From f52ac758dd123f661d37aa399158d9498cb30633 Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Tue, 10 Jun 2025 16:56:14 +0530 Subject: [PATCH 01/14] Add initial TMKMS stack --- .../compose/docker-compose-tmkms.yml | 10 ++++ stack-orchestrator/config/tmkms/run.sh | 12 ++++ .../container-build/tmkms/Dockerfile | 56 +++++++++++++++++++ .../container-build/tmkms/build.sh | 9 +++ stack-orchestrator/stacks/tmkms/stack.yml | 9 +++ 5 files changed, 96 insertions(+) create mode 100644 stack-orchestrator/compose/docker-compose-tmkms.yml create mode 100755 stack-orchestrator/config/tmkms/run.sh create mode 100644 stack-orchestrator/container-build/tmkms/Dockerfile create mode 100755 stack-orchestrator/container-build/tmkms/build.sh create mode 100644 stack-orchestrator/stacks/tmkms/stack.yml diff --git a/stack-orchestrator/compose/docker-compose-tmkms.yml b/stack-orchestrator/compose/docker-compose-tmkms.yml new file mode 100644 index 0000000..ed15609 --- /dev/null +++ b/stack-orchestrator/compose/docker-compose-tmkms.yml @@ -0,0 +1,10 @@ +services: + tmkms: + restart: unless-stopped + image: cerc/tmkms:local + command: ["bash", "-c", "/opt/run.sh"] + volumes: + - ./tmkms:/root + - ../config/tmkms/run.sh:/opt/run.sh + ports: + - "26659" diff --git a/stack-orchestrator/config/tmkms/run.sh b/stack-orchestrator/config/tmkms/run.sh new file mode 100755 index 0000000..45a016a --- /dev/null +++ b/stack-orchestrator/config/tmkms/run.sh @@ -0,0 +1,12 @@ +#!/bin/bash + +if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then + set -x +fi + +set -e + +TMKMS_HOME=/root/.tmkms + +echo "Starting tmkms..." +tmkms start --config $TMKMS_HOME/tmkms.toml diff --git a/stack-orchestrator/container-build/tmkms/Dockerfile b/stack-orchestrator/container-build/tmkms/Dockerfile new file mode 100644 index 0000000..ccd1473 --- /dev/null +++ b/stack-orchestrator/container-build/tmkms/Dockerfile @@ -0,0 +1,56 @@ +# -------- Stage 1: Build -------- +FROM debian:bookworm-slim AS builder + +ARG BACKEND=softsign +ARG VERSION=main + +# Install build dependencies +RUN apt-get update && \ + DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ + build-essential \ + clang \ + curl \ + git \ + pkg-config \ + libsodium-dev \ + libssl-dev \ + ca-certificates && \ + apt-get clean && rm -rf /var/lib/apt/lists/* + +# Create non-root user +RUN useradd -m builder +USER builder +WORKDIR /home/builder + +ENV PATH="/home/builder/.cargo/bin:$PATH" + +# Install Rust +RUN curl https://sh.rustup.rs -sSf | sh -s -- -y && \ + rustup component add rustfmt clippy + +# Clone and build TMKMS +RUN git clone --depth 1 --branch ${VERSION} https://github.com/iqlusioninc/tmkms.git && \ + cd tmkms && \ + cargo build --release --features=${BACKEND} + +# -------- Stage 2: Runtime -------- +FROM debian:bookworm-slim + +# Install runtime dependencies only +RUN apt-get update && \ + DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ + libssl3 \ + libsodium23 \ + ca-certificates && \ + apt-get clean && rm -rf /var/lib/apt/lists/* + +# Copy compiled binary +COPY --from=builder /home/builder/tmkms/target/release/tmkms /usr/local/bin/tmkms + +# Create runtime user +RUN useradd -m tmkmsuser +USER tmkmsuser +WORKDIR /home/tmkmsuser + +# Default command, override with `docker run ... bash` etc. +CMD ["tmkms"] diff --git a/stack-orchestrator/container-build/tmkms/build.sh b/stack-orchestrator/container-build/tmkms/build.sh new file mode 100755 index 0000000..e929727 --- /dev/null +++ b/stack-orchestrator/container-build/tmkms/build.sh @@ -0,0 +1,9 @@ +#!/usr/bin/env bash + +# Build cerc/tmkms +source ${CERC_CONTAINER_BASE_DIR}/build-base.sh + +# See: https://stackoverflow.com/a/246128/1701505 +SCRIPT_DIR=$( cd -- "$( dirname -- "${BASH_SOURCE[0]}" )" &> /dev/null && pwd ) + +docker build -t cerc/tmkms:local ${build_command_args} -f ${SCRIPT_DIR}/Dockerfile ${CERC_REPO_BASE_DIR}/tmkms diff --git a/stack-orchestrator/stacks/tmkms/stack.yml b/stack-orchestrator/stacks/tmkms/stack.yml new file mode 100644 index 0000000..f254a19 --- /dev/null +++ b/stack-orchestrator/stacks/tmkms/stack.yml @@ -0,0 +1,9 @@ +version: "1.0" +name: tmkms +description: "TMKMS for signing consensus messages" +repos: + - https://github.com/iqlusioninc/tmkms.git@v0.14.0 +containers: + - cerc/tmkms +pods: + - tmkms -- 2.54.0 From b888d1934140aa252acedc17f0a13306ec949d0e Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Tue, 10 Jun 2025 18:20:20 +0530 Subject: [PATCH 02/14] Update run script and compose file to initialize tmkms --- .../compose/docker-compose-tmkms.yml | 9 ++++- stack-orchestrator/config/tmkms/run.sh | 35 +++++++++++++++++++ 2 files changed, 43 insertions(+), 1 deletion(-) diff --git a/stack-orchestrator/compose/docker-compose-tmkms.yml b/stack-orchestrator/compose/docker-compose-tmkms.yml index ed15609..de08d95 100644 --- a/stack-orchestrator/compose/docker-compose-tmkms.yml +++ b/stack-orchestrator/compose/docker-compose-tmkms.yml @@ -3,8 +3,15 @@ services: restart: unless-stopped image: cerc/tmkms:local command: ["bash", "-c", "/opt/run.sh"] + environment: + CERC_CHAIN_ID: ${CERC_CHAIN_ID:-laconic-mainnet} + NODE_IP: ${NODE_IP:-localhost} + CERC_KEY_PREFIX: ${CERC_KEY_PREFIX:-laconic} volumes: - - ./tmkms:/root + - tmkms-data:/root - ../config/tmkms/run.sh:/opt/run.sh ports: - "26659" + +volumes: + tmkms-data: diff --git a/stack-orchestrator/config/tmkms/run.sh b/stack-orchestrator/config/tmkms/run.sh index 45a016a..3eb4908 100755 --- a/stack-orchestrator/config/tmkms/run.sh +++ b/stack-orchestrator/config/tmkms/run.sh @@ -7,6 +7,41 @@ fi set -e TMKMS_HOME=/root/.tmkms +TMKMS_SECRETS_DIR=$TMKMS_HOME/secrets +TMKMS_STATE_DIR=$TMKMS_HOME/state + +echo "Initializing tmkms configuration..." + +# Initialize tmkms config +tmkms init config --home $TMKMS_HOME + +# Generate a new softsign key +echo "Generating new softsign key..." +tmkms softsign keygen $TMKMS_SECRETS_DIR/kms-identity.key --home $TMKMS_HOME + +# Update tmkms.toml +echo "Updating tmkms.toml with chain_id, node IP, and key prefixes..." + +# Add chain configuration +cat <> $TMKMS_HOME/tmkms.toml + +[[chain]] +id = "$CERC_CHAIN_ID" +key_format = { type = "cosmos-json", account_key_prefix = "${CERC_KEY_PREFIX}pub", consensus_key_prefix = "${CERC_KEY_PREFIX}valconspub" } +state_file = "$TMKMS_STATE_DIR/priv_validator_state.json" + +[[validator]] +chain_id = "$CERC_CHAIN_ID" +addr = "tcp://$NODE_IP:26659" +secret_key = "$TMKMS_SECRETS_DIR/kms-identity.key" +protocol_version = "v0.34" +reconnect = true + +[[providers.softsign]] +key_type = "consensus" +path = "$TMKMS_SECRETS_DIR/priv_validator_key" +chain_ids = ["$CERC_CHAIN_ID"] +EOF echo "Starting tmkms..." tmkms start --config $TMKMS_HOME/tmkms.toml -- 2.54.0 From d4745e0c275e5098a01328578d126894b8d10306 Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Tue, 10 Jun 2025 19:06:44 +0530 Subject: [PATCH 03/14] Update parent directory for initializing tmkms --- stack-orchestrator/compose/docker-compose-tmkms.yml | 2 +- stack-orchestrator/config/tmkms/run.sh | 6 +++--- .../container-build/{tmkms => cerc-tmkms}/Dockerfile | 0 .../container-build/{tmkms => cerc-tmkms}/build.sh | 0 stack-orchestrator/stacks/tmkms/stack.yml | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) rename stack-orchestrator/container-build/{tmkms => cerc-tmkms}/Dockerfile (100%) rename stack-orchestrator/container-build/{tmkms => cerc-tmkms}/build.sh (100%) diff --git a/stack-orchestrator/compose/docker-compose-tmkms.yml b/stack-orchestrator/compose/docker-compose-tmkms.yml index de08d95..1790eae 100644 --- a/stack-orchestrator/compose/docker-compose-tmkms.yml +++ b/stack-orchestrator/compose/docker-compose-tmkms.yml @@ -8,7 +8,7 @@ services: NODE_IP: ${NODE_IP:-localhost} CERC_KEY_PREFIX: ${CERC_KEY_PREFIX:-laconic} volumes: - - tmkms-data:/root + - tmkms-data:/home/tmkmsuser/tmkms - ../config/tmkms/run.sh:/opt/run.sh ports: - "26659" diff --git a/stack-orchestrator/config/tmkms/run.sh b/stack-orchestrator/config/tmkms/run.sh index 3eb4908..2c5c683 100755 --- a/stack-orchestrator/config/tmkms/run.sh +++ b/stack-orchestrator/config/tmkms/run.sh @@ -6,18 +6,18 @@ fi set -e -TMKMS_HOME=/root/.tmkms +TMKMS_HOME=/home/tmkmsuser/tmkms TMKMS_SECRETS_DIR=$TMKMS_HOME/secrets TMKMS_STATE_DIR=$TMKMS_HOME/state echo "Initializing tmkms configuration..." # Initialize tmkms config -tmkms init config --home $TMKMS_HOME +tmkms init $TMKMS_HOME # Generate a new softsign key echo "Generating new softsign key..." -tmkms softsign keygen $TMKMS_SECRETS_DIR/kms-identity.key --home $TMKMS_HOME +tmkms softsign keygen $TMKMS_SECRETS_DIR/kms-identity.key # Update tmkms.toml echo "Updating tmkms.toml with chain_id, node IP, and key prefixes..." diff --git a/stack-orchestrator/container-build/tmkms/Dockerfile b/stack-orchestrator/container-build/cerc-tmkms/Dockerfile similarity index 100% rename from stack-orchestrator/container-build/tmkms/Dockerfile rename to stack-orchestrator/container-build/cerc-tmkms/Dockerfile diff --git a/stack-orchestrator/container-build/tmkms/build.sh b/stack-orchestrator/container-build/cerc-tmkms/build.sh similarity index 100% rename from stack-orchestrator/container-build/tmkms/build.sh rename to stack-orchestrator/container-build/cerc-tmkms/build.sh diff --git a/stack-orchestrator/stacks/tmkms/stack.yml b/stack-orchestrator/stacks/tmkms/stack.yml index f254a19..8d01b40 100644 --- a/stack-orchestrator/stacks/tmkms/stack.yml +++ b/stack-orchestrator/stacks/tmkms/stack.yml @@ -2,7 +2,7 @@ version: "1.0" name: tmkms description: "TMKMS for signing consensus messages" repos: - - https://github.com/iqlusioninc/tmkms.git@v0.14.0 + - github.com/iqlusioninc/tmkms@v0.14.0 containers: - cerc/tmkms pods: -- 2.54.0 From 1084e0b6d32e615802efde7a4cf3f28e62f24e8d Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Tue, 10 Jun 2025 19:19:47 +0530 Subject: [PATCH 04/14] Fix editing tmkms config file in run script --- stack-orchestrator/config/tmkms/run.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/stack-orchestrator/config/tmkms/run.sh b/stack-orchestrator/config/tmkms/run.sh index 2c5c683..09af613 100755 --- a/stack-orchestrator/config/tmkms/run.sh +++ b/stack-orchestrator/config/tmkms/run.sh @@ -23,7 +23,7 @@ tmkms softsign keygen $TMKMS_SECRETS_DIR/kms-identity.key echo "Updating tmkms.toml with chain_id, node IP, and key prefixes..." # Add chain configuration -cat <> $TMKMS_HOME/tmkms.toml +cat < $TMKMS_HOME/tmkms.toml [[chain]] id = "$CERC_CHAIN_ID" -- 2.54.0 From f0a2cf908283af7217cf8047d872b48bd4a19e7e Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Wed, 11 Jun 2025 10:02:46 +0530 Subject: [PATCH 05/14] Update run script to use validator priv key file --- stack-orchestrator/compose/docker-compose-tmkms.yml | 5 +++-- stack-orchestrator/config/tmkms/run.sh | 13 ++++++++++++- 2 files changed, 15 insertions(+), 3 deletions(-) diff --git a/stack-orchestrator/compose/docker-compose-tmkms.yml b/stack-orchestrator/compose/docker-compose-tmkms.yml index 1790eae..5285688 100644 --- a/stack-orchestrator/compose/docker-compose-tmkms.yml +++ b/stack-orchestrator/compose/docker-compose-tmkms.yml @@ -6,12 +6,13 @@ services: environment: CERC_CHAIN_ID: ${CERC_CHAIN_ID:-laconic-mainnet} NODE_IP: ${NODE_IP:-localhost} + NODE_PORT: ${NODE_PORT:-26659} CERC_KEY_PREFIX: ${CERC_KEY_PREFIX:-laconic} volumes: - tmkms-data:/home/tmkmsuser/tmkms - ../config/tmkms/run.sh:/opt/run.sh - ports: - - "26659" + extra_hosts: + - "host.docker.internal:host-gateway" volumes: tmkms-data: diff --git a/stack-orchestrator/config/tmkms/run.sh b/stack-orchestrator/config/tmkms/run.sh index 09af613..342fd99 100755 --- a/stack-orchestrator/config/tmkms/run.sh +++ b/stack-orchestrator/config/tmkms/run.sh @@ -7,6 +7,7 @@ fi set -e TMKMS_HOME=/home/tmkmsuser/tmkms +INPUT_PRIV_KEY_FILE=$TMKMS_HOME/tmp/priv_validator_key.json TMKMS_SECRETS_DIR=$TMKMS_HOME/secrets TMKMS_STATE_DIR=$TMKMS_HOME/state @@ -32,7 +33,7 @@ state_file = "$TMKMS_STATE_DIR/priv_validator_state.json" [[validator]] chain_id = "$CERC_CHAIN_ID" -addr = "tcp://$NODE_IP:26659" +addr = "tcp://$NODE_IP:$NODE_PORT" secret_key = "$TMKMS_SECRETS_DIR/kms-identity.key" protocol_version = "v0.34" reconnect = true @@ -43,5 +44,15 @@ path = "$TMKMS_SECRETS_DIR/priv_validator_key" chain_ids = ["$CERC_CHAIN_ID"] EOF +# Place validator key in secrets directory +cp $INPUT_PRIV_KEY_FILE $TMKMS_SECRETS_DIR/priv_validator_key.json + +# Import the private validator key into tmkms +echo "Importing private validator key into tmkms..." +tmkms softsign import $TMKMS_SECRETS_DIR/priv_validator_key.json $TMKMS_SECRETS_DIR/priv_validator_key + +# Remove the JSON key file +rm $TMKMS_SECRETS_DIR/priv_validator_key.json + echo "Starting tmkms..." tmkms start --config $TMKMS_HOME/tmkms.toml -- 2.54.0 From 65153f090edd8a1915feb1bb1eb1595dd2979830 Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Wed, 11 Jun 2025 11:48:37 +0530 Subject: [PATCH 06/14] Add playbooks to run tmkms service --- playbooks/tmkms/run-tmkms.yml | 41 +++++++++++++++++++ playbooks/tmkms/setup-tmkms.yml | 34 +++++++++++++++ playbooks/tmkms/tmkms-vars.example.yml | 5 +++ .../compose/docker-compose-tmkms.yml | 2 +- .../container-build/cerc-tmkms/build.sh | 1 + 5 files changed, 82 insertions(+), 1 deletion(-) create mode 100644 playbooks/tmkms/run-tmkms.yml create mode 100644 playbooks/tmkms/setup-tmkms.yml create mode 100644 playbooks/tmkms/tmkms-vars.example.yml diff --git a/playbooks/tmkms/run-tmkms.yml b/playbooks/tmkms/run-tmkms.yml new file mode 100644 index 0000000..2ea5d6b --- /dev/null +++ b/playbooks/tmkms/run-tmkms.yml @@ -0,0 +1,41 @@ +--- +- name: Run TMKMS stack + hosts: localhost + vars_files: + - tmkms-vars.yml + vars: + data_directory: "{{ lookup('env', 'DATA_DIRECTORY') }}" + tmkms_deployment_dir: "{{ lookup('env', 'TMKMS_DEPLOYMENT_DIR') | default('tmkms-deployment', true) }}" + tasks: + - name: Fail if DATA_DIRECTORY env var is not set + fail: + msg: >- + Required environment variable DATA_DIRECTORY is not set. + Please export DATA_DIRECTORY before running the playbook. + when: lookup('env', 'DATA_DIRECTORY') == '' + + - name: Ensure tmp directory exists inside tmkms-data volume + file: + path: "{{data_directory}}/{{ tmkms_deployment_dir }}/data/tmkms-data/tmp" + state: directory + mode: '0755' + + - name: Copy private validator key to tmkms deployment tmp directory + copy: + src: "{{ priv_validator_key_file_path }}" + dest: "{{data_directory}}/{{ tmkms_deployment_dir }}/data/tmkms-data/tmp/priv_validator_key.json" + mode: '0644' + + - name: Create config.env for tmkms deployment + copy: + dest: "{{data_directory}}/{{ tmkms_deployment_dir }}/config.env" + content: | + CERC_CHAIN_ID: "{{ cerc_chain_id }}" + NODE_IP: "{{ node_ip }}" + NODE_PORT: "{{ node_port }}" + CERC_KEY_PREFIX: "{{ cerc_key_prefix }}" + mode: '0777' + + - name: Start tmkms deployment + shell: | + laconic-so deployment --dir {{data_directory}}/{{ tmkms_deployment_dir }} start diff --git a/playbooks/tmkms/setup-tmkms.yml b/playbooks/tmkms/setup-tmkms.yml new file mode 100644 index 0000000..a4a070c --- /dev/null +++ b/playbooks/tmkms/setup-tmkms.yml @@ -0,0 +1,34 @@ +--- +- name: Setup TMKMS stack + hosts: localhost + vars_files: + - tmkms-vars.yml + vars: + data_directory: "{{ lookup('env', 'DATA_DIRECTORY') }}" + tmkms_deployment_dir: "{{ lookup('env', 'TMKMS_DEPLOYMENT_DIR') | default('tmkms-deployment', true) }}" + tmkms_spec_file: "{{data_directory}}/tmkms-spec.yml" + build_args: "{{ '--force-rebuild' if (lookup('env', 'FORCE_REBUILD') | default(omit, true)) not in [ 'false', 'False', '0' ] else '' }}" + tasks: + - name: Fail if DATA_DIRECTORY env var is not set + fail: + msg: >- + Required environment variable DATA_DIRECTORY is not set. + Please export DATA_DIRECTORY before running the playbook. + when: lookup('env', 'DATA_DIRECTORY') == '' + + - name: Setup required repositories for tmkms stack + shell: > + laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms + setup-repositories --git-ssh --pull + + - name: Build tmkms container images + shell: | + laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms build-containers {{ build_args }} + + - name: Create tmkms deployment spec file + shell: | + laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms deploy init --output {{ tmkms_spec_file }} + + - name: Create tmkms deployment from spec file + shell: | + laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms deploy create --spec-file {{ tmkms_spec_file }} --deployment-dir {{data_directory}}/{{ tmkms_deployment_dir }} diff --git a/playbooks/tmkms/tmkms-vars.example.yml b/playbooks/tmkms/tmkms-vars.example.yml new file mode 100644 index 0000000..bf77bad --- /dev/null +++ b/playbooks/tmkms/tmkms-vars.example.yml @@ -0,0 +1,5 @@ +priv_validator_key_file_path: "" +node_ip: "" +node_port: "26659" +cerc_key_prefix: "laconic" +cerc_chain_id: "laconic-mainnet" diff --git a/stack-orchestrator/compose/docker-compose-tmkms.yml b/stack-orchestrator/compose/docker-compose-tmkms.yml index 5285688..f6807cf 100644 --- a/stack-orchestrator/compose/docker-compose-tmkms.yml +++ b/stack-orchestrator/compose/docker-compose-tmkms.yml @@ -5,7 +5,7 @@ services: command: ["bash", "-c", "/opt/run.sh"] environment: CERC_CHAIN_ID: ${CERC_CHAIN_ID:-laconic-mainnet} - NODE_IP: ${NODE_IP:-localhost} + NODE_IP: ${NODE_IP} NODE_PORT: ${NODE_PORT:-26659} CERC_KEY_PREFIX: ${CERC_KEY_PREFIX:-laconic} volumes: diff --git a/stack-orchestrator/container-build/cerc-tmkms/build.sh b/stack-orchestrator/container-build/cerc-tmkms/build.sh index e929727..72fe654 100755 --- a/stack-orchestrator/container-build/cerc-tmkms/build.sh +++ b/stack-orchestrator/container-build/cerc-tmkms/build.sh @@ -6,4 +6,5 @@ source ${CERC_CONTAINER_BASE_DIR}/build-base.sh # See: https://stackoverflow.com/a/246128/1701505 SCRIPT_DIR=$( cd -- "$( dirname -- "${BASH_SOURCE[0]}" )" &> /dev/null && pwd ) +# TODO: Use BACKEND=yubihsm build command arg docker build -t cerc/tmkms:local ${build_command_args} -f ${SCRIPT_DIR}/Dockerfile ${CERC_REPO_BASE_DIR}/tmkms -- 2.54.0 From c37e33e5e769ca60877319e7f5eabada80c2b0eb Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Wed, 11 Jun 2025 11:49:10 +0530 Subject: [PATCH 07/14] Update tmkms instructions to use playbooks --- docs/run-first-validator.md | 128 +++++++++++++++++------------------ docs/run-validator.md | 131 +++++++++++++++++++++--------------- 2 files changed, 135 insertions(+), 124 deletions(-) diff --git a/docs/run-first-validator.md b/docs/run-first-validator.md index 72dc128..cb17428 100644 --- a/docs/run-first-validator.md +++ b/docs/run-first-validator.md @@ -14,6 +14,8 @@ - LPS distribution Google spreadsheet URL or CSV file path +- Machine 4: Where the TMKMS service is to be setup + - Following tools are required in all machines: - [ansible](playbooks/README.md#ansible-installation) @@ -81,6 +83,46 @@ NOTE: This public key is required in [next step to generate the genesis file](#generate-mainnet-genesis-file) +- Copy over the `priv_validator_key.json` located at `$DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json` to the machine where the TMKMS service is to be setup (machine 4) + +## Setup TMKMS + +- For integrating TMKMS with laconicd, follow steps below in the machine where the TMKMS service is to be setup (machine 4) + +- Copy the example variables file: + + ```bash + cp ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.example.yml ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml + ``` + +- Update `~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml` with required values: + + NOTE: Use the `priv_validator_key.json` file copied from the node setup machine (Machine 2) in [previous step](#setup-node) + + ```yaml + # Absolute path to the node's private validator key file + priv_validator_key_file_path: "" + + # Set the IP address of the machine where the laconicd node is setup + node_ip: "" + + # Set the port of the laconicd node + node_port: "26659" + ``` + +- Export the data directory and TMKMS deployment directory as environment variables: + + ```bash + # Parent directory where the deployment directory will live + export DATA_DIRECTORY= + ``` + +- Run ansible playbook to setup the TMKMS service: + + ```bash + ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/setup-tmkms.yml + ``` + ## Export testnet state - Run the following steps in machine where the testnet node is already running (machine 1) @@ -177,72 +219,20 @@ ## Run node -- Run the following steps in the machine where the mainnet node is setup (machine 2) +### Start TMKMS -### Setup TMKMS (Optional but Recommended) +- Run these steps in the machine where the TMKMS service is setup (machine 4) - - -- For integrating existing TMKMS with laconicd, follow steps below in the machine where TMKMS is setup - -- Set `$TMKMS_HOME` to the directory path containing TMKMS config files +- Run ansible playbook to run the TMKMS: ```bash - # Contents of tmkms config directory - ls -l $TMKMS_HOME - drwxrwxr-x 2 ... schema - drwx------ 2 ... secrets - drwxrwxr-x 2 ... state - -rw-rw-r-- 1 ... tmkms.toml + ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/run-tmkms.yml ``` -- Update the TMKMS configuration file `$TMKMS_HOME/tmkms.toml`: - - ```toml - [[chain]] - id = "laconic-mainnet" - key_format = { type = "cosmos-json", account_key_prefix = "laconicpub", consensus_key_prefix = "laconicvalconspub" } - # Replace with absolute path to tmkms config directory - state_file = "/state/priv_validator_state.json" - - [[validator]] - chain_id = "laconic-mainnet" - # Replace with actual IP address of the laconicd node - addr = "tcp://:26659" - # Replace with absolute path to tmkms config directory - secret_key = "/secrets/kms-identity.key" - protocol_version = "v0.34" - reconnect = true - - [[providers.softsign]] - key_type = "consensus" - # Replace with absolute path to tmkms config directory - path = "/secrets/priv_validator_key" - chain_ids = ["laconic-mainnet"] - ``` - -- Copy your validator key to TMKMS: - - - The validator key in laconicd node deployment is present at `$DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json` - - - Place the validator key file in TMKMS config directory at `$TMKMS_HOME/secrets/` - - - Import the private validator key into tmkms: - - ```bash - tmkms softsign import $TMKMS_HOME/secrets/priv_validator_key.json $TMKMS_HOME/secrets/priv_validator_key - ``` - - - Remove the JSON key file - - ```bash - rm $TMKMS_HOME/secrets/priv_validator_key.json - ``` - -- Start TMKMS: +- Check logs to ensure that TMKMS is running: ```bash - tmkms start --config $TMKMS_HOME/tmkms.toml + laconic-so deployment --dir $DATA_DIRECTORY/$TMKMS_DEPLOYMENT_DIR logs tmkms -f ``` - Expected example output: @@ -251,19 +241,12 @@ INFO tmkms::commands::start: tmkms 0.14.0 starting up... INFO tmkms::keyring: [keyring:softsign] added consensus Ed25519 key: {"@type":"/cosmos.crypto.ed25519.PubKey","key":"T24No1A1FmetNRVCOSg2G2XAKWh97oBXuELdAD6DFgw="} INFO tmkms::connection::tcp: KMS node ID: 7f5fd8dae8953e964e7e56edd4700f597ea0d45c - ERROR tmkms::client: [laconic-mainnet@tcp://localhost:26659] I/O error: Connection refused (os error 111) + ERROR tmkms::client: [laconic-mainnet@tcp://:26659] I/O error: Connection refused (os error 111) ``` NOTE: The errors dissapear once the laconicd node starts - - Note the pubkey logged at start for comparing later with validator pubkey on chain - -- Enable TMKMS in the laconicd node configuration: - - ```bash - # Set TMKMS_ENABLED to true in the node's config.env - echo "TMKMS_ENABLED=true" >> $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env - ``` +- Note the pubkey logged at start for comparing later with validator pubkey on chain - Remove the validator key from node deployment as it is no longer required: @@ -275,6 +258,15 @@ ### Start node +- Run the following steps in the machine where the mainnet node is setup (machine 2) + +- Enable TMKMS in the laconicd node configuration: + + ```bash + # Set TMKMS_ENABLED to true in the node's config.env + echo "TMKMS_ENABLED=true" >> $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env + ``` + - Copy the genesis file to the mainnet deployment tmp directory: ```bash @@ -293,7 +285,7 @@ laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR logs laconicd -f ``` -- If TMKMS has been configured verify that validator and TMKMS pubkeys match: +- Verify that validator and TMKMS pubkeys match: - Get validator pubkey on chain diff --git a/docs/run-validator.md b/docs/run-validator.md index 697e8e1..cb95731 100644 --- a/docs/run-validator.md +++ b/docs/run-validator.md @@ -16,6 +16,12 @@ - [ansible](playbooks/README.md#ansible-installation) +- Machine 4: Where the TMKMS service is to be setup + + - laconicd-stack + + - [ansible](playbooks/README.md#ansible-installation) + - [laconic-so](https://github.com/cerc-io/stack-orchestrator/?tab=readme-ov-file#install) is required in all machines - To fetch laconicd-stack: @@ -89,72 +95,85 @@ ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/validator/setup-validator.yml ``` -### Setup TMKMS (Optional but Recommended) - - - -- For integrating existing TMKMS with laconicd, follow steps below in the machine where TMKMS is setup - -- Set `$TMKMS_HOME` to the directory path containing TMKMS config files +- Get the public key of your node: ```bash - # Contents of tmkms config directory - ls -l $TMKMS_HOME - drwxrwxr-x 2 ... schema - drwx------ 2 ... secrets - drwxrwxr-x 2 ... state - -rw-rw-r-- 1 ... tmkms.toml + laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR exec laconicd "laconicd tendermint show-validator" ``` -- Update the TMKMS configuration file `$TMKMS_HOME/tmkms.toml`: + NOTE: This public key is required in next step to create validator - ```toml - [[chain]] - id = "laconic-mainnet" - key_format = { type = "cosmos-json", account_key_prefix = "laconicpub", consensus_key_prefix = "laconicvalconspub" } - # Replace with absolute path to tmkms config directory - state_file = "/state/priv_validator_state.json" +- Copy over the `priv_validator_key.json` located at `$DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json` to the machine from where the TMKMS service is to be setup (machine 4) - [[validator]] - chain_id = "laconic-mainnet" - # Replace with actual IP address of the laconicd node - addr = "tcp://:26659" - # Replace with absolute path to tmkms config directory - secret_key = "/secrets/kms-identity.key" - protocol_version = "v0.34" - reconnect = true +## Setup TMKMS - [[providers.softsign]] - key_type = "consensus" - # Replace with absolute path to tmkms config directory - path = "/secrets/priv_validator_key" - chain_ids = ["laconic-mainnet"] - ``` +- For integrating TMKMS with laconicd, follow steps below in the machine where the TMKMS service is to be setup (machine 4) -- Copy your validator key to TMKMS: - - - The validator key in laconicd node deployment is present at `$DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json` - - - Place the validator key file in TMKMS config directory at `$TMKMS_HOME/secrets/` - - - Import the private validator key into tmkms: - - ```bash - tmkms softsign import $TMKMS_HOME/secrets/priv_validator_key.json $TMKMS_HOME/secrets/priv_validator_key - ``` - - - Remove the JSON key file - - ```bash - rm $TMKMS_HOME/secrets/priv_validator_key.json - ``` - -- Start TMKMS: +- Copy the example variables file: ```bash - tmkms start --config $TMKMS_HOME/tmkms.toml + cp ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.example.yml ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml ``` +- Update `~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml` with required values: + + NOTE: Use the `priv_validator_key.json` file copied from the node setup machine (Machine 2) in [previous step](#setup-node) + + ```yaml + # Absolute path to the node's private validator key file + priv_validator_key_file_path: "" + + # Set the IP address of the machine where the laconicd node is setup + node_ip: "" + + # Set the port of the laconicd node + node_port: "26659" + ``` + +- Export the data directory as environment variable: + + ```bash + # Parent directory where the deployment directory will live + export DATA_DIRECTORY= + ``` + +- Run ansible playbook to setup the TMKMS service: + + ```bash + ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/setup-tmkms.yml + ``` + +## Run Node + +### Start TMKMS + +- Run the following steps in the machine where the TMKMS service is setup (Machine 4) + +- Run ansible playbook to run the TMKMS: + + ```bash + ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/run-tmkms.yml + ``` + +- Check logs to ensure that TMKMS is running: + + ```bash + laconic-so deployment --dir $DATA_DIRECTORY/$TMKMS_DEPLOYMENT_DIR logs tmkms -f + ``` + + - Expected example output: + + ```bash + INFO tmkms::commands::start: tmkms 0.14.0 starting up... + INFO tmkms::keyring: [keyring:softsign] added consensus Ed25519 key: {"@type":"/cosmos.crypto.ed25519.PubKey","key":"T24No1A1FmetNRVCOSg2G2XAKWh97oBXuELdAD6DFgw="} + INFO tmkms::connection::tcp: KMS node ID: 7f5fd8dae8953e964e7e56edd4700f597ea0d45c + ERROR tmkms::client: [laconic-mainnet@:26659] I/O error: Connection refused (os error 111) + ``` + + NOTE: The errors dissapear once the laconicd node starts + +- Note the pubkey logged at start for comparing later with validator pubkey on chain + - Enable TMKMS in the laconicd node configuration: ```bash @@ -162,7 +181,7 @@ echo "TMKMS_ENABLED=true" >> $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env ``` -## Start Node +### Start Node - Start the laconicd node: @@ -234,7 +253,7 @@ laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR exec laconicd 'laconicd query staking validators' ``` - - If TMKMS has been configured, remove the validator key from node deployment as it is no longer required: + - Remove the validator key from node deployment as TMKMS is configured: ```bash rm $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json -- 2.54.0 From 0029ac5247d0d08f05d28f099fa25e19dc77b14e Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Wed, 11 Jun 2025 12:33:39 +0530 Subject: [PATCH 08/14] Update instructions to setup and start tmkms service --- docs/run-first-validator.md | 44 +++++++++++++++++------------------ docs/run-validator.md | 46 +++++++++++++++++++------------------ 2 files changed, 46 insertions(+), 44 deletions(-) diff --git a/docs/run-first-validator.md b/docs/run-first-validator.md index cb17428..1988806 100644 --- a/docs/run-first-validator.md +++ b/docs/run-first-validator.md @@ -89,27 +89,6 @@ - For integrating TMKMS with laconicd, follow steps below in the machine where the TMKMS service is to be setup (machine 4) -- Copy the example variables file: - - ```bash - cp ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.example.yml ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml - ``` - -- Update `~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml` with required values: - - NOTE: Use the `priv_validator_key.json` file copied from the node setup machine (Machine 2) in [previous step](#setup-node) - - ```yaml - # Absolute path to the node's private validator key file - priv_validator_key_file_path: "" - - # Set the IP address of the machine where the laconicd node is setup - node_ip: "" - - # Set the port of the laconicd node - node_port: "26659" - ``` - - Export the data directory and TMKMS deployment directory as environment variables: ```bash @@ -223,6 +202,27 @@ - Run these steps in the machine where the TMKMS service is setup (machine 4) +- Copy the example variables file: + + ```bash + cp ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.example.yml ~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml + ``` + +- Update `~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml` with required values: + + NOTE: Use the `priv_validator_key.json` file copied from the node setup machine (Machine 2) in [previous step](#setup-node) + + ```yaml + # Absolute path to the node's private validator key file + priv_validator_key_file_path: "" + + # Set the IP address of the machine where the laconicd node is setup + node_ip: "" + + # Set the port of the laconicd node + node_port: "26659" + ``` + - Run ansible playbook to run the TMKMS: ```bash @@ -232,7 +232,7 @@ - Check logs to ensure that TMKMS is running: ```bash - laconic-so deployment --dir $DATA_DIRECTORY/$TMKMS_DEPLOYMENT_DIR logs tmkms -f + laconic-so deployment --dir $DATA_DIRECTORY/tmkms-deployment logs tmkms -f ``` - Expected example output: diff --git a/docs/run-validator.md b/docs/run-validator.md index cb95731..8ab887c 100644 --- a/docs/run-validator.md +++ b/docs/run-validator.md @@ -109,6 +109,25 @@ - For integrating TMKMS with laconicd, follow steps below in the machine where the TMKMS service is to be setup (machine 4) +- Export the data directory as environment variable: + + ```bash + # Parent directory where the deployment directory will live + export DATA_DIRECTORY= + ``` + +- Run ansible playbook to setup the TMKMS service: + + ```bash + ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/setup-tmkms.yml + ``` + +## Run Node + +### Start TMKMS + +- Run the following steps in the machine where the TMKMS service is setup (Machine 4) + - Copy the example variables file: ```bash @@ -130,25 +149,6 @@ node_port: "26659" ``` -- Export the data directory as environment variable: - - ```bash - # Parent directory where the deployment directory will live - export DATA_DIRECTORY= - ``` - -- Run ansible playbook to setup the TMKMS service: - - ```bash - ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/setup-tmkms.yml - ``` - -## Run Node - -### Start TMKMS - -- Run the following steps in the machine where the TMKMS service is setup (Machine 4) - - Run ansible playbook to run the TMKMS: ```bash @@ -158,7 +158,7 @@ - Check logs to ensure that TMKMS is running: ```bash - laconic-so deployment --dir $DATA_DIRECTORY/$TMKMS_DEPLOYMENT_DIR logs tmkms -f + laconic-so deployment --dir $DATA_DIRECTORY/tmkms-deployment logs tmkms -f ``` - Expected example output: @@ -174,6 +174,10 @@ - Note the pubkey logged at start for comparing later with validator pubkey on chain +### Start Node + +- Run the following steps in the machine where the validator node is setup (machine 2) + - Enable TMKMS in the laconicd node configuration: ```bash @@ -181,8 +185,6 @@ echo "TMKMS_ENABLED=true" >> $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env ``` -### Start Node - - Start the laconicd node: ```bash -- 2.54.0 From 2c98c019cc4178a5ba6cf2cc26a83cf2190a0ae5 Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Wed, 11 Jun 2025 15:23:49 +0530 Subject: [PATCH 09/14] Remove tmkms stack and update setup playbook --- playbooks/tmkms/setup-tmkms.yml | 14 +++-- .../compose/docker-compose-tmkms.yml | 18 ------ stack-orchestrator/config/tmkms/run.sh | 58 ------------------- .../container-build/cerc-tmkms/Dockerfile | 56 ------------------ .../container-build/cerc-tmkms/build.sh | 10 ---- stack-orchestrator/stacks/tmkms/stack.yml | 9 --- 6 files changed, 8 insertions(+), 157 deletions(-) delete mode 100644 stack-orchestrator/compose/docker-compose-tmkms.yml delete mode 100755 stack-orchestrator/config/tmkms/run.sh delete mode 100644 stack-orchestrator/container-build/cerc-tmkms/Dockerfile delete mode 100755 stack-orchestrator/container-build/cerc-tmkms/build.sh delete mode 100644 stack-orchestrator/stacks/tmkms/stack.yml diff --git a/playbooks/tmkms/setup-tmkms.yml b/playbooks/tmkms/setup-tmkms.yml index a4a070c..c98cd9d 100644 --- a/playbooks/tmkms/setup-tmkms.yml +++ b/playbooks/tmkms/setup-tmkms.yml @@ -1,8 +1,6 @@ --- - name: Setup TMKMS stack hosts: localhost - vars_files: - - tmkms-vars.yml vars: data_directory: "{{ lookup('env', 'DATA_DIRECTORY') }}" tmkms_deployment_dir: "{{ lookup('env', 'TMKMS_DEPLOYMENT_DIR') | default('tmkms-deployment', true) }}" @@ -16,19 +14,23 @@ Please export DATA_DIRECTORY before running the playbook. when: lookup('env', 'DATA_DIRECTORY') == '' + - name: Fetch tmkms stack + shell: | + laconic-so fetch-stack git.vdb.to/LaconicNetwork/tmkms-stack --git-ssh --pull + - name: Setup required repositories for tmkms stack shell: > - laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms + laconic-so --stack ~/cerc/tmkms-stack/stack-orchestrator/stacks/tmkms setup-repositories --git-ssh --pull - name: Build tmkms container images shell: | - laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms build-containers {{ build_args }} + laconic-so --stack ~/cerc/tmkms-stack/stack-orchestrator/stacks/tmkms build-containers {{ build_args }} - name: Create tmkms deployment spec file shell: | - laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms deploy init --output {{ tmkms_spec_file }} + laconic-so --stack ~/cerc/tmkms-stack/stack-orchestrator/stacks/tmkms deploy init --output {{ tmkms_spec_file }} - name: Create tmkms deployment from spec file shell: | - laconic-so --stack ~/cerc/laconicd-stack/stack-orchestrator/stacks/tmkms deploy create --spec-file {{ tmkms_spec_file }} --deployment-dir {{data_directory}}/{{ tmkms_deployment_dir }} + laconic-so --stack ~/cerc/tmkms-stack/stack-orchestrator/stacks/tmkms deploy create --spec-file {{ tmkms_spec_file }} --deployment-dir {{data_directory}}/{{ tmkms_deployment_dir }} diff --git a/stack-orchestrator/compose/docker-compose-tmkms.yml b/stack-orchestrator/compose/docker-compose-tmkms.yml deleted file mode 100644 index f6807cf..0000000 --- a/stack-orchestrator/compose/docker-compose-tmkms.yml +++ /dev/null @@ -1,18 +0,0 @@ -services: - tmkms: - restart: unless-stopped - image: cerc/tmkms:local - command: ["bash", "-c", "/opt/run.sh"] - environment: - CERC_CHAIN_ID: ${CERC_CHAIN_ID:-laconic-mainnet} - NODE_IP: ${NODE_IP} - NODE_PORT: ${NODE_PORT:-26659} - CERC_KEY_PREFIX: ${CERC_KEY_PREFIX:-laconic} - volumes: - - tmkms-data:/home/tmkmsuser/tmkms - - ../config/tmkms/run.sh:/opt/run.sh - extra_hosts: - - "host.docker.internal:host-gateway" - -volumes: - tmkms-data: diff --git a/stack-orchestrator/config/tmkms/run.sh b/stack-orchestrator/config/tmkms/run.sh deleted file mode 100755 index 342fd99..0000000 --- a/stack-orchestrator/config/tmkms/run.sh +++ /dev/null @@ -1,58 +0,0 @@ -#!/bin/bash - -if [[ -n "$CERC_SCRIPT_DEBUG" ]]; then - set -x -fi - -set -e - -TMKMS_HOME=/home/tmkmsuser/tmkms -INPUT_PRIV_KEY_FILE=$TMKMS_HOME/tmp/priv_validator_key.json -TMKMS_SECRETS_DIR=$TMKMS_HOME/secrets -TMKMS_STATE_DIR=$TMKMS_HOME/state - -echo "Initializing tmkms configuration..." - -# Initialize tmkms config -tmkms init $TMKMS_HOME - -# Generate a new softsign key -echo "Generating new softsign key..." -tmkms softsign keygen $TMKMS_SECRETS_DIR/kms-identity.key - -# Update tmkms.toml -echo "Updating tmkms.toml with chain_id, node IP, and key prefixes..." - -# Add chain configuration -cat < $TMKMS_HOME/tmkms.toml - -[[chain]] -id = "$CERC_CHAIN_ID" -key_format = { type = "cosmos-json", account_key_prefix = "${CERC_KEY_PREFIX}pub", consensus_key_prefix = "${CERC_KEY_PREFIX}valconspub" } -state_file = "$TMKMS_STATE_DIR/priv_validator_state.json" - -[[validator]] -chain_id = "$CERC_CHAIN_ID" -addr = "tcp://$NODE_IP:$NODE_PORT" -secret_key = "$TMKMS_SECRETS_DIR/kms-identity.key" -protocol_version = "v0.34" -reconnect = true - -[[providers.softsign]] -key_type = "consensus" -path = "$TMKMS_SECRETS_DIR/priv_validator_key" -chain_ids = ["$CERC_CHAIN_ID"] -EOF - -# Place validator key in secrets directory -cp $INPUT_PRIV_KEY_FILE $TMKMS_SECRETS_DIR/priv_validator_key.json - -# Import the private validator key into tmkms -echo "Importing private validator key into tmkms..." -tmkms softsign import $TMKMS_SECRETS_DIR/priv_validator_key.json $TMKMS_SECRETS_DIR/priv_validator_key - -# Remove the JSON key file -rm $TMKMS_SECRETS_DIR/priv_validator_key.json - -echo "Starting tmkms..." -tmkms start --config $TMKMS_HOME/tmkms.toml diff --git a/stack-orchestrator/container-build/cerc-tmkms/Dockerfile b/stack-orchestrator/container-build/cerc-tmkms/Dockerfile deleted file mode 100644 index ccd1473..0000000 --- a/stack-orchestrator/container-build/cerc-tmkms/Dockerfile +++ /dev/null @@ -1,56 +0,0 @@ -# -------- Stage 1: Build -------- -FROM debian:bookworm-slim AS builder - -ARG BACKEND=softsign -ARG VERSION=main - -# Install build dependencies -RUN apt-get update && \ - DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ - build-essential \ - clang \ - curl \ - git \ - pkg-config \ - libsodium-dev \ - libssl-dev \ - ca-certificates && \ - apt-get clean && rm -rf /var/lib/apt/lists/* - -# Create non-root user -RUN useradd -m builder -USER builder -WORKDIR /home/builder - -ENV PATH="/home/builder/.cargo/bin:$PATH" - -# Install Rust -RUN curl https://sh.rustup.rs -sSf | sh -s -- -y && \ - rustup component add rustfmt clippy - -# Clone and build TMKMS -RUN git clone --depth 1 --branch ${VERSION} https://github.com/iqlusioninc/tmkms.git && \ - cd tmkms && \ - cargo build --release --features=${BACKEND} - -# -------- Stage 2: Runtime -------- -FROM debian:bookworm-slim - -# Install runtime dependencies only -RUN apt-get update && \ - DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ - libssl3 \ - libsodium23 \ - ca-certificates && \ - apt-get clean && rm -rf /var/lib/apt/lists/* - -# Copy compiled binary -COPY --from=builder /home/builder/tmkms/target/release/tmkms /usr/local/bin/tmkms - -# Create runtime user -RUN useradd -m tmkmsuser -USER tmkmsuser -WORKDIR /home/tmkmsuser - -# Default command, override with `docker run ... bash` etc. -CMD ["tmkms"] diff --git a/stack-orchestrator/container-build/cerc-tmkms/build.sh b/stack-orchestrator/container-build/cerc-tmkms/build.sh deleted file mode 100755 index 72fe654..0000000 --- a/stack-orchestrator/container-build/cerc-tmkms/build.sh +++ /dev/null @@ -1,10 +0,0 @@ -#!/usr/bin/env bash - -# Build cerc/tmkms -source ${CERC_CONTAINER_BASE_DIR}/build-base.sh - -# See: https://stackoverflow.com/a/246128/1701505 -SCRIPT_DIR=$( cd -- "$( dirname -- "${BASH_SOURCE[0]}" )" &> /dev/null && pwd ) - -# TODO: Use BACKEND=yubihsm build command arg -docker build -t cerc/tmkms:local ${build_command_args} -f ${SCRIPT_DIR}/Dockerfile ${CERC_REPO_BASE_DIR}/tmkms diff --git a/stack-orchestrator/stacks/tmkms/stack.yml b/stack-orchestrator/stacks/tmkms/stack.yml deleted file mode 100644 index 8d01b40..0000000 --- a/stack-orchestrator/stacks/tmkms/stack.yml +++ /dev/null @@ -1,9 +0,0 @@ -version: "1.0" -name: tmkms -description: "TMKMS for signing consensus messages" -repos: - - github.com/iqlusioninc/tmkms@v0.14.0 -containers: - - cerc/tmkms -pods: - - tmkms -- 2.54.0 From 70d0a0038b3a868a085d173de68857f411e5581a Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Wed, 11 Jun 2025 19:08:32 +0530 Subject: [PATCH 10/14] Update tmkms env vars --- playbooks/tmkms/run-tmkms.yml | 4 ++-- playbooks/tmkms/setup-tmkms.yml | 5 ----- playbooks/tmkms/tmkms-vars.example.yml | 4 ++-- 3 files changed, 4 insertions(+), 9 deletions(-) diff --git a/playbooks/tmkms/run-tmkms.yml b/playbooks/tmkms/run-tmkms.yml index 2ea5d6b..bfe3d87 100644 --- a/playbooks/tmkms/run-tmkms.yml +++ b/playbooks/tmkms/run-tmkms.yml @@ -30,10 +30,10 @@ copy: dest: "{{data_directory}}/{{ tmkms_deployment_dir }}/config.env" content: | - CERC_CHAIN_ID: "{{ cerc_chain_id }}" + CHAIN_ID: "{{ chain_id }}" NODE_IP: "{{ node_ip }}" NODE_PORT: "{{ node_port }}" - CERC_KEY_PREFIX: "{{ cerc_key_prefix }}" + KEY_PREFIX: "{{ key_prefix }}" mode: '0777' - name: Start tmkms deployment diff --git a/playbooks/tmkms/setup-tmkms.yml b/playbooks/tmkms/setup-tmkms.yml index c98cd9d..643040f 100644 --- a/playbooks/tmkms/setup-tmkms.yml +++ b/playbooks/tmkms/setup-tmkms.yml @@ -18,11 +18,6 @@ shell: | laconic-so fetch-stack git.vdb.to/LaconicNetwork/tmkms-stack --git-ssh --pull - - name: Setup required repositories for tmkms stack - shell: > - laconic-so --stack ~/cerc/tmkms-stack/stack-orchestrator/stacks/tmkms - setup-repositories --git-ssh --pull - - name: Build tmkms container images shell: | laconic-so --stack ~/cerc/tmkms-stack/stack-orchestrator/stacks/tmkms build-containers {{ build_args }} diff --git a/playbooks/tmkms/tmkms-vars.example.yml b/playbooks/tmkms/tmkms-vars.example.yml index bf77bad..917d642 100644 --- a/playbooks/tmkms/tmkms-vars.example.yml +++ b/playbooks/tmkms/tmkms-vars.example.yml @@ -1,5 +1,5 @@ priv_validator_key_file_path: "" node_ip: "" node_port: "26659" -cerc_key_prefix: "laconic" -cerc_chain_id: "laconic-mainnet" +key_prefix: "laconic" +chain_id: "laconic-mainnet" -- 2.54.0 From 3333c91fef6d9a588c9f4b0ace41a607092387ef Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Thu, 12 Jun 2025 10:08:53 +0530 Subject: [PATCH 11/14] Handle re-running tmkms playbook --- docs/run-first-validator.md | 64 +++++++++++++++---- docs/run-validator.md | 57 +++++++++++++++-- .../cosmos-multisig-vars.example.yml | 31 +++++++++ .../first-validator-vars.example.yml | 16 +++++ .../first-validator/setup-first-validator.yml | 1 + playbooks/tmkms/run-tmkms.yml | 6 ++ playbooks/tmkms/tmkms-vars.example.yml | 11 ++++ playbooks/validator/setup-validator.yml | 1 + .../validator/validator-vars.example.yml | 25 ++++++++ 9 files changed, 194 insertions(+), 18 deletions(-) diff --git a/docs/run-first-validator.md b/docs/run-first-validator.md index 1988806..2c72419 100644 --- a/docs/run-first-validator.md +++ b/docs/run-first-validator.md @@ -55,6 +55,9 @@ # Set desired key name key_name: "laconic-validator" + + # Enable TMKMS + tmkms_enabled: true ``` - Export the data directory and mainnet deployment directory as environment variables: @@ -248,6 +251,16 @@ - Note the pubkey logged at start for comparing later with validator pubkey on chain +- Remove the `priv_validator_key.json` file from TMKMS machine as it is no longer required: + + ```bash + rm -rf + ``` + +### Start node + +- Run the following steps in the machine where the mainnet node is setup (machine 2) + - Remove the validator key from node deployment as it is no longer required: ```bash @@ -256,17 +269,6 @@ NOTE: Store it safely offline in case of an emergency -### Start node - -- Run the following steps in the machine where the mainnet node is setup (machine 2) - -- Enable TMKMS in the laconicd node configuration: - - ```bash - # Set TMKMS_ENABLED to true in the node's config.env - echo "TMKMS_ENABLED=true" >> $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env - ``` - - Copy the genesis file to the mainnet deployment tmp directory: ```bash @@ -323,6 +325,46 @@ laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR exec laconicd "laconicd query bank balances $EARLY_SUPPORTS_ACC_ADDR" ``` +## Update config + +- Run following steps to update the config for TMKMS and node + +### TMKMS + +- Run these steps in the machine where the TMKMS service is setup (machine 4) + +- Stop the TMKMS deployment: + + ```bash + laconic-so deployment --dir $DATA_DIRECTORY/$TMKMS_DEPLOYMENT_DIR stop + ``` + +- Update `~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml` with required values + +- Run ansible playbook to run the TMKMS: + + ```bash + ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/run-tmkms.yml + ``` + +### Node + +- Run these steps in the machine where the mainnet node is setup (machine 2) + +- Stop the node deployment: + + ```bash + laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR stop + ``` + +- Update `$DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env` with required values + +- Start the node deployment: + + ```bash + laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR start + ``` + ## Publish required artifacts - Run the following steps in machine where the genesis file and staking amount files are generated (machine 3) diff --git a/docs/run-validator.md b/docs/run-validator.md index 8ab887c..fcc9d97 100644 --- a/docs/run-validator.md +++ b/docs/run-validator.md @@ -77,6 +77,10 @@ # Set persistent peers (comma-separated list of node IDs and addresses) # You can find the list of available peers in https://git.vdb.to/cerc-io/laconicd-stack/src/branch/main/node-addresses.yml cerc_peers: "@:26656,@:26656" + + # Enable TMKMS + # Setting this to true will configure the node to use TMKMS for signing blocks + tmkms_enabled: true ``` - Export the data directory and mainnet deployment directory as environment variables: @@ -174,17 +178,16 @@ - Note the pubkey logged at start for comparing later with validator pubkey on chain +- Remove the `priv_validator_key.json` file from TMKMS machine as it is no longer required: + + ```bash + rm -rf + ``` + ### Start Node - Run the following steps in the machine where the validator node is setup (machine 2) -- Enable TMKMS in the laconicd node configuration: - - ```bash - # Set TMKMS_ENABLED to true in the node's config.env - echo "TMKMS_ENABLED=true" >> $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env - ``` - - Start the laconicd node: ```bash @@ -263,6 +266,46 @@ NOTE: Store it safely offline in case of an emergency +## Update config + +- Run following steps to update the config for TMKMS and node + +### TMKMS + +- Run these steps in the machine where the TMKMS service is setup (machine 4) + +- Stop the TMKMS deployment: + + ```bash + laconic-so deployment --dir $DATA_DIRECTORY/$TMKMS_DEPLOYMENT_DIR stop + ``` + +- Update `~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml` with required values + +- Run ansible playbook to run the TMKMS: + + ```bash + ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/tmkms/run-tmkms.yml + ``` + +### Node + +- Run these steps in the machine where the mainnet node is setup (machine 2) + +- Stop the node deployment: + + ```bash + laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR stop + ``` + +- Update `$DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/config.env` with required values + +- Start the node deployment: + + ```bash + laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR start + ``` + ## Register Your Node - Get your node's address: diff --git a/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml b/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml index 4467c24..135a162 100644 --- a/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml +++ b/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml @@ -1,16 +1,47 @@ +# Set to true if the application supports multiple chains next_public_multichain: false + +# The name of the blockchain registry next_public_registry_name: "laconic" + +# URL or path to the blockchain's logo next_public_logo: "" + +# The chain ID for the blockchain network next_public_chain_id: "laconic-mainnet" + +# Display name for the blockchain network next_public_chain_display_name: "Laconic Mainnet" + +# Comma-separated list of node addresses for the application to connect to next_public_node_addresses: '[]' + +# The REST endpoint for the node node_rest_endpoint: "" + +# The base denomination of the native token next_public_denom: "alnt" + +# The display denomination of the native token next_public_display_denom: "ALNT" + +# The exponent for the display denomination (e.g., 18 for 10^18). next_public_display_denom_exponent: 18 + +# JSON array of asset definitions, including denom units, base, name, display, and symbol next_public_assets: '[{"denom_units":[{"denom":"alnt","exponent":0}],"base":"alnt","name":"Laconic Token","display":"ALNT","symbol":"alnt"}]' + +# Default gas price for transactions next_public_gas_price: "0.001alnt" + +# The address prefix for the blockchain next_public_address_prefix: "laconic" + +# Set to true if HTTP is enabled for the application next_public_is_http_enabled: false + +# Set to true to use host network mode for the Docker container use_host_network: "" + +# Domain for Dgraph service dgraph_domain: "" diff --git a/playbooks/first-validator/first-validator-vars.example.yml b/playbooks/first-validator/first-validator-vars.example.yml index fd788c0..57b86d6 100644 --- a/playbooks/first-validator/first-validator-vars.example.yml +++ b/playbooks/first-validator/first-validator-vars.example.yml @@ -1,6 +1,22 @@ +# Custom moniker for the validator node cerc_moniker: "LaconicMainnetNode" + +# The chain ID for the blockchain network cerc_chain_id: "laconic-mainnet" + +# Minimum gas price for transactions, in ALNT (e.g., 0.001alnt) min_gas_price: 0.001 + +# Log level for the laconicd node (e.g., "info", "debug", "error") cerc_loglevel: "info" + +# Desired key name for the validator account key_name: "laconic-validator" + +# Set to true to enable TMKMS (Tendermint Key Management System) for this node +# If true, the node will use an external TMKMS for signing validator operations +tmkms_enabled: false + +# The public key of the validator node. This is required for generating the genesis file +# It should be wrapped in single quotes validator_pub_key: '' diff --git a/playbooks/first-validator/setup-first-validator.yml b/playbooks/first-validator/setup-first-validator.yml index 830684d..b58e3a5 100644 --- a/playbooks/first-validator/setup-first-validator.yml +++ b/playbooks/first-validator/setup-first-validator.yml @@ -46,6 +46,7 @@ CERC_CHAIN_ID: "{{ cerc_chain_id }}" MIN_GAS_PRICE: "{{ min_gas_price }}" CERC_LOGLEVEL: "{{ cerc_loglevel }}" + TMKMS_ENABLED: "{{ tmkms_enabled }}" mode: '0777' - name: Initialize laconicd node diff --git a/playbooks/tmkms/run-tmkms.yml b/playbooks/tmkms/run-tmkms.yml index bfe3d87..c761c00 100644 --- a/playbooks/tmkms/run-tmkms.yml +++ b/playbooks/tmkms/run-tmkms.yml @@ -20,11 +20,17 @@ state: directory mode: '0755' + - name: Check if priv_validator_key_file_path exists + stat: + path: "{{ priv_validator_key_file_path }}" + register: priv_key_file + - name: Copy private validator key to tmkms deployment tmp directory copy: src: "{{ priv_validator_key_file_path }}" dest: "{{data_directory}}/{{ tmkms_deployment_dir }}/data/tmkms-data/tmp/priv_validator_key.json" mode: '0644' + when: priv_key_file.stat.exists - name: Create config.env for tmkms deployment copy: diff --git a/playbooks/tmkms/tmkms-vars.example.yml b/playbooks/tmkms/tmkms-vars.example.yml index 917d642..5518fef 100644 --- a/playbooks/tmkms/tmkms-vars.example.yml +++ b/playbooks/tmkms/tmkms-vars.example.yml @@ -1,5 +1,16 @@ +# Absolute path to the node's private validator key file (e.g., /path/to/priv_validator_key.json). +# This file is copied into the TMKMS deployment priv_validator_key_file_path: "" + +# The IP address of the machine where the laconicd node is set up +# TMKMS will connect to this IP address node_ip: "" + +# The port of the laconicd node that TMKMS will connect to node_port: "26659" + +# The key prefix used for account and consensus public keys in the blockchain key_prefix: "laconic" + +# The chain ID for the blockchain network chain_id: "laconic-mainnet" diff --git a/playbooks/validator/setup-validator.yml b/playbooks/validator/setup-validator.yml index 79ac21c..d0d102d 100644 --- a/playbooks/validator/setup-validator.yml +++ b/playbooks/validator/setup-validator.yml @@ -54,6 +54,7 @@ CERC_PEERS: "{{ cerc_peers }}" MIN_GAS_PRICE: "{{ min_gas_price }}" CERC_LOGLEVEL: "{{ cerc_loglevel }}" + TMKMS_ENABLED: "{{ tmkms_enabled }}" mode: '0777' - name: Ensure tmp directory exists inside laconicd-data diff --git a/playbooks/validator/validator-vars.example.yml b/playbooks/validator/validator-vars.example.yml index a9b99ae..e8819f7 100644 --- a/playbooks/validator/validator-vars.example.yml +++ b/playbooks/validator/validator-vars.example.yml @@ -1,10 +1,35 @@ +# The URL of the laconicd node's RPC endpoint (e.g., "tcp://NODE_PUBLIC_IP_ADDRESS:26657") node_url: "" + +# The public key of the validator node. This is required for creating the validator on chain +# It should be wrapped in single quotes validator_pub_key: '' + +# Custom moniker for the validator node cerc_moniker: "" + +# Comma-separated list of persistent peers for the laconicd node +# You can find available peers in https://git.vdb.to/cerc-io/laconicd-stack/src/branch/main/node-addresses.yml cerc_peers: "" + +# The chain ID for the blockchain network cerc_chain_id: "laconic-mainnet" + +# Minimum gas price for transactions, in ALNT (e.g., 0.001alnt) min_gas_price: 0.001 + +# Log level for the laconicd node (e.g., "info", "debug", "error") cerc_loglevel: "info" + +# Absolute path to the mainnet genesis.json file genesis_file: "~/cerc/laconicd-stack/config/mainnet-genesis.json" + +# Absolute path to the staking-amount.json file staking_amount_file: "~/cerc/laconicd-stack/config/staking-amount.json" + +# Desired key name for the validator account key_name: "laconic-validator" + +# Set to true to enable TMKMS (Tendermint Key Management System) for this node +# If true, the node will use an external TMKMS for signing validator operations +tmkms_enabled: false -- 2.54.0 From c356fb1928139c4e66fa3cfa8461251c895536be Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Thu, 12 Jun 2025 15:25:07 +0530 Subject: [PATCH 12/14] Remove key file in playbook --- docs/run-first-validator.md | 8 +------- docs/run-validator.md | 6 ------ playbooks/tmkms/run-tmkms.yml | 6 ++++++ 3 files changed, 7 insertions(+), 13 deletions(-) diff --git a/docs/run-first-validator.md b/docs/run-first-validator.md index 2c72419..2652aac 100644 --- a/docs/run-first-validator.md +++ b/docs/run-first-validator.md @@ -251,12 +251,6 @@ - Note the pubkey logged at start for comparing later with validator pubkey on chain -- Remove the `priv_validator_key.json` file from TMKMS machine as it is no longer required: - - ```bash - rm -rf - ``` - ### Start node - Run the following steps in the machine where the mainnet node is setup (machine 2) @@ -264,7 +258,7 @@ - Remove the validator key from node deployment as it is no longer required: ```bash - rm $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json + rm -rf $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json ``` NOTE: Store it safely offline in case of an emergency diff --git a/docs/run-validator.md b/docs/run-validator.md index fcc9d97..01f319b 100644 --- a/docs/run-validator.md +++ b/docs/run-validator.md @@ -178,12 +178,6 @@ - Note the pubkey logged at start for comparing later with validator pubkey on chain -- Remove the `priv_validator_key.json` file from TMKMS machine as it is no longer required: - - ```bash - rm -rf - ``` - ### Start Node - Run the following steps in the machine where the validator node is setup (machine 2) diff --git a/playbooks/tmkms/run-tmkms.yml b/playbooks/tmkms/run-tmkms.yml index c761c00..fbd3052 100644 --- a/playbooks/tmkms/run-tmkms.yml +++ b/playbooks/tmkms/run-tmkms.yml @@ -45,3 +45,9 @@ - name: Start tmkms deployment shell: | laconic-so deployment --dir {{data_directory}}/{{ tmkms_deployment_dir }} start + + - name: Remove input private validator key file + file: + path: "{{ priv_validator_key_file_path }}" + state: absent + when: priv_key_file.stat.exists -- 2.54.0 From 3a75574a52b99d8e80bf1e1a344688e0e00628a6 Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Thu, 12 Jun 2025 16:31:12 +0530 Subject: [PATCH 13/14] Update readme steps --- docs/run-first-validator.md | 8 +++--- docs/run-validator.md | 28 ++++++------------- .../first-validator-vars.example.yml | 17 +++++------ .../validator/validator-vars.example.yml | 8 +++--- 4 files changed, 26 insertions(+), 35 deletions(-) diff --git a/docs/run-first-validator.md b/docs/run-first-validator.md index 2652aac..fe8e71f 100644 --- a/docs/run-first-validator.md +++ b/docs/run-first-validator.md @@ -203,7 +203,7 @@ ### Start TMKMS -- Run these steps in the machine where the TMKMS service is setup (machine 4) +- Run these steps in the machine where [the TMKMS service is setup (machine 4)](#setup-tmkms) - Copy the example variables file: @@ -253,16 +253,16 @@ ### Start node -- Run the following steps in the machine where the mainnet node is setup (machine 2) +- Run the following steps in the machine where [the mainnet node is setup (machine 2)](#setup-node) - Remove the validator key from node deployment as it is no longer required: + NOTE: Store it safely offline in case of an emergency + ```bash rm -rf $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json ``` - NOTE: Store it safely offline in case of an emergency - - Copy the genesis file to the mainnet deployment tmp directory: ```bash diff --git a/docs/run-validator.md b/docs/run-validator.md index 01f319b..de428e5 100644 --- a/docs/run-validator.md +++ b/docs/run-validator.md @@ -79,7 +79,6 @@ cerc_peers: "@:26656,@:26656" # Enable TMKMS - # Setting this to true will configure the node to use TMKMS for signing blocks tmkms_enabled: true ``` @@ -99,14 +98,6 @@ ansible-playbook -i localhost, -c local ~/cerc/laconicd-stack/playbooks/validator/setup-validator.yml ``` -- Get the public key of your node: - - ```bash - laconic-so deployment --dir $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR exec laconicd "laconicd tendermint show-validator" - ``` - - NOTE: This public key is required in next step to create validator - - Copy over the `priv_validator_key.json` located at `$DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json` to the machine from where the TMKMS service is to be setup (machine 4) ## Setup TMKMS @@ -130,7 +121,7 @@ ### Start TMKMS -- Run the following steps in the machine where the TMKMS service is setup (Machine 4) +- Run the following steps in the machine where [the TMKMS service is setup (Machine 4)](#setup-tmkms) - Copy the example variables file: @@ -180,7 +171,7 @@ ### Start Node -- Run the following steps in the machine where the validator node is setup (machine 2) +- Run the following steps in the machine where [the validator node is setup (machine 2)](#setup-node) - Start the laconicd node: @@ -206,8 +197,6 @@ - Run these steps in a machine from where [the create-validator transaction is to be signed (machine 3)](#build-laconicd-to-create-validator) - This command clones the entire repository into the `~/cerc` folder, which includes the genesis file published by the first validator. - - Copy the example variables file: ```bash @@ -233,7 +222,6 @@ ```bash export DATA_DIRECTORY= - export MAINNET_DEPLOYMENT_DIR=mainnet-validator-deployment ``` - Run ansible playbook to create validator on running chain: @@ -254,12 +242,12 @@ - Remove the validator key from node deployment as TMKMS is configured: - ```bash - rm $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json - ``` - NOTE: Store it safely offline in case of an emergency + ```bash + rm -rf $DATA_DIRECTORY/$MAINNET_DEPLOYMENT_DIR/data/laconicd-data/config/priv_validator_key.json + ``` + ## Update config - Run following steps to update the config for TMKMS and node @@ -271,7 +259,7 @@ - Stop the TMKMS deployment: ```bash - laconic-so deployment --dir $DATA_DIRECTORY/$TMKMS_DEPLOYMENT_DIR stop + laconic-so deployment --dir $DATA_DIRECTORY/tmkms-deployment stop ``` - Update `~/cerc/laconicd-stack/playbooks/tmkms/tmkms-vars.yml` with required values @@ -302,6 +290,8 @@ ## Register Your Node +- Run the following steps in the machine where the mainnet node is setup (machine 2) + - Get your node's address: ```bash diff --git a/playbooks/first-validator/first-validator-vars.example.yml b/playbooks/first-validator/first-validator-vars.example.yml index 57b86d6..6ea4197 100644 --- a/playbooks/first-validator/first-validator-vars.example.yml +++ b/playbooks/first-validator/first-validator-vars.example.yml @@ -1,9 +1,18 @@ + +# The public key of the validator node. This is required for generating the genesis file +# It should be wrapped in single quotes +validator_pub_key: '' + # Custom moniker for the validator node cerc_moniker: "LaconicMainnetNode" # The chain ID for the blockchain network cerc_chain_id: "laconic-mainnet" +# Set to true to enable TMKMS (Tendermint Key Management System) for this node +# If true, the node will use an external TMKMS for signing validator operations +tmkms_enabled: false + # Minimum gas price for transactions, in ALNT (e.g., 0.001alnt) min_gas_price: 0.001 @@ -12,11 +21,3 @@ cerc_loglevel: "info" # Desired key name for the validator account key_name: "laconic-validator" - -# Set to true to enable TMKMS (Tendermint Key Management System) for this node -# If true, the node will use an external TMKMS for signing validator operations -tmkms_enabled: false - -# The public key of the validator node. This is required for generating the genesis file -# It should be wrapped in single quotes -validator_pub_key: '' diff --git a/playbooks/validator/validator-vars.example.yml b/playbooks/validator/validator-vars.example.yml index e8819f7..bd857af 100644 --- a/playbooks/validator/validator-vars.example.yml +++ b/playbooks/validator/validator-vars.example.yml @@ -12,6 +12,10 @@ cerc_moniker: "" # You can find available peers in https://git.vdb.to/cerc-io/laconicd-stack/src/branch/main/node-addresses.yml cerc_peers: "" +# Set to true to enable TMKMS (Tendermint Key Management System) for this node +# If true, the node will use an external TMKMS for signing validator operations +tmkms_enabled: false + # The chain ID for the blockchain network cerc_chain_id: "laconic-mainnet" @@ -29,7 +33,3 @@ staking_amount_file: "~/cerc/laconicd-stack/config/staking-amount.json" # Desired key name for the validator account key_name: "laconic-validator" - -# Set to true to enable TMKMS (Tendermint Key Management System) for this node -# If true, the node will use an external TMKMS for signing validator operations -tmkms_enabled: false -- 2.54.0 From ec344f2afb1d8e4cfff451c9789af1907a791ec6 Mon Sep 17 00:00:00 2001 From: Shreerang Kale Date: Thu, 12 Jun 2025 16:43:24 +0530 Subject: [PATCH 14/14] Update default vars values --- .../cosmos-multisig-app/cosmos-multisig-vars.example.yml | 6 +++--- playbooks/first-validator/first-validator-vars.example.yml | 2 +- playbooks/validator/validator-vars.example.yml | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml b/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml index 135a162..0abc814 100644 --- a/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml +++ b/playbooks/cosmos-multisig-app/cosmos-multisig-vars.example.yml @@ -2,7 +2,7 @@ next_public_multichain: false # The name of the blockchain registry -next_public_registry_name: "laconic" +next_public_registry_name: "laconic-mainnet" # URL or path to the blockchain's logo next_public_logo: "" @@ -25,8 +25,8 @@ next_public_denom: "alnt" # The display denomination of the native token next_public_display_denom: "ALNT" -# The exponent for the display denomination (e.g., 18 for 10^18). -next_public_display_denom_exponent: 18 +# The exponent for the display denomination +next_public_display_denom_exponent: 0 # JSON array of asset definitions, including denom units, base, name, display, and symbol next_public_assets: '[{"denom_units":[{"denom":"alnt","exponent":0}],"base":"alnt","name":"Laconic Token","display":"ALNT","symbol":"alnt"}]' diff --git a/playbooks/first-validator/first-validator-vars.example.yml b/playbooks/first-validator/first-validator-vars.example.yml index 6ea4197..933aa8c 100644 --- a/playbooks/first-validator/first-validator-vars.example.yml +++ b/playbooks/first-validator/first-validator-vars.example.yml @@ -11,7 +11,7 @@ cerc_chain_id: "laconic-mainnet" # Set to true to enable TMKMS (Tendermint Key Management System) for this node # If true, the node will use an external TMKMS for signing validator operations -tmkms_enabled: false +tmkms_enabled: # Minimum gas price for transactions, in ALNT (e.g., 0.001alnt) min_gas_price: 0.001 diff --git a/playbooks/validator/validator-vars.example.yml b/playbooks/validator/validator-vars.example.yml index bd857af..a71f858 100644 --- a/playbooks/validator/validator-vars.example.yml +++ b/playbooks/validator/validator-vars.example.yml @@ -14,7 +14,7 @@ cerc_peers: "" # Set to true to enable TMKMS (Tendermint Key Management System) for this node # If true, the node will use an external TMKMS for signing validator operations -tmkms_enabled: false +tmkms_enabled: # The chain ID for the blockchain network cerc_chain_id: "laconic-mainnet" -- 2.54.0