Skip to content

Register the node

Produce a DCAP quote and sign tx register auth.

Updated from v1.27.2 notes, View as Markdown

Use this on a new machine, or after you reset the enclave. If the node already has a seed, follow Upgrade a seeded node and do not register again.

Finish SGX prerequisites. Use secretd 1.27.2. ~/.secretd/config/priv_validator_key.json must already exist, from secretd init on this home or copied from the machine you are replacing. Stop the old process before you copy that key. Put an account key in the file keyring. That key pays the fee. It is not the consensus key.

init-enclave writes a DCAP quote. The report data is the registration public key plus the ed25519 public key of priv_validator_key.json, unless you pass --unbound-attestation. tx register auth submits attestation_combined.bin. On success, configure-secret writes ~/.secretd/.node/new_seed.json. Do not run secretd start until that file exists. Without it, start panics Initialize node seed failed.

Steps

secretd init-enclave

secretd tx register auth /opt/secret/.sgx_secrets/attestation_combined.bin \
  --from KEY --chain-id secret-4 \
  --node https://rpc.secret.mainnet.secret3.dev

# wait until that transaction is in a block

secretd query register secret-network-params \
  --node https://rpc.secret.mainnet.secret3.dev

NODE_ID=$(secretd dump /opt/secret/.sgx_secrets/pubkey.bin)
SEED=$(secretd query register seed "$NODE_ID" \
  --node https://rpc.secret.mainnet.secret3.dev | sed 's/^0x//')
secretd configure-secret node-master-key.txt "$SEED"

Run secret-network-params and configure-secret from the directory that contains node-master-key.txt. Start the unit only after new_seed.json exists:

test -s ~/.secretd/.node/new_seed.json
sudo systemctl enable --now secret-node

If genesis.json is still the placeholder, configure the seed, then replace genesis on Create the node home before you enable the unit. restore.sh refuses to run without new_seed.json or seed.json. The usual order is seed first, then Sync.

Files and flags

Item Value
Secrets directory $SCRT_SGX_STORAGE, or /opt/secret/.sgx_secrets
Quote file attestation_combined.bin in that directory. EPID section length 0.
Registration public key pubkey.bin, 32 raw bytes. secretd dump prints 64 hex characters, no 0x.
Sealed registration key data.sealed
Id accepted by query register seed exactly 64 hex characters
Files secret-network-params writes node-master-key.txt and io-master-key.txt in the cwd, mode 0600, base64
Seed file $HOME/.secretd/.node/new_seed.json, mode 0600, version 2
Seed string hex, no 0x, length a multiple of 96
init-enclave flags --reset, --migration, --unbound-attestation

Create a custom SCRT_SGX_STORAGE directory before init-enclave. The command does not create a missing custom path. The unit sets SCRT_ENCLAVE_DIR for secret-node.

Confirm the transaction

On success the message event has signer, encrypted_seed (0x plus hex), and node_id (0x plus 64 hex). Tx response data is S: plus the ciphertext hex. Failure is Failed to authenticate node (codespace register, code 2). query register seed prints 0x plus hex and a newline. sed 's/^0x//' matches that. An unknown id returns Failed to query seed for …. secret-network-params prints a one-line JSON object and a literal /n. Success is the two files on disk. configure-secret exits 0 and prints the seed to stdout. Do not start on a seed query that ran before the register transaction was in a block.

Use RPC https://rpc.secret.mainnet.secret3.dev and chain-id secret-4. LCD https://lcd.secret.mainnet.secret3.dev serves GET /registration/v1beta1/tx-key, /registration-key, and /encrypted-seed/{pub_key}.

Reset and re-register

  • secretd reset-enclave deletes ~/.secretd/.node/new_seed.json and the secrets directory, then recreates the directory. Your account keys stay.
  • The blocks above the snapshot are still on disk. Do not restore this snapshot onto this enclave. Put those blocks back.
  • This is a new full node and those blocks are gone. Reset the enclave, register, configure-secret, then run restore.sh.
  • This consensus key is already a live validator. Do not register a second seed to get past the snapshot.
  • init-enclave --reset generates a new registration key and does not delete new_seed.json. The new pubkey.bin is a new node id. Fetch the seed for the new id after the new transaction commits.
  • If data.sealed already exists, init-enclave without --reset keeps it and only refreshes the quote.

Upgrade

If you are already on 1.27.2 and you have a seed, do not register. Follow Upgrade a seeded node. A quote from an older binary fails as MrEnclaveMismatch. Produce the quote with the 1.27.2 enclave. Mainnet measurement is f0d59dd2561b1c86de88ef27b8b9146bcc2c1b02875ba3c48db48a32bb20d90b.

Warnings

  • Do not pass --unbound-attestation if you may later use --replace-machine-id. An unbound quote omits the validator key and cannot prove ownership of the old machine id.
  • If the machine is not on the allowlist, registration is rejected. The CPU is deprecated. Running forbidden means the FMSPC is in the end-of-life set. Follow Allowlist and machine replacement.
  • configure-secret rejects a bad seed with invalid encrypted seed format (requires hex string of multiples of 96 bytes without 0x prefix). Strip the 0x prefix.
  • Keep /opt/secret/.sgx_secrets/ (data.sealed, attestation_combined.bin, pubkey.bin), ~/.secretd/.node/new_seed.json, config/node_key.json, config/genesis.json, and config/config.toml. If you delete the seed or the sealed key, register again.
  • init-enclave requires priv_validator_key.json on this home.

After the seed file exists, go to Sync.

↑
Navigation

Type to search…

↑↓ navigate↵ selectEsc close