# Igneum public testnet: the go checklist Prepared 5 October 2026 by the infrastructure and consensus engineer for the 19:00 BST (18:00 UTC) opening. State of every line as of 16:05 UTC. Nothing mines until the owner says go; the seeds hold the chain at height 0. ## What runs now | Piece | Where | State at 16:05 UTC | |---|---|---| | `igneum-testnet-1` seed 1 | `seed1.testnet.igneum.network` = 195.201.35.33, Hetzner cx23, Nuremberg (nbg1), Debian 13 | up, unit `igneumd` active, p2p 26811 open, 2 peers, height 0, sink = genesis | | seed 2 | `seed2.testnet.igneum.network` = 5.161.232.205, Hetzner cpx21, Ashburn (ash), Debian 13 | up, 2 peers, height 0 | | seed 3 | `seed3.testnet.igneum.network` = 5.223.52.210, Hetzner cpx22, Singapore (sin), Debian 13 | up, 2 peers, height 0 | | Public JSON-RPC | `https://rpc.testnet.igneum.network` (seed 1: nginx, Let's Encrypt, 20 req/s per address with a burst of 40, 20 connections per address, bodies to 256 KiB, then `rpc-filter.py` on 127.0.0.1:8545, then the node's EVM RPC on 127.0.0.1:26890) | live: `eth_chainId` = 0x116e (4462), `eth_blockNumber` = 0x0, `net_version` = 4462; `admin_peers` and `igneum_submitProofRecord` refused with -32601 | | DNS | deSEC (`ns1.desec.io`, `ns2.desec.org`), A records for the three seeds and `rpc.testnet`, TTL 3600 | all four resolve from the authoritative servers | | Firewalls | `igneum-testnet-seed` (22, 26811, icmp) on all three; `igneum-testnet-rpc` (80, 443) on seed 1 only | applied | | The node binary | `igneumd 1c19441d` (fork branch `testnet-infra`), built on PC 1 by build job `build-20261005-154330` (WSL2 Ubuntu 24.04, glibc 2.39), sha256 `a9ea25f8ada29e3ee1dfc2ccced4e088a56237511be75d5d80f7bb7a72414b10` | on every seed as `/opt/igneum/bin/igneumd` | | Mining | none | nothing mines; no `--enable-unsynced-mining`, no miner process anywhere on the testnet | Each seed's start-up log, identical on the three: ``` Fees on igneum-testnet-1: pgas table v1, B_p 120000 pgas, S_p 30000 pgas, floors 100000000000 wei per gas and 10000000000000 wei per pgas; calibrated v1 from DAA score 0 Consensus params digest: b7d8c915f20f5af261e69e7f4aa9c3d03a9c4a462174776502b63fa1e9ec8447 (exchanged in the p2p handshake; a peer with another digest is refused) igneumd/2.1.0 [igneum-exec] genesis 87617621714af1bf33bd17f291f90a7e0bff760a669bba53083ea8c0f7cbd840 executed: chain id 4462, registry at 0x0000000000000000000000000000000000000210 ``` `health.sh` shows `synced=False` on all three: that is the no-blocks state (a node is synced once it has blocks past genesis), not a fault. The check: `cd infra/seed-nodes && NET=testnet ./health.sh`. ## The genesis, final | Field | Value | |---|---| | Network | `igneum-testnet-1`, chain id 4462, address prefix `igneumtest`, ports 26810 (gRPC), 26811 (p2p), 28810 (wRPC JSON), 26890 (EVM JSON-RPC) | | Coinbase message | `igneum-testnet-1 \| 2026-10-05 \| coins here have no value \| resets are announced` ("proposed, not final" dropped before the first public node) | | Timestamp | 1,791,158,400,000 ms = 2026-10-05T00:00:00Z | | Bits | `0x1d100000` | | Hash | `87617621714af1bf33bd17f291f90a7e0bff760a669bba53083ea8c0f7cbd840` | | Merkle root | `44acfc40b1c6647011510f3c39ddb7606f979df92ad26a2914de56e44610efad` | | Consensus digest | `b7d8c915f20f5af261e69e7f4aa9c3d03a9c4a462174776502b63fa1e9ec8447` | | Fees | `CALIBRATED_V1` from DAA 0 | | DNS seeders in `TESTNET_PARAMS` | `seed1.testnet.igneum.network`, `seed2.testnet.igneum.network`, `seed3.testnet.igneum.network` | | `--netsuffix` | defaults to 1 under `--testnet` | The proposal's hash `52a3e6a9...` is void: it hashed the old message. Any node built from a fork commit before 1c19441d has the old genesis and never completes a handshake with the seeds (different genesis, different digest). ## Branches and commits (nothing pushed, nothing merged) | Repository | Branch | Head | What | |---|---|---|---| | node fork (`vendor/igneum-node-testnet-infra`, from `release-0.3.6` 2b6d23ef) | `testnet-infra` | 1c19441d | final genesis message, hash and merkle root; `--netsuffix` default 1; the three DNS seeders; `igneum_testnet_identity` and `test_genesis_hashes` updated | | app repository (`igneum-wt-testnet-infra`, from master 23d11d5) | `testnet-infra` | 358e565 | `infra/seed-nodes`: `NET=testnet` profile, `seeds-testnet.tsv`, `dns.sh`, `rpc/` (filter, unit, nginx site), `node/install-rpc.sh`, `install-rpc-from-mac.sh`, ports from `seed.env`, glibc check, debian-13 images, quoted env values; `tools/build-job.mjs` forwards `--node-tests`/`--app-tests` and its watcher reads the SUMMARY wherever it sits; `docs/testnet/README.md` final genesis; this file | | app repository (`igneum-wt-testnet-app`, from `testnet-infra` 9fa2bb3) | `testnet-app` | c00df85 | the app's network setting: `Packaged.network/peers/public_rpc`, `Network` enum with the testnet's ports, seeds and node directory, `Runtime::from_env_and_packaged`, the dashboard's chain label `testnet-1` with the public RPC on its tooltip, the testnet node keeps its DNS seeders; `packaged-config.sh` `IGNEUM_PACKAGE_NETWORK` (default testnet; the fleet's devnet builds pass `devnet`) | | app repository (`igneum-wt-testnet-wallet`, from `wallet-v1` a238781) | `testnet-wallet` | fe6e5e8 | `igneum-common`: `Packaged.network`, `TESTNET_PUBLIC_RPC`, `chain_id`, `effective_public_rpc`; the wallet engine reads the effective URL; the wallet's packaged config follows `IGNEUM_PACKAGE_NETWORK` | Tests: `kaspa-consensus-core` and `igneum-app` suites on PC 2, build job `build-20261005-155547`, both exit 0 (cargo's own status; the relayed log keeps only the last `test result` line). `cargo test -p igneum-common` on the Mac: 27 passed (the crate is not in the PC build inputs). The packager's self-test: all checks passed on both branches. `cargo check --tests` of the app on the Mac: clean. ## The go: what the project lead presses, in order | # | Step | Who presses | State at 16:05 UTC | |---|---|---|---| | 1 | Seeds up at height 0, peered, the public RPC answering | nobody (done) | DONE: three seeds, 2 peers each, RPC live | | 2 | Merge `testnet-infra` and `testnet-app` to master; the fork's `testnet-infra` into `release-0.3.6` (or the release branch the 0.4.0 cut uses) | the release engineer, on the project lead's word | NOT DONE: branches ready, nothing merged | | 3 | Cut 0.4.0 from `testnet-app` (`tools/ship-app.mjs 0.4.0 --node vendor/igneum-node-testnet-infra ...`); the Mac DMG, the Windows installer through the PC build job; the packaged file must say `"network": "testnet"` (the default) | the release engineer | NOT DONE: the packager writes the testnet by default; the fleet's devnet update, if any, needs `IGNEUM_PACKAGE_NETWORK=devnet` | | 4 | The prover's fee-table mirror at `CALIBRATED_V1` (`proving/igneum-prove/core/src/config.rs`, `pgas.rs`; `docs/plans/release-0.3.6.md` section 5 step 6): on the testnet fees are v1 from genesis, so a prover with the prototype table produces shard statements the node refuses. Needed before the first testnet proof, not before the first block | the execution engineer | NOT DONE | | 5 | History rewrite (`docs/plans/history-rewrite.md`, G14: the 40 commits with a personal name) | the project lead, then the repository goes public | NOT DONE | | 6 | Repository public (`gh repo edit igneum-network/igneum --visibility public`) | the project lead | NOT DONE | | 7 | Downloads public: the 0.4.0 manifest in the downloads folder, `publish-manifest.sh --deploy` | the release engineer | NOT DONE | | 8 | The site's buttons: the download section points at 0.4.0, `site/wallet.html` carries `https://rpc.testnet.igneum.network` and chain id 4462 in place of the placeholder, the terms card (`#testnet-terms`) stays; `node site/build.mjs`, push to master (Vercel deploys) | the site agent | NOT DONE: the placeholder is still in `site/wallet.html` | | 9 | Announcement text | the project lead | PLACEHOLDER: "Igneum testnet-1 is open. Coins here have no value. Resets are announced seven days ahead. Download: igneum.network. RPC: rpc.testnet.igneum.network, chain id 4462." (the project lead's words replace this) | | 10 | The first miner: one app on the testnet (PC 1 or PC 2 with the 0.4.0 build, or `igneumd --testnet` plus `igneum-miner --network testnet` by hand) produces block 1; the seeds relay it, `health.sh` shows blocks=1 on all three, `synced=True` | the project lead says go, the miner-community lead starts it | NOT DONE: nothing mines until the word | | 11 | Watch: `NET=testnet ./health.sh --watch`, the RPC's `eth_blockNumber`, the DAA after 600 blocks (the launch difficulty `0x1d100000` is sized for a few hundred MH/s) | the infrastructure engineer | ready | Legal is out of scope here (the project lead: "all but legal"). ## Cost | Item | USD per month, net (Hetzner API, 5 October 2026) | |---|---| | seed 1, cx23 nbg1 | 6.49 | | seed 2, cpx21 ash (4 GB; the only 4 GB type in the US at this price) | 37.49 | | seed 3, cpx22 sin | 30.99 | | three primary IPv4 | 1.80 | | total | 76.77 net, about 92 gross; billed hourly, 20 TB traffic included per server | A cheaper US seed is cpx11 (2 GB, 20.49), rejected because the node keeps up to four 256 MiB lottery caches once the chain has epochs; the unit's `MemoryMax=3200M` would not fit. The devnet seed (`igneum-seed-1`, 6.49) is untouched. ## What was not done, and what to watch | Item | Note | |---|---| | The explorer | not built; the public RPC serves the wallet and MetaMask | | `site/wallet.html` RPC placeholder | still a placeholder; step 8 | | The Windows WSL verifier wrapper, the prover's table mirror | `docs/plans/release-0.3.6.md` section 7; step 4 above | | The app's Windows side | `testnet-app` compiles on the Mac and its suite passed on PC 2 (Linux); the Windows build is the 0.4.0 cut's job | | Seeds and proofs | the seeds run no proof verifier (`verifier: Off`); they relay and hold the chain. A seed never includes proof records, which is fine for a seed | | Build inputs zip | `build-inputs.zip` on the downloads host is ONE file for every agent: a second agent's push between a job's publish and its fetch fails that job's sha256 check. Both testnet jobs fetched the right zip (verified by sha256 before each fetch); the hazard stays until the zip carries the job id in its name | | glibc | a PC-built Linux binary wants glibc 2.39 (Ubuntu 24.04); the seeds are Debian 13 (2.41) for that reason, and `provision-seed.sh` now refuses a binary the seed cannot run. The Mac's zig cross-build (glibc 2.36) stays the route for a Debian 12 host | ## How to redo any part ``` cd infra/seed-nodes NET=testnet ./health.sh # one line per seed NET=testnet ./dns.sh --check # the four A records NET=testnet BUILD_WHERE=cross ./provision-seed.sh seed2.testnet # re-install the node from infra/cross/out (a new binary) NET=testnet ./install-rpc-from-mac.sh seed1.testnet # the public RPC again (idempotent; certbot keeps its certificate) ``` The node binary for the seeds: `node tools/build-job.mjs run --node /Users/joshm/Projects/igneum/vendor/igneum-node-testnet-infra --target ae432dc7 --targets linux --no-tests` then `node tools/build-job.mjs fetch ` (lands in `infra/cross/out/`).