igneum/infra/seed-nodes/install-rpc-from-mac.sh
igneum-labs 72351e8270 Testnet seeds: NET=testnet profile for the seed scripts, seeds-testnet.tsv (3 Hetzner VMs), dns.sh (deSEC), the public RPC allowlist and nginx site, build-job.mjs forwards --node-tests
seed1.testnet nbg1 195.201.35.33, seed2.testnet ash 5.161.232.205, seed3.testnet sin 5.223.52.210 (5 October 2026). Ports 26810/26811/28810/26890
from seed.env; provision-seed.sh BUILD_WHERE=cross takes the PC build job's Linux igneumd from infra/cross/out.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:46:22 +00:00

22 lines
1.5 KiB
Bash
Executable file

#!/usr/bin/env bash
# The public RPC on one seed (the one rpc.<net>.igneum.network points at): NET=testnet ./install-rpc-from-mac.sh seed1.testnet [email]
# Adds the igneum-<net>-rpc firewall (80, 443 from anywhere) to that server, uploads rpc/ and node/install-rpc.sh, runs it.
. "$(dirname "$0")/lib.sh"
name="${1:-}"; email="${2:-}"; [ -n "$name" ] || die "which seed?"
ip=$(seed_ip "$name"); [ -n "$ip" ] || die "$name not in $SEEDS_TSV"
host="rpc${DNS_ZONE_SUB:+.$DNS_ZONE_SUB}.igneum.network"
hetzner_auth
fw="igneum-$NET-rpc"
if ! hcloud firewall describe "$fw" >/dev/null 2>&1; then
hcloud firewall create --name "$fw" --label igneum=rpc --label net="$NET" >/dev/null
hcloud firewall add-rule "$fw" --direction in --protocol tcp --port 80 --source-ips 0.0.0.0/0 --source-ips ::/0 --description http-acme >/dev/null
hcloud firewall add-rule "$fw" --direction in --protocol tcp --port 443 --source-ips 0.0.0.0/0 --source-ips ::/0 --description https-rpc >/dev/null
log "created firewall $fw (80, 443)"
fi
hcloud firewall apply-to-resource "$fw" --type server --server "$name" >/dev/null 2>&1 || true
log "firewall $fw on $name"
sscp "$HERE/rpc/rpc-filter.py" "$SSH_USER@$ip:/opt/igneum/bin/"
sscp "$HERE/rpc/igneum-rpc-filter.service" "$HERE/rpc/nginx-rpc.conf" "$HERE/node/install-rpc.sh" "$SSH_USER@$ip:/root/"
sssh "$ip" "bash /root/install-rpc.sh '$host' '$email'"
log "public RPC: https://$host (chain id check):"
curl -s -m 15 -X POST -H 'Content-Type: application/json' --data '{"jsonrpc":"2.0","id":1,"method":"eth_chainId","params":[]}' "https://$host"; echo