bin/secretcli`
- `/usr/lib/libgo_cosmwasm.so`
- `/usr/lib/librandom_api.so`
- `/usr/lib/librust_cosmwasm_enclave.signed.so`

The 22.04 package is `secretnetwork` `1.27.2` `amd64` and depends only on `libsnappy1v5`. `dpkg` does not ship `config.toml`, `app.toml`, or `check-hw`.

The signed enclave `.so` in the two mainnet debs is the same file (sha256 `bf11471011a5ec3cdc3f33ae9aea66e8c0638227a8cf3ee9af9a306c2a039316`). `secretd`, `secretcli`, and `libgo_cosmwasm.so` differ between the debs. Mainnet measurement: `f0d59dd2561b1c86de88ef27b8b9146bcc2c1b02875ba3c48db48a32bb20d90b`.

Use Ubuntu 22.04 or 24.04 only. The filenames are `amd64` and `goleveldb` only.

## Unit the package writes

`postinst` writes this unit, then runs `daemon-reload`. It also creates `/opt/secret/.sgx_secrets`, `/opt/secret/.secretd/.node`, and `~$SUDO_USER/.sgx_secrets`, changes owner of `/opt/secret` to `SUDO_USER`, and runs `chmod -R 777 /opt/secret`. `/opt/secret/.sgx_secrets` holds `data.sealed`, `data-<mrenclave>.bin`, and the quote.

```ini
[Unit]
Description=Secret node service
After=network.target

[Service]
Type=simple
Environment=SCRT_ENCLAVE_DIR=/usr/lib
WorkingDirectory=/home/<sudo-user>
ExecStart=/usr/local/bin/secretd start
User=<sudo-user>
Restart=on-failure
StartLimitInterval=0
RestartSec=3
LimitNOFILE=65535
LimitMEMLOCK=209715200

[Install]
WantedBy=multi-user.target
```

`LimitMEMLOCK=209715200` is a 200 MiB memlock cap, not the RAM size. `ExecStart` does not pass `--home`. The process uses that user’s `~/.secretd`. The unit does not set `SCRT_SGX_STORAGE`, so enclave files go to `/opt/secret/.sgx_secrets`. `/opt/secret/.secretd/.node` stays unused unless you later add `--home /opt/secret/.secretd`. `postrm` stops and disables `secret-node`, deletes the unit, and reloads systemd.

After each `dpkg -i`, set `/opt/secret` and `/opt/secret/.sgx_secrets` owned by the unit user and not world-writable:

```bash
unit="$(systemctl show -p User --value secret-node)"
sudo chown -R "$unit:$unit" /opt/secret /opt/secret/.sgx_secrets
sudo find /opt/secret /opt/secret/.sgx_secrets -type d -exec chmod 750 {} \;
sudo find /opt/secret /opt/secret/.sgx_secrets -type f -exec chmod 600 {} \;
```

The next package install opens them again until `postinst` is changed.

On a fresh machine, keep the unit `dpkg` wrote. If you already customized the unit, copy it aside first and follow [Upgrade a seeded node](/operators/upgrade). Next, [create the node home](/operators/home).

Source: https://docs-redux.pages.dev/operators/install/index.mdx
