Sentry node architecture
A sentry layer keeps the validator off the public internet. The validator talks only to a few full nodes you run, the sentries, and the sentries talk to the rest of the network. A DDoS attack then hits a replaceable full node instead of costing you missed blocks. Each sentry is an ordinary full node, set up like the validator (samelumerad, genesis, and sync), on its own server. Run at least two. If every sentry is down, the validator has no peers.
Find each node’s ID on that node.
~/.lumera/config/config.toml.
~/.lumera/config/config.toml.
private_peer_ids keeps the sentries from gossiping the validator’s address. With pex = false, the validator dials only the peers listed.
Then let only the sentries reach the validator’s P2P port, and restart.
Protect the consensus key
The validator signs blocks with~/.lumera/config/priv_validator_key.json. The node’s P2P identity is ~/.lumera/config/node_key.json.
- Back up both files offline, encrypted. Never keep the only copy on the server.
- Never run the same
priv_validator_key.jsonon two machines at once. Two signers double-sign, and double signing is slashed and tombstoned permanently. - When you restore or move a validator, stop the old node and make sure it can’t start again before you start the new one. See migrating to a new server.
- Protect the operator key’s keyring with a strong passphrase.
Host hardening beyond node setup
Install security updates automatically.Metrics and alerts
The operations pages list what to alert on (mainnet, testnet). This is a minimal Prometheus setup to start from. Turn on the node’s metrics: setprometheus = true in the [instrumentation] section of ~/.lumera/config/config.toml and restart. Metrics are then served on localhost:26660/metrics.
Add host metrics with node_exporter. Check the node_exporter releases for the current version.
Metric names start with the
namespace set in the [instrumentation] section, cometbft by default. List what your node exports with curl -s localhost:26660/metrics | grep missed and adjust the rule to match.Next steps
Mainnet operations
Upgrades, monitoring, troubleshooting, and migration on mainnet.
Testnet operations
The same procedures on testnet.