curl -fsSL https://docs.scrt.network/secret-setup.py -o secret-setup.py && curl -fsSL https://docs.scrt.network/restore.sh -o restore.sh && python3 secret-setup.pyRun it on Ubuntu 22.04 or 24.04, x86_64, as the account that will own ~/.secretd. Do not run it as root. If genesis.json already exists, the script skips the moniker and secretd init. It still asks for the key, the password, public RPC, public gRPC, and public LCD. It asks for prune only when app.toml has no pruning line. It rewrites p2p.seeds to the seven Home-page peers and leaves persistent_peers as they are. On a physical host, enable SGX in firmware first. On Azure, use a DCsv3 or DCdsv3 Gen2 image. The script installs the Intel DCAP packages, writes /etc/sgx_default_qcnl.conf for that host, enables and restarts aesmd, adds your user to sgx and sgx_prv, then runs init-enclave.
On a new home it asks, in this order:
- Moniker.
- Key name. Use letters, digits,
.,_, or-. - Keyring password. It is not echoed. Use at least 8 characters and at most 72 bytes. If that name is already in the file keyring, the script uses it. If it is not, the script creates it and prints the mnemonic. Write the mnemonic down.
- Public RPC? Answer
yesorno. - Public gRPC? Answer
yesorno. - Public LCD? Answer
yesorno. Yes does not bind0.0.0.0. - Prune setting:
default,nothing, oreverything.nothingkeeps archive state.archiveis accepted asnothing.
Then it does this:
- Install
curl,ca-certificates,jq,zstd,tar, andlibsnappy1v5. - Probe Azure metadata for one second with
--noproxy '*'. A DCsv3 or DCdsv3 answer and any other host both install the full Intel list, includinglibsgx-dcap-default-qpl. Do not installaz-dcap-client. Then download the v1.27.2MAINNETdeb for that Ubuntu release, check the release SHA-256, and install it withdpkg -i. Requiresecretd versionto print1.27.2. The deb does not shiplibsgx_dcap_ql.so.1,libsgx_dcap_quoteverify.so.1, orlibsgx_urts.so.2. - Set the client keyring backend to
fileand the client chain-id tosecret-4. - Run
secretd init <moniker> --chain-id secret-4when the home is new. On resume, skip this step. - Set
p2p.seedsinconfig.tomlto the seven public secret-4 peers on Create the node home. On a new home, leavepersistent_peersempty. On resume, leavepersistent_peersunchanged. For chain-idsecret-4,initwrites three peers,scrt-seed-01.scrtlabs.com,scrt-seed-02.scrtlabs.com, andscrt-seed-03.scrtlabs.com. This step replaces that line. - Write
/etc/sgx_default_qcnl.conffor the host from step 2, then enable and restartaesmd, then add your user tosgxandsgx_prv. A physical host gets Intel PCS v4. Azure 22.04 and Azure 24.04 get the DCAP 1.22 file: PCK from THIM, collateral from Intel PCS v4. - Run
secretd init-enclaveundersg sgx/sgx_prvso the new groups apply without logging out. - Sign
tx register authfor/opt/secret/.sgx_secrets/attestation_combined.bin($SCRT_SGX_STORAGEif you set it). Send it tohttps://rpc.secret.mainnet.secret3.devwith--fromyour key,--chain-id secret-4,--keyring-backend file,--gas 700000, and--gas-prices 0.1uscrt. The password goes on stdin. Do not use--gas auto. - Wait until that transaction is in a block. If the machine is not on the allowlist, the script stops. If the balance is under 70,000
uscrt(0.07 SCRT), the script prints the address and stops before it sends the transaction. - Run
secretd query register secret-network-params,secretd dumponpubkey.bin,secretd query register seed, andsecretd configure-secret. That writes~/.secretd/.node/new_seed.json. - Set
pruningto the value you chose. Setiavl-disable-fastnode = truein the root ofapp.toml. Leave RPC ontcp://127.0.0.1:26657, LCD ontcp://127.0.0.1:1317, and gRPC on127.0.0.1:9090. Answering yes does not bind0.0.0.0. If you answered yes, setenabled-unsafe-cors = falseand publish a proxy on RPC and LCD. Firewall26657,1317,9090,6060, and26660. - Run
restore.shfrom this site. It downloads the snapshot fromhttps://mainnet-secret-snapshot.secret3.dev. A rerun skipsrestore.shwhendata/application.dbordata/blockstore.dbexists and127.0.0.1:26657does not answer, and it does not print Snapshot restore finished.
If you will not run the script, follow Manual from SGX prerequisites through Sync.