Run a Stake Pool Part V — Tips Guided mode

Part V — Tips

Small things that come up.

  1. Start hereThe picture, the dangers, how BRIAN runs it4 steps
  2. IInstallMachines, a hardened Ubuntu, the node5 steps
  3. IIConfigureChain, topology, offline machine, service5 steps
  4. IIIRegisterKeys, stake address, the pool5 steps
  5. IVRunKES, rewards, votes, upgrades8 steps
  6. VTipsPayments, files, swap, checklist4 steps

V-1 Send ADA

A plain payment, here 10 ₳.

Block producer or relay
cardano-cli latest transaction build \
  --tx-in $(cardano-cli latest query utxo --address $(cat payment.addr) --output-json | jq -r 'keys[0]') \
  --tx-out "<receiver-address>+10000000" \
  --change-address $(cat payment.addr) \
  --out-file tx.raw

Sign with payment.skey, submit. Check the receiver address on the air-gapped machine before signing: cardano-cli debug transaction view --tx-file tx.raw.

Next: Move files →

V-2 Move files

scp to the nodes, a USB stick to the air-gapped machine.

Your own computer
scp -P 2222 cardano-op@<node-ip>:~/tx.raw .
scp -P 2222 tx.signed cardano-op@<node-ip>:~/

Caution Never copy a signing key over the network. Wipe the stick after moving key files.

Next: Add swap →

V-3 Add swap

Protects a node with little RAM from memory peaks.

All nodes
sudo fallocate -l 8G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
free -h
Next: Checklist →

V-4 Checklist

The habits that keep a pool safe.

  • Cold keys only offline, two tested encrypted backups
  • Block producer reachable only from your relays
  • SSH with keys only, fail2ban on
  • Every download checked against its SHA-256
  • KES renewed before day 90 — reminder set
  • Pledge never below what you declared
  • Releases installed, relays first
  • Votes cast, reward account delegated
  • Every change tried on the testnet first
Sources and license

Text, pictures and order are BRIAN's. Commands for system setup, the firewall, Mithril and the service file are adapted from the Cardano Developer Portal; every cardano-cli command was written for and run against cardano-cli 11.2.3. The node's own documentation always takes precedence.

Developer Portal license (MIT) — Copyright (c) 2021 Cardano Foundation

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.