Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - inv4fee2020/xf_node: Xinfin XDC node installation with nginx & lets encrypt · GitHub
Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - inv4fee2020/xf_node: Xinfin XDC node installation with nginx & lets encrypt · GitHub
Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - inv4fee2020/xf_node: Xinfin XDC node installation with nginx & lets encrypt · GitHub
Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - inv4fee2020/xf_node: Xinfin XDC node installation with nginx & lets encrypt · GitHub
Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - inv4fee2020/xf_node: Xinfin XDC node installation with nginx & lets encrypt · GitHub
Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - inv4fee2020/xf_node: Xinfin XDC node installation with nginx & lets encrypt · GitHub
Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - inv4fee2020/xf_node: Xinfin XDC node installation with nginx & lets encrypt · GitHub
Skip to content

Latest commit

History

134 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

XinFinOrg XDC RPC Node

Xinfin XDC custom Docker node installation with nginx & lets encrypt TLS certificate.


This script will take the standard XDC Docker node install and supplement it with the necessary configuration to provide a TLS secured RPC/WSS endpoint using Nginx.

Note: If you have an existing node deployed using the standard Docker installation method from XinFinOrg then you must run the script under the same account which you originally installed your node.

Table of Contents




Current functionality

  • Install options for Mainnet & Testnet
  • Supports the use of custom variables using the xf_node.vars file
  • Detects if existing Docker installation & modifies to support Nginx.
  • Detects UFW firewall & applies necessary firewall updates.
  • Installs & configures Nginx
    • Currently only supports multi-domain deployment with one A record & two CNAME records (requires operator has control over the domain)
    • Automatically detects the ssh session source IP & adds to the config as a permitted source
  • Applies NIST security best practices

Planned functionality

  • Add '0x' prefix support
  • Add cron job for lets-encrypt auto renewal
  • Add support for docker upgrades e.g. stashing customisations & re-applying
  • Add support for single domain with sub-folder for RPC & WSS
  • Add support for multiple nginx permitted IPv4 source addresses via the xf_node.vars file
  • Add IPv6 support for source address permit lists
  • Improve error detection & handling within the script
  • Add backup features to save out customisations
  • Add backup of Staked Apothem node e.g. wallet keystore etc.

How to download & use

To download the script(s) to your local node & install, read over the following sections and when ready simply copy and paste the code snippets to your terminal window.

Clone the repo

 cd ~/
git clone https://github.com/inv4fee2020/xf_node.git
cd xf_node
chmod +x *.sh

Vars file (xf_node.vars)

The vars file allows you to manually update the following variables which help to avoid interactive prompts during the install;

  • USER_DOMAINS - note the order in which the A & CNAME records must be entered.
  • CERT_EMAIL - email address for certificate renewals etc.

The file also controls some of the packages that are installed on the node. More features will be added over time.

Simply clone down the repo and update the file using your preferred editor such as nano;

 nano ~/xf_node/xf_node.vars

Script Usage

The following example will install a testnet node

 ./setup.sh testnet
 Usage: ./setup.sh {function}
example: ./setup.sh testnet
where {function} is one of the following;
mainnet == deploys the full Mainnet node with Nginx & Let's Encrypt TLS certificate
testnet == deploys the full Apothem node with Nginx & Let's Encrypt TLS certificate
logrotate == implements the logrotate config for chain log file(s)"

Nginx related

It is assumed that the node is being deployed to a dedicated host with no other nginx configuration. The node specfic config is contained in the NGX_CONF_NEW variable which is a file named xinfin.

As part of the installation, the script adds the ssh session source IPv4 address as a permitted source for accessing reverse proxied services. Operators should update this as necessary with additional source IPv4 addresses as required.

Permitted Access - scripted

tbc

Permitted Access - manual

In order to add/remove source IPv4 addresses from the permit list within the nginx config, you simple access the file with your preferred editor e.g. vim or nano etc. Each of the server blocks must be updated to reflect your desired access control policy.

Open the file with the 'nano' editor; sudo nano /etc/nginx/sites-available/xinfin

Move the cursor to the server blocks, similar to the following;

 location / {
try_files / =404;
allow 198.51.100.102; # Allow the source IP of the SSH session
allow 198.51.100.171; # Mgmt VPS station
deny all;
proxy_pass http://172.19.0.2:8556;

ADD : Simply add a new line after the last allow (& above the deny all) being sure to enter a valid IPv4 address and end with a semi-colon ';'

REMOVE : Simple delete the entire line.

Save the file and exit the editor.

For the changes to take effect, you will need to restart the nginx service as follows;

 sudo systemctl restart nginx

Testing your RPC/WSS endpoint

The following are examples of tests that have been used successfully to validate correct operation;

RPC

Copy the following command and update with the your RPC domain that you entered at run time or in the vars file.

 curl -H "Content-Type: application/json" --data "{\"jsonrpc\":\"2.0\",\"method\":\"net_version\",\"params\":[],\"id\":67}" https://rpc.mydomain.com/

This should return an output similar to the following;

{"jsonrpc":"2.0","id":67,"result":"51"}

The 'net_version' result is the chain id for the node e.g. mainnet or testnet, depending on your chosen option.

WSS

Copy the following command and update with the your WSS domain that you entered at run time or in the vars file.

 wscat -c wss://wss.mydomain.com

This should open another session within your terminal, similar to the below;

Connected (press CTRL+C to quit)
>

..where you can then enter the following test string;

 {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}

This should then return a value similar to the following;

Connected (press CTRL+C to quit)
> {"jsonrpc": "2.0", "id": 0, "method": "eth_gasPrice"}
< {"jsonrpc":"2.0","id":0,"result":"0x2e90edd00"}
>

Manual updates

To apply repo updates to your local clone, be sure to stash any modifications you may have made to the xf_node.vars file & take a manual backup also.

 cd ~/xf_node
git stash
cp xf_node.vars ~/xf_node_$(date +'%Y%m%d%H%M%S').vars
git pull
git stash apply

Contributers:

A special thanks & shout out to the following community members for their input & testing;


Feedback

Please provide feedback on any issues encountered or indeed functionality by utilising the relevant Github issues & xdc.dev comments section and I will endeavour to update/integrate where possible.

About

Xinfin XDC node installation with nginx & lets encrypt

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages