The first stage run built v4 on igneum-seed-1 in 60 min 49 s and then failed on `igneumd --version | head -1` under pipefail, because the devnet-v4 igneumd prints its version and exits 1. The post-build steps now write to files and test them; the tarball is unpacked once per src.stamp so a rerun is incremental; `stage-v4.sh <seed> resume` reruns the build script on the tree already on the VM and then waits and installs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| node | ||
| .gitignore | ||
| addpeer-from-mac.sh | ||
| config.sh | ||
| create-seed.sh | ||
| health.sh | ||
| lib.sh | ||
| provision-seed.sh | ||
| README.md | ||
| seeds.tsv | ||
| seeds.txt | ||
| stage-v4.sh | ||
| switch-v4.sh | ||
Igneum seed nodes
A seed is a small VM with a fixed public IPv4 that runs igneumd with p2p open, no mining, RPC on loopback, and
serves peer exchange (the address manager stays on; --connect is never used). seeds.txt lists one <ip>:26611
per seed and is the file the consensus engineer bakes into the network parameters and every package reads as
SEED_PEERS. The plan, the client path and the rotation procedure are in docs/plans/seed-nodes.md.
The first seed, igneum-seed-1, was created on 3 Oct 2026 (Hetzner cx23, Falkenstein, USD 6.49 per month net plus
the IPv4). It runs the shared devnet (--devnet, no suffix).
cd infra/seed-nodes
./create-seed.sh # one VM, persistent IPv4, firewall 22 + 26611 + icmp, appends seeds.tsv, rewrites seeds.txt
./provision-seed.sh igneum-seed-1 # source tarball -> build on the VM (about an hour on 2 vCPU) -> unit igneumd, started
./health.sh # one line per seed: p2p port, unit, RPC, synced, blocks, peers, known addresses
./addpeer-from-mac.sh relay start # a non-mining relay igneumd on the Mac peers with the live node (LAN) and the seed; the
# live node runs in safe RPC mode, so addPeer over grpcurl is refused (see the script)
SEED_NAME=igneum-seed-2 SEED_LOCATION=ash SEED_TYPE=cpx11 ./create-seed.sh # the next seed; provision adds the first as --addpeer
./stage-v4.sh igneum-seed-1 # devnet v4 (4 Oct 2026): source tarball of vendor/igneum-node-v4 -> detached, niced, memory-capped
# build on the VM into /root/v4 -> /opt/igneum/v4/bin, /var/lib/igneum-v4 (fresh), unit igneumd-v4
# installed DISABLED; the v3 unit keeps running. `wait` and `status` modes.
./switch-v4.sh igneum-seed-1 # the cut-over: stop+disable igneumd, enable+start igneumd-v4, print its sync state; --back reverses
Devnet v4 is a new chain from the same genesis (docs/fork-divergence.md, "Compatibility"), so the seed runs it from a
fresh data directory, /var/lib/igneum-v4, with its own launcher (node/run-seed-v4.sh, same flags, binary from
/opt/igneum/v4/bin), env file (/etc/igneum/seed-v4.env, a copy of seed.env) and unit (node/igneumd-v4.service,
Conflicts=igneumd.service: the two bind the same ports). The v3 database in /var/lib/igneum stays as it is for the
rollback. health.sh reports unit=active-v4 once the v4 unit serves. The runbook is docs/plans/cutover-2026-10-04.md.
Settings in config.sh: provider, name, type, location, image, ssh key (~/.ssh/igneum_ed25519), SSH_SOURCE
(any, me or a CIDR for port 22), NETWORK_ARGS (--devnet; a private network: --devnet --devnet-suffix=20),
SEED_PEERS, BUILD_WHERE (seed builds on the VM; bin reuses ../cloud-devnet/build/bin). The Hetzner token is
read from ~/.config/igneum/hetzner-token and never printed.
Node flags (node/run-seed.sh): --devnet --appdir=/var/lib/igneum --rpclisten=127.0.0.1:26610 --rpclisten-json=127.0.0.1:28610 --listen=0.0.0.0:26611 --externalip=<ip> --nodnsseed --disable-upnp --nologfiles --yes --maxinpeers=128 --outpeers=8 [--addpeer=<other seeds>]. No --enable-unsynced-mining (nothing mines here) and
no --connect (it would set the inbound limit to 0 and switch the address manager off).
Files: create-seed.sh, provision-seed.sh, health.sh, addpeer-from-mac.sh, stage-v4.sh, switch-v4.sh, config.sh,
lib.sh, node/{install-seed.sh,run-seed.sh,igneumd.service,build-v4-on-seed.sh,run-seed-v4.sh,igneumd-v4.service},
seeds.txt, seeds.tsv, build/ (logs and the v4 source tarball, git-ignored).