Run a Stake Pool Part I — Install Guided mode

Part I — Install

Machines, a hardened Ubuntu, time sync, the node.

  1. Start hereThe picture, the dangers, how BRIAN runs it4 steps
  2. IInstallMachines, a hardened Ubuntu, the node5 steps
  3. IIConfigureChain, topology, offline machine, service5 steps
  4. IIIRegisterKeys, stake address, the pool5 steps
  5. IVRunKES, rewards, votes, upgrades8 steps
  6. VTipsPayments, files, swap, checklist4 steps

I-1 What you need

Three kinds of machine and at least 505 ADA.

  • 2+relays
  • 1block producer
  • 1air-gapped computer
  • 24 GBRAM with swap
  • 300 GBdisk
  • 505 ₳deposits + fees

Each node: Ubuntu LTS (64-bit), 2+ cores, a static IP, 10 Mbps. Plus your pledge in ADA. Deposits can change by governance vote — Part III reads them from the chain.

Next: Harden every server →

I-2 Harden every server

Own user, key-only SSH, updates, fail2ban.

All nodes
sudo useradd -m -s /bin/bash cardano-op
sudo passwd cardano-op
sudo usermod -aG sudo cardano-op
sudo passwd -l root
Your own computer
ssh-keygen -t ed25519 -C "stake-pool-ops"
ssh-copy-id -i ~/.ssh/id_ed25519.pub cardano-op@<server-ip>

In /etc/ssh/sshd_config:

File
Port 2222
PubkeyAuthentication yes
PasswordAuthentication no
PermitRootLogin no
PermitEmptyPasswords no
X11Forwarding no
KbdInteractiveAuthentication no
MaxAuthTries 3
LoginGraceTime 30
All nodes
sudo sshd -t && sudo systemctl reload ssh
sudo apt-get update -y && sudo apt-get upgrade -y && sudo apt-get autoremove -y
sudo apt-get install -y unattended-upgrades fail2ban jq
sudo dpkg-reconfigure -plow unattended-upgrades
sudo systemctl enable --now fail2ban

Important Keep your session open and log in from a second terminal on port 2222 before you close it.

Check ssh -p 2222 cardano-op@<server-ip> works with your key; a password login is refused.

Next: Firewall →

I-3 Firewall

Relays open to the world, the block producer only to your relays.

Relay
  • 6000 · Cardanoanyone
  • 2222 · SSHyour keys only
  • everything elsedropped
Block producer
  • 6000 · Cardanoyour relays only
  • 2222 · SSHyour IP only
  • everything elsedropped
Which ports open to whom.

Relay — /etc/nftables.conf:

File
#!/usr/sbin/nft -f

flush ruleset

table inet filter {
    chain input {
        type filter hook input priority 0; policy drop;

        ct state established,related accept
        iifname "lo" accept
        ip protocol icmp accept
        ip6 nexthdr icmpv6 accept

        tcp dport 2222 accept
        tcp dport 6000 accept
    }

    chain forward {
        type filter hook forward priority 0; policy drop;
    }

    chain output {
        type filter hook output priority 0; policy accept;
    }
}

Block producer — /etc/nftables.conf:

File
#!/usr/sbin/nft -f

flush ruleset

table inet filter {
    chain input {
        type filter hook input priority 0; policy drop;

        ct state established,related accept
        iifname "lo" accept
        ip protocol icmp accept
        ip6 nexthdr icmpv6 accept

        ip saddr <your-management-ip> tcp dport 2222 accept
        ip saddr { <relay-1-ip>, <relay-2-ip>, <relay-3-ip> } tcp dport 6000 accept
    }

    chain forward {
        type filter hook forward priority 0; policy drop;
    }

    chain output {
        type filter hook output priority 0; policy accept;
    }
}
All nodes
sudo apt-get install -y nftables
sudo systemctl enable nftables
sudo nft -f /etc/nftables.conf
sudo nft list ruleset

Check From another server, nc -zv <block-producer-ip> 6000 times out; from a relay it connects.

Next: Time sync →

I-4 Time sync

Blocks come in one-second slots; a drifting clock misses them.

All nodes
sudo apt-get install -y chrony
sudo systemctl enable --now chrony
chronyc tracking

Check System time is off by a few milliseconds at most.

Next: Install cardano-node — and check it →

I-5 Install cardano-node — and check it

Official release, verified by its SHA-256 before it runs.

All nodes
VERSION=11.1.3
cd ~
wget https://github.com/IntersectMBO/cardano-node/releases/download/${VERSION}/cardano-node-${VERSION}-linux-amd64.tar.gz
wget https://github.com/IntersectMBO/cardano-node/releases/download/${VERSION}/cardano-node-${VERSION}-sha256sums.txt
sha256sum --ignore-missing -c cardano-node-${VERSION}-sha256sums.txt
mkdir -p ~/.local
tar -xzf cardano-node-${VERSION}-linux-amd64.tar.gz -C ~/.local/
sudo install -m 755 ~/.local/bin/cardano-node ~/.local/bin/cardano-cli /usr/local/bin/
cardano-node --version
cardano-cli --version

Check sha256sum prints cardano-node-11.1.3-linux-amd64.tar.gz: OK. Anything else: stop and delete the file.

Newer release? Take it from IntersectMBO/cardano-node only. The archive also holds the network configuration files.

Sources and license

Text, pictures and order are BRIAN's. Commands for system setup, the firewall, Mithril and the service file are adapted from the Cardano Developer Portal; every cardano-cli command was written for and run against cardano-cli 11.2.3. The node's own documentation always takes precedence.

Developer Portal license (MIT) — Copyright (c) 2021 Cardano Foundation

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.