igneum/infra/seed-nodes/node/install-rpc.sh
igneum-labs 72351e8270 Testnet seeds: NET=testnet profile for the seed scripts, seeds-testnet.tsv (3 Hetzner VMs), dns.sh (deSEC), the public RPC allowlist and nginx site, build-job.mjs forwards --node-tests
seed1.testnet nbg1 195.201.35.33, seed2.testnet ash 5.161.232.205, seed3.testnet sin 5.223.52.210 (5 October 2026). Ports 26810/26811/28810/26890
from seed.env; provision-seed.sh BUILD_WHERE=cross takes the PC build job's Linux igneumd from infra/cross/out.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 15:46:22 +00:00

26 lines
1.7 KiB
Bash
Executable file

#!/usr/bin/env bash
# Runs ON the seed as root: install-rpc.sh <rpc host, e.g. rpc.testnet.igneum.network> <contact email>
# Expects /opt/igneum/bin/rpc-filter.py, /root/igneum-rpc-filter.service, /root/nginx-rpc.conf and /etc/igneum/seed.env
# (EVM_RPC_PORT). Installs the filter unit, the nginx site, then certbot --nginx for the TLS certificate (port 80 and
# 443 must be open: the Mac side adds the igneum-testnet-rpc firewall first). Idempotent.
set -euo pipefail
host="$1"; email="${2:-}"
export DEBIAN_FRONTEND=noninteractive
command -v nginx >/dev/null 2>&1 || { apt-get update -qq; apt-get install -y -qq nginx certbot python3-certbot-nginx >/dev/null; }
chmod +x /opt/igneum/bin/rpc-filter.py
python3 /opt/igneum/bin/rpc-filter.py --test
cp /root/igneum-rpc-filter.service /etc/systemd/system/igneum-rpc-filter.service
systemctl daemon-reload
systemctl enable igneum-rpc-filter >/dev/null 2>&1
systemctl restart igneum-rpc-filter
sed "s/RPC_HOST/$host/" /root/nginx-rpc.conf > /etc/nginx/sites-available/igneum-rpc
ln -sf /etc/nginx/sites-available/igneum-rpc /etc/nginx/sites-enabled/igneum-rpc
rm -f /etc/nginx/sites-enabled/default
nginx -t
systemctl enable nginx >/dev/null 2>&1; systemctl restart nginx
if [ ! -d "/etc/letsencrypt/live/$host" ]; then
certbot --nginx -n --agree-tos --no-eff-email ${email:+-m "$email"} ${email:---register-unsafely-without-email} -d "$host" --redirect
fi
systemctl is-active igneum-rpc-filter nginx
curl -s -m 10 -X POST -H 'Content-Type: application/json' --data '{"jsonrpc":"2.0","id":1,"method":"eth_chainId","params":[]}' http://127.0.0.1:8545; echo
curl -s -m 10 -X POST -H 'Content-Type: application/json' --data '{"jsonrpc":"2.0","id":1,"method":"admin_peers","params":[]}' http://127.0.0.1:8545; echo