Use this on a new machine, or after you reset the enclave. If the node already has a seed, follow Upgrade a seeded node and do not register again.
Finish SGX prerequisites. Use secretd 1.27.2. ~/.secretd/config/priv_validator_key.json must already exist, from secretd init on this home or copied from the machine you are replacing. Stop the old process before you copy that key. Put an account key in the file keyring. That key pays the fee. It is not the consensus key.
init-enclave writes a DCAP quote. The report data is the registration public key plus the ed25519 public key of priv_validator_key.json, unless you pass --unbound-attestation. tx register auth submits attestation_combined.bin. On success, configure-secret writes ~/.secretd/.node/new_seed.json. Do not run secretd start until that file exists. Without it, start panics Initialize node seed failed.
Steps
secretd init-enclave
secretd tx register auth /opt/secret/.sgx_secrets/attestation_combined.bin \
--from KEY --chain-id secret-4 \
--node https://rpc.secret.mainnet.secret3.dev
# wait until that transaction is in a block
secretd query register secret-network-params \
--node https://rpc.secret.mainnet.secret3.dev
NODE_ID=$(secretd dump /opt/secret/.sgx_secrets/pubkey.bin)
SEED=$(secretd query register seed "$NODE_ID" \
--node https://rpc.secret.mainnet.secret3.dev | sed 's/^0x//')
secretd configure-secret node-master-key.txt "$SEED"Run secret-network-params and configure-secret from the directory that contains node-master-key.txt. Start the unit only after new_seed.json exists:
test -s ~/.secretd/.node/new_seed.json
sudo systemctl enable --now secret-nodeIf genesis.json is still the placeholder, configure the seed, then replace genesis on Create the node home before you enable the unit. restore.sh refuses to run without new_seed.json or seed.json. The usual order is seed first, then Sync.
Files and flags
| Item | Value |
|---|---|
| Secrets directory | $SCRT_SGX_STORAGE, or /opt/secret/.sgx_secrets |
| Quote file | attestation_combined.bin in that directory. EPID section length 0. |
| Registration public key | pubkey.bin, 32 raw bytes. secretd dump prints 64 hex characters, no 0x. |
| Sealed registration key | data.sealed |
Id accepted by query register seed |
exactly 64 hex characters |
Files secret-network-params writes |
node-master-key.txt and io-master-key.txt in the cwd, mode 0600, base64 |
| Seed file | $HOME/.secretd/.node/new_seed.json, mode 0600, version 2 |
| Seed string | hex, no 0x, length a multiple of 96 |
init-enclave flags |
--reset, --migration, --unbound-attestation |
Create a custom SCRT_SGX_STORAGE directory before init-enclave. The command does not create a missing custom path. The unit sets SCRT_ENCLAVE_DIR for secret-node.
Confirm the transaction
On success the message event has signer, encrypted_seed (0x plus hex), and node_id (0x plus 64 hex). Tx response data is S: plus the ciphertext hex. Failure is Failed to authenticate node (codespace register, code 2). query register seed prints 0x plus hex and a newline. sed 's/^0x//' matches that. An unknown id returns Failed to query seed for …. secret-network-params prints a one-line JSON object and a literal /n. Success is the two files on disk. configure-secret exits 0 and prints the seed to stdout. Do not start on a seed query that ran before the register transaction was in a block.
Use RPC https://rpc.secret.mainnet.secret3.dev and chain-id secret-4. LCD https://lcd.secret.mainnet.secret3.dev serves GET /registration/v1beta1/tx-key, /registration-key, and /encrypted-seed/{pub_key}.
Reset and re-register
secretd reset-enclavedeletes~/.secretd/.node/new_seed.jsonand the secrets directory, then recreates the directory. Your account keys stay.- The blocks above the snapshot are still on disk. Do not restore this snapshot onto this enclave. Put those blocks back.
- This is a new full node and those blocks are gone. Reset the enclave, register,
configure-secret, then runrestore.sh. - This consensus key is already a live validator. Do not register a second seed to get past the snapshot.
init-enclave --resetgenerates a new registration key and does not deletenew_seed.json. The newpubkey.binis a new node id. Fetch the seed for the new id after the new transaction commits.- If
data.sealedalready exists,init-enclavewithout--resetkeeps it and only refreshes the quote.
Upgrade
If you are already on 1.27.2 and you have a seed, do not register. Follow Upgrade a seeded node. A quote from an older binary fails as MrEnclaveMismatch. Produce the quote with the 1.27.2 enclave. Mainnet measurement is f0d59dd2561b1c86de88ef27b8b9146bcc2c1b02875ba3c48db48a32bb20d90b.
Warnings
- Do not pass
--unbound-attestationif you may later use--replace-machine-id. An unbound quote omits the validator key and cannot prove ownership of the old machine id. - If the machine is not on the allowlist, registration is rejected.
The CPU is deprecated. Running forbiddenmeans the FMSPC is in the end-of-life set. Follow Allowlist and machine replacement. configure-secretrejects a bad seed withinvalid encrypted seed format (requires hex string of multiples of 96 bytes without 0x prefix). Strip the0xprefix.- Keep
/opt/secret/.sgx_secrets/(data.sealed,attestation_combined.bin,pubkey.bin),~/.secretd/.node/new_seed.json,config/node_key.json,config/genesis.json, andconfig/config.toml. If you delete the seed or the sealed key, register again. init-enclaverequirespriv_validator_key.jsonon this home.
After the seed file exists, go to Sync.