Files
ethereum-rpc-docker/plasma/reth/plasma-testnet-reth-pruned-trace.yml
Claude Agent db81e62c73 plasma: add testnet compose + assets (reth + plasma-consensus)
Canonicalize plasma-testnet so the tracked compose adopts the same
volume/service names as the de-32 hand-written override (rpc_plasma-
testnet-reth-pruned-trace-{execution,consensus,jwt}). Also refresh
mainnet observer sed to be chain-agnostic.
2026-07-19 04:15:45 +00:00

264 lines
10 KiB
YAML

---
x-logging-defaults: &logging-defaults
driver: json-file
options:
max-size: "512m"
max-file: "2"
# Usage:
#
# mkdir rpc && cd rpc
#
# git init
# git remote add origin https://github.com/StakeSquid/ethereum-rpc-docker.git
# git fetch origin vibe
# git checkout origin/vibe
#
# docker run --rm alpine sh -c "printf '0x'; head -c32 /dev/urandom | xxd -p -c 64" > .jwtsecret
#
# env
# ...
# IP=$(curl ipinfo.io/ip)
# DOMAIN=${IP}.traefik.me
# COMPOSE_FILE=base.yml:rpc.yml:plasma/reth/plasma-testnet-reth-pruned-trace.yml
#
# docker compose up -d
#
# curl -X POST https://${IP}.traefik.me/plasma-testnet \
# -H "Content-Type: application/json" \
# --data '{"jsonrpc":"2.0","method":"eth_blockNumber","params":[],"id":1}'
services:
plasma-testnet-initialize-openssl:
image: ${PLASMA_OPENSSL_IMAGE:-docker.io/alpine/openssl}:${PLASMA_OPENSSL_VERSION:-3.5.2}
entrypoint: [/bin/sh, -c]
command:
- |
if [ ! -f /jwt/jwt.hex ]; then
echo 'INFO Generating jwt secret'
openssl rand -hex 32 | tr -d '\n' > /jwt/jwt.hex
else
echo 'INFO JWT secret already exists'
fi
if [ ! -f /consensus/ec-secp256k1-non-validator.pem ]; then
echo 'INFO Generating secp256k1 keypair for non-validator'
openssl ecparam -name secp256k1 -genkey -noout -out /consensus/ec-secp256k1-non-validator.pem
openssl ec -in /consensus/ec-secp256k1-non-validator.pem -outform DER -no_public -out /consensus/ec-secp256k1-non-validator.der
else
echo 'INFO secp256k1 keypair for non-validator already exists'
fi
echo 'INFO OpenSSL initialization completed'
restart: no
networks:
- chains
volumes:
- ${PLASMA_TESTNET_RETH_PRUNED_TRACE_CONSENSUS_DATA:-plasma-testnet-reth-pruned-trace-consensus}:/consensus:rw
- plasma-testnet-reth-pruned-trace-jwt:/jwt:rw
logging: *logging-defaults
plasma-testnet-initialize-consensus:
image: ${PLASMA_PLASMA_CONSENSUS_IMAGE:-ghcr.io/plasmalaboratories/plasma-consensus-public}:${PLASMA_TESTNET_PLASMA_CONSENSUS_VERSION:-0.15.0}
user: 0:0
entrypoint: [/bin/bash, -c]
command:
- |
set -euo pipefail
if [ ! -f /consensus/data.mdb ]; then
echo "INFO Generating consensus database for testnet network"
plasma-cli init \
--chain /node/genesis.json \
--data-dir /consensus
else
echo "INFO Consensus database already exists at /consensus/data.mdb"
fi
if [ ! -f /consensus/peer-id.txt ]; then
echo "INFO Generating peer ID for non-validator"
plasma-cli peer-id \
--identity-file-path /consensus/ec-secp256k1-non-validator.der > /consensus/peer-id.txt
else
echo "INFO Peer ID for non-validator already exists"
fi
restart: no
depends_on:
plasma-testnet-initialize-openssl:
condition: service_completed_successfully
networks:
- chains
volumes:
- ${PLASMA_TESTNET_RETH_PRUNED_TRACE_CONSENSUS_DATA:-plasma-testnet-reth-pruned-trace-consensus}:/consensus:rw
- ./plasma/testnet/genesis.json:/node/genesis.json:ro
- plasma-testnet-reth-pruned-trace-jwt:/jwt:ro
logging: *logging-defaults
plasma-testnet-initialize-execution:
image: ${PLASMA_RETH_IMAGE:-ghcr.io/paradigmxyz/reth}:${PLASMA_TESTNET_RETH_VERSION:-v1.11.3}
user: 0:0
entrypoint: [/bin/bash, -c]
command:
- |
set -euo pipefail
if [ ! -f /execution/db/mdbx.dat ]; then
echo "INFO Generating execution database for testnet network"
reth init \
--chain /node/genesis.json \
--datadir /execution \
--log.file.directory /execution/log
else
echo "INFO Execution database already exists at /execution/db"
fi
restart: no
depends_on:
plasma-testnet-initialize-consensus:
condition: service_completed_successfully
networks:
- chains
volumes:
- ${PLASMA_TESTNET_RETH_PRUNED_TRACE_EXECUTION_DATA:-plasma-testnet-reth-pruned-trace-execution}:/execution:rw
- ./plasma/testnet/genesis.json:/node/genesis.json:ro
- plasma-testnet-reth-pruned-trace-jwt:/jwt:ro
logging: *logging-defaults
plasma-testnet:
image: ${PLASMA_RETH_IMAGE:-ghcr.io/paradigmxyz/reth}:${PLASMA_TESTNET_RETH_VERSION:-v1.11.3}
sysctls:
# TCP Performance
net.ipv4.tcp_slow_start_after_idle: 0 # Disable slow start after idle
net.ipv4.tcp_no_metrics_save: 1 # Disable metrics cache
net.ipv4.tcp_rmem: 4096 87380 16777216 # Increase TCP read buffers
net.ipv4.tcp_wmem: 4096 87380 16777216 # Increase TCP write buffers
net.core.somaxconn: 32768 # Higher connection queue
# Memory/Connection Management
# net.core.netdev_max_backlog: 50000 # Increase network buffer
net.ipv4.tcp_max_syn_backlog: 30000 # More SYN requests
net.ipv4.tcp_max_tw_buckets: 2000000 # Allow more TIME_WAIT sockets
ulimits:
nofile: 1048576 # Max open files (for RPC/WS connections)
memlock: -1 # Disable memory locking limits (for in-memory DBs like MDBX)
user: 0:0
ports:
- 14566:30303
- 14566:30303/udp
expose:
- 8545
- 8551
- 9001
entrypoint: [/bin/bash, -c]
command:
- |
reth node \
--chain /node/genesis.json \
--datadir /execution \
--trusted-peers "enode://263b9c64548d2d06b9c514a203087cec8abe72945906d8cf38c97ea8ada5a2385cd58a8680bdab8df25921c1d8aee79976a406364012db09516fd1a6a8a41796@plasma-testnet-observer-ex-1.plasmalabs.tech:30303?discport=30304,enode://66379af5b9c704b88c92093c6a2cdcc0e7086d02ab6a0720cb08a4a050b7f35e7e2ded7204a6fd4f839494a62443301daae59773fa099f031375f2f887e96f6b@plasma-testnet-observer-ex-4.plasmalabs.tech:30303?discport=30304,enode://a1cee61c9fc0f1c98c7348bb9a8cdc2fe56d80a4dc979c463729692ccd835c02e3e0cd238852cb9311c0b3fc6fb0f496d8109599d6be0039b7ffbcb4e577de05@plasma-testnet-observer-ex-9.plasmalabs.tech:30303?discport=30304" \
--authrpc.jwtsecret /jwt/jwt.hex \
--authrpc.addr 0.0.0.0 \
--authrpc.port 8551 \
--http \
--http.addr 0.0.0.0 \
--http.api eth,net,web3,txpool,debug \
--http.corsdomain '*' \
--metrics 0.0.0.0:9001 \
--color never \
--rpc.gascap 600000000 \
--txpool.gas-limit 36000000 \
--txpool.blobpool-max-count 0 \
--txpool.blobpool-max-size 0 \
--txpool.blob-cache-size 0 \
--log.file.directory /execution/log
restart: unless-stopped
stop_grace_period: 5m
depends_on:
plasma-testnet-initialize-execution:
condition: service_completed_successfully
networks:
- chains
volumes:
- ${PLASMA_TESTNET_RETH_PRUNED_TRACE_EXECUTION_DATA:-plasma-testnet-reth-pruned-trace-execution}:/execution:rw
- ./plasma/testnet/genesis.json:/node/genesis.json:ro
- /slowdisk:/slowdisk
- plasma-testnet-reth-pruned-trace-jwt:/jwt:ro
healthcheck:
test: [CMD, bash, -c, exec 6<> /dev/tcp/localhost/8545 && exec 6<> /dev/tcp/localhost/8551]
interval: 10s
timeout: 10s
retries: 30
logging: *logging-defaults
labels:
- prometheus-scrape.enabled=true
- prometheus-scrape.port=9001
- prometheus-scrape.path=/metrics
- traefik.enable=true
- traefik.http.middlewares.plasma-testnet-reth-pruned-trace-stripprefix.stripprefix.prefixes=/plasma-testnet
- traefik.http.services.plasma-testnet-reth-pruned-trace.loadbalancer.server.port=8545
- ${NO_SSL:-traefik.http.routers.plasma-testnet-reth-pruned-trace.entrypoints=websecure}
- ${NO_SSL:-traefik.http.routers.plasma-testnet-reth-pruned-trace.tls.certresolver=myresolver}
- ${NO_SSL:-traefik.http.routers.plasma-testnet-reth-pruned-trace.rule=Host(`$DOMAIN`) && (Path(`/plasma-testnet`) || Path(`/plasma-testnet/`))}
- ${NO_SSL:+traefik.http.routers.plasma-testnet-reth-pruned-trace.rule=Path(`/plasma-testnet`) || Path(`/plasma-testnet/`)}
- traefik.http.routers.plasma-testnet-reth-pruned-trace.middlewares=plasma-testnet-reth-pruned-trace-stripprefix, ipallowlist
shm_size: 2gb
plasma-testnet-node:
image: ${PLASMA_PLASMA_CONSENSUS_IMAGE:-ghcr.io/plasmalaboratories/plasma-consensus-public}:${PLASMA_TESTNET_PLASMA_CONSENSUS_VERSION:-0.15.0}
user: 0:0
ports:
- 19566:34070
expose:
- 35070
- 9001
entrypoint: [/bin/bash, -c]
command:
- |
# Rewrite engine_api_url to this compose service (mainnet/testnet tomls ship chain-specific hosts).
sed -E 's|http://[^[:space:]/"]+:8551|http://plasma-testnet:8551|g' /config/non-validator.toml > /tmp/non-validator.toml
exec plasma-cli observer \
--config-path /tmp/non-validator.toml \
--no-color \
--timeout-stream-manager 5s \
--telemetry.enable-metrics \
--telemetry.enable-health \
--telemetry.host 0.0.0.0 \
--telemetry.port 9001 \
-vvv
restart: unless-stopped
stop_grace_period: 5m
depends_on:
plasma-testnet-initialize-consensus:
condition: service_completed_successfully
plasma-testnet:
condition: service_healthy
networks:
- chains
volumes:
- ${PLASMA_TESTNET_RETH_PRUNED_TRACE_CONSENSUS_DATA:-plasma-testnet-reth-pruned-trace-consensus}:/consensus:rw
- ./plasma/testnet/genesis.json:/node/genesis.json:ro
- ./plasma/testnet/identities:/node/identities:ro
- ./plasma/testnet/keys:/node/keys:ro
- ./plasma/testnet/non-validator.toml:/config/non-validator.toml:ro
- plasma-testnet-reth-pruned-trace-jwt:/jwt:ro
logging: *logging-defaults
labels:
- prometheus-scrape.enabled=true
- prometheus-scrape.port=9001
volumes:
plasma-testnet-reth-pruned-trace-consensus:
plasma-testnet-reth-pruned-trace-execution:
plasma-testnet-reth-pruned-trace-jwt:
x-upstreams:
- id: $${ID}
labels:
provider: $${PROVIDER}
connection:
generic:
rpc:
url: $${RPC_URL}
chain: plasma-testnet
method-groups:
enabled:
- debug
- filter
- trace
methods:
enabled:
- name: txpool_content
...