diff --git a/compose_registry.json b/compose_registry.json index 87171a23..70eeddad 100644 --- a/compose_registry.json +++ b/compose_registry.json @@ -8463,6 +8463,36 @@ "starknet-sepolia-pathfinder-pruned" ] }, + { + "chain": "mainnet", + "client": "tacchaind", + "compose_file": "tac/tacchaind/tac-mainnet-tacchaind-pruned", + "features": [], + "network": "tac", + "node": "config", + "relay": null, + "stack": null, + "type": "pruned", + "volumes": [ + "tac-mainnet-tacchaind-pruned", + "tac-mainnet-tacchaind-pruned_config" + ] + }, + { + "chain": "spb", + "client": "tacchaind", + "compose_file": "tac/tacchaind/tac-spb-tacchaind-pruned", + "features": [], + "network": "tac", + "node": "config", + "relay": null, + "stack": null, + "type": "pruned", + "volumes": [ + "tac-spb-tacchaind-pruned", + "tac-spb-tacchaind-pruned_config" + ] + }, { "chain": "alethia", "client": "geth", diff --git a/tac/scripts/cometbft-common.sh b/tac/scripts/cometbft-common.sh new file mode 100644 index 00000000..e2710b3f --- /dev/null +++ b/tac/scripts/cometbft-common.sh @@ -0,0 +1,223 @@ +#!/bin/sh +# cometbft-common.sh — reusable CometBFT-node bootstrap helpers (family C). +# +# Source this from a chain-specific init.sh. It encapsulates the operations every +# CometBFT-consensus node needs (init, fetch config artifacts, patch config.toml / +# app.toml, seed priv_validator_state), extracted verbatim from the proven berachain +# beacon-kit entrypoint so callers inherit known-good behavior. +# +# Each function takes explicit arguments (paths/values) — it is binary-agnostic. The +# caller owns the binary name, the ` init` invocation, the artifact URLs, and +# the final `exec start ...`. EL-driven chains (beacon-kit, morph) also call +# the JWT / engine-dial helpers; pure-consensus chains (gaiad) skip them. +# +# Conventions: POSIX sh (alpine). Config dir is conventionally $HOME_DIR/config. +# Used by: morph-node, gaiad (cosmos batch), and any future family-C chain. +# beacon-kit (berachain) keeps its own bespoke init.sh on purpose — do not retrofit it. + +set -e + +ct_log() { echo "[cometbft-init] $*"; } + +# Ensure curl exists (alpine base images often omit it). Idempotent. +ct_require_curl() { + if ! command -v curl >/dev/null 2>&1; then + ct_log "installing curl" + apk add --no-cache curl + fi +} + +# ct_fetch URL DEST [required] +# Download URL -> DEST. If the 3rd arg is "required", a failure is fatal; +# otherwise a missing/failed fetch is logged and skipped (returns 0). +ct_fetch() { + _url="$1"; _dest="$2"; _req="${3:-optional}" + [ -n "$_url" ] || { [ "$_req" = required ] && { ct_log "FATAL: empty URL for $_dest"; exit 1; }; return 0; } + if curl -fsSL "$_url" -o "$_dest"; then + ct_log "fetched $_url -> $_dest" + else + if [ "$_req" = required ]; then + ct_log "FATAL: failed to fetch required $_url"; exit 1 + fi + ct_log "skip: could not fetch optional $_url" + fi +} + +# ct_patch_p2p CONFIG_TOML IP P2P_PORT +# Bind p2p to 0.0.0.0:PORT and advertise IP:PORT (only within the [p2p] section). +ct_patch_p2p() { + _cfg="$1"; _ip="$2"; _port="$3" + [ -f "$_cfg" ] || { ct_log "patch_p2p: $_cfg missing, skipping"; return 0; } + _laddr="tcp:\\/\\/0\\.0\\.0\\.0\\:${_port}" + sed -i "/^\[p2p\]/,/^\[/{s|^laddr = .*|laddr = \"$_laddr\"|}" "$_cfg" + sed -i "/^\[p2p\]/,/^\[/{s|^external_address = .*|external_address = \"${_ip}:${_port}\"|}" "$_cfg" +} + +# ct_merge_seeds CONFIG_TOML CONFIGURED_SEEDS [SEEDS_URL] +# Merge operator-configured seeds with an optional official seed list (1 entry per +# line, first line skipped like the berachain cl-seeds.txt header), dedupe, write. +ct_merge_seeds() { + _cfg="$1"; _seeds="$2"; _url="$3" + [ -f "$_cfg" ] || return 0 + if [ -n "$_url" ]; then + _official=$(curl -f -s "$_url" | tail -n +2 | tr '\n' ',' | sed 's/,$//' || true) + if [ -n "$_official" ]; then + ct_log "merging official seeds from $_url" + _seeds=$(echo "${_seeds},${_official}" | tr ',' '\n' | sed '/^$/d' | sort -u | paste -sd,) + else + ct_log "no official seeds fetched from $_url (continuing with configured)" + fi + fi + if [ -n "$_seeds" ]; then + sed -i "s/^seeds = \".*\"/seeds = \"${_seeds}\"/" "$_cfg" + fi +} + +# ct_set_persistent_peers CONFIG_TOML PEERS +# Handles both cometbft-classic `persistent_peers` (underscore) and forks that use +# `persistent-peers` (hyphen, e.g. sei) — patches whichever key is present. +ct_set_persistent_peers() { + _cfg="$1"; _peers="$2" + [ -f "$_cfg" ] || return 0 + [ -n "$_peers" ] || return 0 + sed -i "s/^persistent_peers = \".*\"/persistent_peers = \"${_peers}\"/" "$_cfg" + sed -i "s/^persistent-peers = \".*\"/persistent-peers = \"${_peers}\"/" "$_cfg" + return 0 +} + +# ct_set_moniker CONFIG_TOML MONIKER +ct_set_moniker() { + _cfg="$1"; _mon="$2" + [ -f "$_cfg" ] || return 0 + [ -n "$_mon" ] && sed -i "s/^moniker = \".*\"/moniker = \"$_mon\"/" "$_cfg" + return 0 +} + +# ct_set_addrbook CONFIG_DIR ADDRBOOK_URL +# Optional: cosmos chains often seed an addrbook.json for faster peer discovery. +ct_set_addrbook() { + _dir="$1"; _url="$2" + [ -n "$_url" ] || return 0 + ct_fetch "$_url" "$_dir/addrbook.json" optional +} + +# ct_write_jwt CONFIG_DIR [JWT_SRC] +# EL-driven chains: copy the shared engine JWT (default /jwtsecret) into the config +# dir as jwt.hex so the CL can authenticate to the EL engine API. +ct_write_jwt() { + _dir="$1"; _src="${2:-/jwtsecret}" + [ -f "$_src" ] || { ct_log "write_jwt: $_src missing, skipping"; return 0; } + cat "$_src" > "$_dir/jwt.hex" +} + +# ct_set_rpc_dial_url APP_TOML AUTH_RPC +# beacon-kit / app.toml-style EL engine endpoint (e.g. http://:8551). +ct_set_rpc_dial_url() { + _app="$1"; _rpc="$2" + [ -f "$_app" ] || return 0 + [ -n "$_rpc" ] && sed -i "s|^rpc-dial-url = \".*\"|rpc-dial-url = \"$_rpc\"|" "$_app" + return 0 +} + +# ct_seed_priv_validator_state HOME_DIR +# Ensure data/priv_validator_state.json exists (cometbft refuses to start without it +# when one is present in config/). Mirrors the berachain init.sh behavior. +ct_seed_priv_validator_state() { + _home="$1" + if [ -e "$_home/config/priv_validator_state.json" ] && [ ! -e "$_home/data/priv_validator_state.json" ]; then + mkdir -p "$_home/data" + cp "$_home/config/priv_validator_state.json" "$_home/data/priv_validator_state.json" + fi + return 0 +} + +# ct_apk PKG... +# Install alpine packages idempotently (most cosmos init scripts need curl, some jq). +ct_apk() { + apk add --no-cache "$@" +} + +# ct_localize_home CONFIG_DIR +# Rewrite `~/` to `/root/` in config.toml + app.toml. Cosmos `init` writes home-relative +# paths; the container runs as root with a static home, so make paths absolute. +ct_localize_home() { + _dir="$1" + [ -f "$_dir/config.toml" ] && sed -i 's|~/|/root/|g' "$_dir/config.toml" + [ -f "$_dir/app.toml" ] && sed -i 's|~/|/root/|g' "$_dir/app.toml" + return 0 +} + +# ct_set_min_gas_prices APP_TOML PRICE +# Cosmos chains reject txs (and sometimes refuse to start) with an empty +# minimum-gas-prices. PRICE e.g. "0.01usei", "0.0025uatom", "0.01hqq". +ct_set_min_gas_prices() { + _app="$1"; _price="$2" + [ -f "$_app" ] || return 0 + [ -n "$_price" ] || return 0 + sed -i "s/minimum-gas-prices = \"\"/minimum-gas-prices = \"${_price}\"/g" "$_app" + return 0 +} + +# ct_configure_statesync CONFIG_TOML RPC_SERVERS [TRUST_OFFSET] +# Enable cometbft state-sync so a fresh node bootstraps near chainhead instead of +# replaying from genesis — the single biggest lever for "can't keep it at chainhead" +# chains. RPC_SERVERS = comma list of trusted RPC endpoints (>=2 recommended; a single +# endpoint is duplicated). TRUST_OFFSET = blocks below head to trust (default 2000). +# Requires jq + curl. No-op (logged) if head height can't be fetched. +ct_configure_statesync() { + _cfg="$1"; _rpc="$2"; _offset="${3:-2000}" + [ -f "$_cfg" ] || return 0 + # NEVER re-arm statesync on a node that already has application state (a restored + # snapshot or a prior sync). Re-statesyncing over it leaves a broken/partial datadir and, + # for wasm chains, drops the wasm files -> startup panic. _cfg is $HOME/config/config.toml, + # so application state lives at $HOME/data/application.db. + _home=$(dirname "$(dirname "$_cfg")") + if [ -e "$_home/data/application.db" ]; then + ct_log "statesync: existing data dir, skipping" + return 0 + fi + [ -n "$_rpc" ] || { ct_log "statesync: no RPC servers given, skipping"; return 0; } + _primary=$(echo "$_rpc" | cut -d, -f1) + _latest=$(curl -s "$_primary/block" | jq -r '.result.block.header.height // .block.header.height' 2>/dev/null || true) + if [ -z "$_latest" ] || [ "$_latest" = null ]; then + ct_log "statesync: could not read head height from $_primary, skipping"; return 0 + fi + _trust_h=$((_latest - _offset)) + _trust_hash=$(curl -s "$_primary/block?height=$_trust_h" | jq -r '.result.block_id.hash // .block_id.hash' 2>/dev/null || true) + [ -n "$_trust_hash" ] && [ "$_trust_hash" != null ] || { ct_log "statesync: no trust hash, skipping"; return 0; } + # second server defaults to the first (cometbft wants >=2 for light-client cross-check) + echo "$_rpc" | grep -q ',' || _rpc="$_rpc,$_rpc" + ct_log "statesync: enable trust_height=$_trust_h trust_hash=$_trust_hash" + # Patch ONLY the [statesync] section. CometBFT config.toml uses underscore keys + # (rpc_servers/trust_height/trust_hash); tolerate hyphen variants with [_-]. + sed -i.bak -E "/^\[statesync\]/,/^\[/{ + s|^([[:space:]]*enable[[:space:]]*=[[:space:]]*).*|\1true| + s|^([[:space:]]*rpc[_-]servers[[:space:]]*=[[:space:]]*).*|\1\"$_rpc\"| + s|^([[:space:]]*trust[_-]height[[:space:]]*=[[:space:]]*).*|\1$_trust_h| + s|^([[:space:]]*trust[_-]hash[[:space:]]*=[[:space:]]*).*|\1\"$_trust_hash\"| + }" "$_cfg" + return 0 +} + +# ct_ensure_wasm HOME_DIR WASM_SNAPSHOT_URL +# CosmWasm + IBC 08-wasm bytecode are FILES on disk that state-sync does NOT restore, so +# a state-synced wasm chain panics at startup ("wasmlckeeper failed initialize pinned codes +# / Error opening Wasm file"). Seed them from a wasm-only snapshot (e.g. polkachu +# cosmos_wasmonly.tar.lz4) when the wasm dir is missing/empty. No-op if URL unset or wasm +# already present. Best-effort (logs on failure); the fully robust path for wasm chains is a +# FULL snapshot restore. Requires lz4 + tar (installed here). +ct_ensure_wasm() { + _home="$1"; _url="$2" + [ -n "$_url" ] || return 0 + if [ -d "$_home/wasm" ] && [ -n "$(ls -A "$_home/wasm" 2>/dev/null)" ]; then + return 0 # wasm already present + fi + ct_log "wasm: empty, fetching snapshot $_url" + ct_apk lz4 tar + if curl -sL "$_url" | lz4 -dc | tar -xf - -C "$_home"; then + ct_log "wasm: extracted into $_home" + else + ct_log "WARN wasm: fetch/extract failed ($_url)" + fi + return 0 +} diff --git a/tac/scripts/init.sh b/tac/scripts/init.sh new file mode 100755 index 00000000..164b6d4c --- /dev/null +++ b/tac/scripts/init.sh @@ -0,0 +1,40 @@ +#!/bin/sh +# tacchaind entrypoint — TAC (Cosmos-SDK + embedded EVM). Genesis replay is impractical +# (5 gov upgrades), so fresh nodes statesync near head via cometbft-common.sh. +set -e +. /usr/local/bin/cometbft-common.sh + +HOME_DIR="/root/.tacchaind" +CONFIG_DIR="$HOME_DIR/config" +CHAIN_ID="${CHAIN_ID:-tacchain_239-1}" +GENESIS_URL="${GENESIS_URL:-https://raw.githubusercontent.com/TacBuild/tacchain/refs/heads/main/networks/tacchain_239-1/genesis.json}" +STATESYNC_RPC="${STATESYNC_RPC:-https://tendermint.rpc.tac.build}" +MIN_GAS="${MIN_GAS:-25000000000utac}" +API="${API:-eth,net,web3,txpool,debug}" +MONIKER="${MONIKER:-rpc-node}" + +ct_apk curl jq + +if tacchaind init "$MONIKER" --chain-id "$CHAIN_ID" --home "$HOME_DIR" >/dev/null 2>&1; then + ct_log "fresh init; fetching genesis" + ct_fetch "$GENESIS_URL" "$CONFIG_DIR/genesis.json" required + ct_localize_home "$CONFIG_DIR" + ct_set_min_gas_prices "$CONFIG_DIR/app.toml" "$MIN_GAS" +else + ct_log "already initialized, continuing" +fi + +ct_patch_p2p "$CONFIG_DIR/config.toml" "$IP" "${P2P_PORT:-26656}" +ct_set_persistent_peers "$CONFIG_DIR/config.toml" "$PERSISTENT_PEERS" +ct_set_moniker "$CONFIG_DIR/config.toml" "$MONIKER" +ct_configure_statesync "$CONFIG_DIR/config.toml" "$STATESYNC_RPC" + +sed -i -e "s/^indexer *=.*/indexer = \"null\"/" "$CONFIG_DIR/config.toml" + +sed -i "/^\[json-rpc\]/,/^\[/{s|^address = .*|address = \"0.0.0.0:8545\"|}" "$CONFIG_DIR/app.toml" +sed -i "/^\[json-rpc\]/,/^\[/{s|^ws-address = .*|ws-address = \"0.0.0.0:8546\"|}" "$CONFIG_DIR/app.toml" +sed -i "/^\[json-rpc\]/,/^\[/{s|^api = .*|api = \"$API\"|}" "$CONFIG_DIR/app.toml" + +ct_seed_priv_validator_state "$HOME_DIR" + +exec tacchaind start --chain-id="$CHAIN_ID" --pruning=default --json-rpc.enable --home "$HOME_DIR" "$@" diff --git a/tac/tacchaind.Dockerfile b/tac/tacchaind.Dockerfile new file mode 100644 index 00000000..c3a44760 --- /dev/null +++ b/tac/tacchaind.Dockerfile @@ -0,0 +1,35 @@ +# tacchaind — source build mirroring upstream TacBuild/tacchain Dockerfile (v1.6.0). +ARG VERSION=v1.6.0 + +FROM golang:1.23.8-alpine3.21 AS go-builder + +RUN apk add --no-cache \ + ca-certificates \ + build-base \ + libusb-dev \ + linux-headers \ + eudev-dev + +WORKDIR /code +RUN git clone https://github.com/TacBuild/tacchain.git /code && \ + cd /code && \ + git checkout "${VERSION}" && \ + LEDGER_ENABLED=true make build + +FROM alpine:3.21 + +RUN apk upgrade --no-cache && \ + apk add --no-cache \ + ca-certificates \ + libusb + +COPY --from=go-builder /code/build/tacchaind /usr/bin/tacchaind +COPY ./scripts/cometbft-common.sh /usr/local/bin/cometbft-common.sh +COPY ./scripts/init.sh /usr/local/bin/init.sh +RUN chmod +x /usr/local/bin/init.sh /usr/local/bin/cometbft-common.sh + +WORKDIR /opt + +EXPOSE 1317 26656 26657 + +ENTRYPOINT ["init.sh"] diff --git a/tac/tacchaind/tac-mainnet-tacchaind-pruned.yml b/tac/tacchaind/tac-mainnet-tacchaind-pruned.yml new file mode 100644 index 00000000..618b99fa --- /dev/null +++ b/tac/tacchaind/tac-mainnet-tacchaind-pruned.yml @@ -0,0 +1,126 @@ +--- +x-logging-defaults: &logging-defaults + driver: json-file + options: + max-size: "10m" + max-file: "3" + +# Usage: +# +# mkdir rpc && cd rpc +# +# git init +# git remote add origin https://github.com/StakeSquid/ethereum-rpc-docker.git +# git fetch origin vibe +# git checkout origin/vibe +# +# docker run --rm alpine sh -c "printf '0x'; head -c32 /dev/urandom | xxd -p -c 64" > .jwtsecret +# +# env +# ... +# IP=$(curl ipinfo.io/ip) +# DOMAIN=${IP}.traefik.me +# COMPOSE_FILE=base.yml:rpc.yml:tac/tacchaind/tac-mainnet-tacchaind-pruned.yml +# +# docker compose up -d +# +# curl -X POST https://${IP}.traefik.me/tac-mainnet \ +# -H "Content-Type: application/json" \ +# --data '{"jsonrpc":"2.0","method":"eth_blockNumber","params":[],"id":1}' + +services: + tac-mainnet: + build: + context: ./tac + dockerfile: tacchaind.Dockerfile + args: + VERSION: ${TAC_MAINNET_TACCHAIND_VERSION:-v1.6.0} + sysctls: + # TCP Performance + net.ipv4.tcp_slow_start_after_idle: 0 # Disable slow start after idle + net.ipv4.tcp_no_metrics_save: 1 # Disable metrics cache + net.ipv4.tcp_rmem: 4096 87380 16777216 # Increase TCP read buffers + net.ipv4.tcp_wmem: 4096 87380 16777216 # Increase TCP write buffers + net.core.somaxconn: 32768 # Higher connection queue + # Memory/Connection Management + # net.core.netdev_max_backlog: 50000 # Increase network buffer + net.ipv4.tcp_max_syn_backlog: 30000 # More SYN requests + net.ipv4.tcp_max_tw_buckets: 2000000 # Allow more TIME_WAIT sockets + ulimits: + nofile: 1048576 # Max open files (for RPC/WS connections) + user: root + ports: + - 10283:10283 + - 10283:10283/udp + expose: + - 8545 + - 8546 + - 6065 + environment: + - API=eth,net,web3,txpool,debug + - CHAIN_ID=tacchain_239-1 + - GENESIS_URL=https://raw.githubusercontent.com/TacBuild/tacchain/refs/heads/main/networks/tacchain_239-1/genesis.json + - IP=${IP} + - MIN_GAS=25000000000utac + - MONIKER=d${DOMAIN:-local} + - P2P_PORT=10283 + - PERSISTENT_PEERS=d0a80c43a10a6b60475864728db6d9ba4ead42d2@107.6.113.60:58960,10550a03e4f7fa487c78fbd07e0770e2b0f085c7@64.46.115.78:58960,0efae9d157f0ef60ad7d25507d6939799f832e34@173.244.202.99:58960,78079166d06e345dbf4a5c932ee3c69a04148e92@107.6.91.38:58960 + - STATESYNC_RPC=https://tendermint.rpc.tac.build + restart: unless-stopped + stop_grace_period: 5m + networks: + - chains + volumes: + - ${TAC_MAINNET_TACCHAIND_PRUNED_DATA:-tac-mainnet-tacchaind-pruned}:/root/.tacchaind/data + - /slowdisk:/slowdisk + - tac-mainnet-tacchaind-pruned_config:/root/.tacchaind/config + logging: *logging-defaults + labels: + - prometheus-scrape.enabled=true + - prometheus-scrape.port=6065 + - prometheus-scrape.path=/metrics + - traefik.enable=true + - traefik.http.middlewares.tac-mainnet-tacchaind-pruned-stripprefix.stripprefix.prefixes=/tac-mainnet + - traefik.http.services.tac-mainnet-tacchaind-pruned.loadbalancer.server.port=8545 + - ${NO_SSL:-traefik.http.routers.tac-mainnet-tacchaind-pruned.entrypoints=websecure} + - ${NO_SSL:-traefik.http.routers.tac-mainnet-tacchaind-pruned.tls.certresolver=myresolver} + - ${NO_SSL:-traefik.http.routers.tac-mainnet-tacchaind-pruned.rule=Host(`$DOMAIN`) && (Path(`/tac-mainnet`) || Path(`/tac-mainnet/`))} + - ${NO_SSL:+traefik.http.routers.tac-mainnet-tacchaind-pruned.rule=Path(`/tac-mainnet`) || Path(`/tac-mainnet/`)} + - traefik.http.routers.tac-mainnet-tacchaind-pruned.middlewares=tac-mainnet-tacchaind-pruned-stripprefix, ipallowlist + - traefik.http.routers.tac-mainnet-tacchaind-pruned.priority=50 # gets any request that is not GET with UPGRADE header + - traefik.http.routers.tac-mainnet-tacchaind-pruned-ws.priority=100 # answers GET requests first + - traefik.http.services.tac-mainnet-tacchaind-pruned-ws.loadbalancer.server.port=8546 + - traefik.http.routers.tac-mainnet-tacchaind-pruned-ws.service=tac-mainnet-tacchaind-pruned-ws + - traefik.http.routers.tac-mainnet-tacchaind-pruned.service=tac-mainnet-tacchaind-pruned + - ${NO_SSL:-traefik.http.routers.tac-mainnet-tacchaind-pruned-ws.entrypoints=websecure} + - ${NO_SSL:-traefik.http.routers.tac-mainnet-tacchaind-pruned-ws.tls.certresolver=myresolver} + - ${NO_SSL:-traefik.http.routers.tac-mainnet-tacchaind-pruned-ws.rule=Host(`$DOMAIN`) && (Path(`/tac-mainnet`) || Path(`/tac-mainnet/`)) && HeadersRegexp(`Upgrade`, `(?i)websocket`)} + - ${NO_SSL:+traefik.http.routers.tac-mainnet-tacchaind-pruned-ws.rule=(Path(`/tac-mainnet`) || Path(`/tac-mainnet/`)) && HeadersRegexp(`Upgrade`, `(?i)websocket`)} + - traefik.http.routers.tac-mainnet-tacchaind-pruned-ws.middlewares=tac-mainnet-tacchaind-pruned-stripprefix, ipallowlist + +volumes: + tac-mainnet-tacchaind-pruned: + tac-mainnet-tacchaind-pruned_config: + +x-upstreams: + - id: $${ID} + labels: + provider: $${PROVIDER} + connection: + generic: + rpc: + url: $${RPC_URL} + ws: + frameSize: 20Mb + msgSize: 50Mb + url: $${WS_URL} + chain: tac + method-groups: + enabled: + - debug + - filter + methods: + disabled: + enabled: + - name: txpool_content # TODO: should be disabled for rollup nodes +... \ No newline at end of file diff --git a/tac/tacchaind/tac-spb-tacchaind-pruned.yml b/tac/tacchaind/tac-spb-tacchaind-pruned.yml new file mode 100644 index 00000000..c8aa3299 --- /dev/null +++ b/tac/tacchaind/tac-spb-tacchaind-pruned.yml @@ -0,0 +1,126 @@ +--- +x-logging-defaults: &logging-defaults + driver: json-file + options: + max-size: "10m" + max-file: "3" + +# Usage: +# +# mkdir rpc && cd rpc +# +# git init +# git remote add origin https://github.com/StakeSquid/ethereum-rpc-docker.git +# git fetch origin vibe +# git checkout origin/vibe +# +# docker run --rm alpine sh -c "printf '0x'; head -c32 /dev/urandom | xxd -p -c 64" > .jwtsecret +# +# env +# ... +# IP=$(curl ipinfo.io/ip) +# DOMAIN=${IP}.traefik.me +# COMPOSE_FILE=base.yml:rpc.yml:tac/tacchaind/tac-spb-tacchaind-pruned.yml +# +# docker compose up -d +# +# curl -X POST https://${IP}.traefik.me/tac-spb \ +# -H "Content-Type: application/json" \ +# --data '{"jsonrpc":"2.0","method":"eth_blockNumber","params":[],"id":1}' + +services: + tac-spb: + build: + context: ./tac + dockerfile: tacchaind.Dockerfile + args: + VERSION: ${TAC_SPB_TACCHAIND_VERSION:-v1.6.0} + sysctls: + # TCP Performance + net.ipv4.tcp_slow_start_after_idle: 0 # Disable slow start after idle + net.ipv4.tcp_no_metrics_save: 1 # Disable metrics cache + net.ipv4.tcp_rmem: 4096 87380 16777216 # Increase TCP read buffers + net.ipv4.tcp_wmem: 4096 87380 16777216 # Increase TCP write buffers + net.core.somaxconn: 32768 # Higher connection queue + # Memory/Connection Management + # net.core.netdev_max_backlog: 50000 # Increase network buffer + net.ipv4.tcp_max_syn_backlog: 30000 # More SYN requests + net.ipv4.tcp_max_tw_buckets: 2000000 # Allow more TIME_WAIT sockets + ulimits: + nofile: 1048576 # Max open files (for RPC/WS connections) + user: root + ports: + - 14331:14331 + - 14331:14331/udp + expose: + - 8545 + - 8546 + - 6065 + environment: + - API=eth,net,web3,txpool,debug + - CHAIN_ID=tacchain_2391-1 + - GENESIS_URL=https://raw.githubusercontent.com/TacBuild/tacchain/refs/heads/main/networks/tacchain_2391-1/genesis.json + - IP=${IP} + - MIN_GAS=25000000000utac + - MONIKER=d${DOMAIN:-local} + - P2P_PORT=14331 + - PERSISTENT_PEERS=9c32b3b959a2427bd2aa064f8c9a8efebdad4c23@206.217.210.164:45130,04a2152eed9f73dc44779387a870ea6480c41fe7@206.217.210.164:45140,5aaaf8140262d7416ac53abe4e0bd13b0f582168@23.92.177.41:45110,ddb3e8b8f4d051e914686302dafc2a73adf9b0d2@23.92.177.41:45120 + - STATESYNC_RPC=https://spb.tendermint.rpc.tac.build + restart: unless-stopped + stop_grace_period: 5m + networks: + - chains + volumes: + - ${TAC_SPB_TACCHAIND_PRUNED_DATA:-tac-spb-tacchaind-pruned}:/root/.tacchaind/data + - /slowdisk:/slowdisk + - tac-spb-tacchaind-pruned_config:/root/.tacchaind/config + logging: *logging-defaults + labels: + - prometheus-scrape.enabled=true + - prometheus-scrape.port=6065 + - prometheus-scrape.path=/metrics + - traefik.enable=true + - traefik.http.middlewares.tac-spb-tacchaind-pruned-stripprefix.stripprefix.prefixes=/tac-spb + - traefik.http.services.tac-spb-tacchaind-pruned.loadbalancer.server.port=8545 + - ${NO_SSL:-traefik.http.routers.tac-spb-tacchaind-pruned.entrypoints=websecure} + - ${NO_SSL:-traefik.http.routers.tac-spb-tacchaind-pruned.tls.certresolver=myresolver} + - ${NO_SSL:-traefik.http.routers.tac-spb-tacchaind-pruned.rule=Host(`$DOMAIN`) && (Path(`/tac-spb`) || Path(`/tac-spb/`))} + - ${NO_SSL:+traefik.http.routers.tac-spb-tacchaind-pruned.rule=Path(`/tac-spb`) || Path(`/tac-spb/`)} + - traefik.http.routers.tac-spb-tacchaind-pruned.middlewares=tac-spb-tacchaind-pruned-stripprefix, ipallowlist + - traefik.http.routers.tac-spb-tacchaind-pruned.priority=50 # gets any request that is not GET with UPGRADE header + - traefik.http.routers.tac-spb-tacchaind-pruned-ws.priority=100 # answers GET requests first + - traefik.http.services.tac-spb-tacchaind-pruned-ws.loadbalancer.server.port=8546 + - traefik.http.routers.tac-spb-tacchaind-pruned-ws.service=tac-spb-tacchaind-pruned-ws + - traefik.http.routers.tac-spb-tacchaind-pruned.service=tac-spb-tacchaind-pruned + - ${NO_SSL:-traefik.http.routers.tac-spb-tacchaind-pruned-ws.entrypoints=websecure} + - ${NO_SSL:-traefik.http.routers.tac-spb-tacchaind-pruned-ws.tls.certresolver=myresolver} + - ${NO_SSL:-traefik.http.routers.tac-spb-tacchaind-pruned-ws.rule=Host(`$DOMAIN`) && (Path(`/tac-spb`) || Path(`/tac-spb/`)) && HeadersRegexp(`Upgrade`, `(?i)websocket`)} + - ${NO_SSL:+traefik.http.routers.tac-spb-tacchaind-pruned-ws.rule=(Path(`/tac-spb`) || Path(`/tac-spb/`)) && HeadersRegexp(`Upgrade`, `(?i)websocket`)} + - traefik.http.routers.tac-spb-tacchaind-pruned-ws.middlewares=tac-spb-tacchaind-pruned-stripprefix, ipallowlist + +volumes: + tac-spb-tacchaind-pruned: + tac-spb-tacchaind-pruned_config: + +x-upstreams: + - id: $${ID} + labels: + provider: $${PROVIDER} + connection: + generic: + rpc: + url: $${RPC_URL} + ws: + frameSize: 20Mb + msgSize: 50Mb + url: $${WS_URL} + chain: tac-spb + method-groups: + enabled: + - debug + - filter + methods: + disabled: + enabled: + - name: txpool_content # TODO: should be disabled for rollup nodes +... \ No newline at end of file