~/.evmd/config/app.toml 中配置 EVM 特定设置。本指南介绍 EVM 实现独有的参数。
- EVM
- 交易池
- JSON-RPC
- 运行时标志
- 应用配置
- 验证者节点
EVM 执行环境配置。
控制 VM 执行跟踪,用于调试。有效选项:
""- 禁用(默认)"json"- JSON 格式的完整执行跟踪,用于debug_traceTransactionRPC"struct"- 用于程序化处理的 Go 结构体格式"access_list"- 生成用于 Gas 优化的 EIP-2930 访问列表"markdown"- 便于人工分析的人类可读格式
server/config/config.go:139
实现: x/vm/keeper/state_transition.go:150-157在 CheckTx 模式下限制交易的 Gas,以防止 DoS 攻击。设为 0 时,将接受任意 Gas 数量,这可能导致 mempool 垃圾交易。来源:
server/config/config.go:141
测试网默认值: 由 evmd/cmd/evmd/cmd/testnet.go:303 设置在 VM 中启用 SHA3 原像记录,便于调试工具反向查询哈希。启用后会增加内存占用。来源:
server/config/config.go:143EIP-155 重放保护链 ID。必须与预期的网络链 ID 一致。用于交易签名校验。来源:
server/config/config.go:145
使用位置: x/vm/genesis.go:22交易进入 mempool 所需的最小优先费(tip)。低于此值的交易可能会被拒绝。设为 0 可禁用过滤。标志:
EVMMinTip
来源: server/config/config.go:150
类型: 内部转换为 uint256.Intgo-ethereum 指标服务器地址。以 Prometheus 格式输出 EVM 专用指标,并与 Cosmos SDK 指标分离在独立服务器上提供。来源:
server/config/config.go:152
新增于: v0.5.0用于交易池管理的 EVM mempool 配置。低资源节点:严格的垃圾交易防护:
v0.5.0 新增:现在
app.toml 已完整暴露 mempool 配置,无需修改代码即可调整。此前这些设置是硬编码的。进入池时强制要求的最小 Gas 价格(单位 wei)。Gas 价格低于此值的交易会被 mempool 拒绝。来源:
server/config/config.go:160
校验: 必须至少为 1替换已存在交易(nonce 相同)所需的最小提价百分比。替换同一 nonce 的交易时,新交易的 Gas 价格必须至少高出此百分比。来源:
server/config/config.go:162
示例: 10 = 需要高出 10% 的 Gas 价格
校验: 必须至少为 1每个账户保证拥有的可执行交易槽位数量。每个账户在可执行队列中都保证可拥有这么多待处理交易。来源:
server/config/config.go:164
校验: 必须至少为 1所有账户可执行交易槽位的最大数量。所有账户待处理可执行交易的总容量(4096 + 1024 = 5120)。来源:
server/config/config.go:166
校验: 必须至少为 1每个账户允许的不可执行交易槽位最大数量。用于 nonce 序列存在缺口的交易(未来交易)。来源:
server/config/config.go:168
校验: 必须至少为 1所有账户不可执行交易槽位的最大数量。所有账户排队中(不可执行)交易的总容量。来源:
server/config/config.go:170
校验: 必须至少为 1不可执行交易保留在队列中的最长时间。持续超过该时长仍不可执行的交易将从 mempool 中移除。来源:
server/config/config.go:172
格式: Go 时长字符串(例如:"1h30m"、"30m0s"、"24h0m0s")
校验: 必须至少为 1ns配置示例
高吞吐链:[evm.mempool]
global-slots = 10240
global-queue = 2048
price-limit = 100000000 # 0.1 gwei minimum
lifetime = "6h0m0s"
[evm.mempool]
global-slots = 2048
global-queue = 512
lifetime = "1h0m0s"
account-slots = 8
[evm.mempool]
price-limit = 1000000000 # 1 gwei minimum
price-bump = 25 # 25% replacement cost
lifetime = "30m0s"
account-slots = 4
Ethereum JSON-RPC 服务器配置。
核心设置
启用 JSON-RPC 服务器。对于 Ethereum 兼容性,必须设为
true。来源: server/config/config.go:169
测试网配置: evmd/cmd/evmd/cmd/testnet.go:303使用标准 Ethereum RPC 端口的 HTTP 服务器绑定地址。来源:
server/config/config.go:153用于
eth_subscribe 方法的 WebSocket 服务器地址。来源: server/config/config.go:155
实现: rpc/stream/rpc.go要启用的 JSON-RPC 命名空间。可用命名空间:
web3、eth、personal、net、txpool、debug、miner来源: server/config/config.go:151
命名空间实现: rpc/namespaces/WebSocket 连接允许的 CORS 源。来源:
server/config/config.go:195资源限制
eth_call/estimateGas 操作的 Gas 上限(2500 万 Gas)。设为 0 表示无限制。来源: server/config/config.go:157
生效位置: rpc/namespaces/ethereum/eth/api.go:1039eth_sendTransaction 的最大交易费上限(单位 ether)。来源: server/config/config.go:163
生效位置: rpc/namespaces/ethereum/eth/api.go:1586每个连接允许的最大并发过滤器数量。来源:
server/config/config.go:165
实现: rpc/namespaces/ethereum/eth/filters/eth_feeHistory 可获取的最大区块数。来源: server/config/config.go:167单次
eth_getLogs 查询返回的最大日志数。来源: server/config/config.go:171
生效位置: rpc/namespaces/ethereum/eth/filters/api.go:442eth_getLogs 查询允许的最大区块范围。来源: server/config/config.go:173
生效位置: rpc/namespaces/ethereum/eth/filters/filter.go:268连接设置
单个批量请求中的最大请求数(go-ethereum 标准)。来源:
server/config/config.go:182批量调用返回的最大字节数(25MB)。来源:
server/config/config.go:184HTTP JSON-RPC 服务器的读/写超时时间。来源:
server/config/config.go:175HTTP 连接的空闲超时时间。来源:
server/config/config.go:177服务器监听器允许的最大并发连接数。设为 0 表示无限制。来源:
server/config/config.go:187eth_call 操作的全局超时时间。来源: server/config/config.go:161功能
为 EVM 交易启用自定义交易索引器。以下功能必需:
eth_getLogs、eth_getTransactionReceipt来源: server/config/config.go:189
测试网默认值: evmd/cmd/evmd/cmd/testnet.go:303在
debug 命名空间中启用 pprof 端点。来源: server/config/config.go:197Prometheus 指标服务器地址。指标路径:
/debug/metrics/prometheus来源: server/config/config.go:191安全性
允许提交非 EIP155 签名交易。来源:
server/config/config.go:180在启用
personal 命名空间时允许不安全的账户解锁。来源: server/config/config.go:159用于运行时配置的 CLI 标志和环境变量。这些参数可以通过命令行或环境变量设置,以覆盖配置文件中的设置。
上下文:这些是 EVM 专用的运行时参数,与标准 Cosmos SDK 标志互补。它们控制与 EVM 功能相关的链初始化和运行时行为。
用于交易签名和网络标识的 Cosmos SDK 链标识符。CLI 标志:
--chain-id
环境变量: EVMD_CHAIN_ID
用法: evmd start --chain-id mychain-1用于兼容 Ethereum 的 EIP-155 重放保护链 ID。它必须在所有 EVM 网络中保持唯一。CLI 标志:
--evm.evm-chain-id
环境变量: EVMD_EVM_CHAIN_ID
用法: evmd start --evm.evm-chain-id 9000
配置方式: 在 app.toml 的 [evm] evm-chain-id 下设置原生代币交易和质押的基础面额。CLI 标志:
--denom
环境变量: EVMD_DENOM
用法: evmd init mynode --denom mytoken进入内存池所需的最低优先费(单位:wei)。CLI 标志:
--evm.min-tip
环境变量: EVMD_EVM_MIN_TIP
用法: evmd start --evm.min-tip 1000000000
配置方式: 在 app.toml 的 [evm] min-tip 下设置CheckTx 验证模式下交易的最大 gas 限额。CLI 标志:
--evm.max-tx-gas-wanted
环境变量: EVMD_MAX_TX_GAS_WANTED
用法: evmd start --evm.max-tx-gas-wanted 50000000
配置方式: 在 app.toml 的 [evm] max-tx-gas-wanted 下设置完整的 LogsCap 定义单次
logs-cap = 10000BlockRangeCap 定义
block-range-cap = 10000EVM 专用参数:
app.toml,其中突出显示了 EVM 特定章节。Complete Application Configuration
# 这是一个 TOML 配置文件。
# 更多信息请参见 https://github.com/toml-lang/toml
###############################################################################
### 基础配置 ###
###############################################################################
# 验证者愿意接受并处理交易的最低 gas 价格。
# 交易费用必须满足此配置中任一指定面额的最低要求
# (例如 0.25token1,0.0001token2)。
minimum-gas-prices = "0atest"
# 通过 rest/grpc 发起的查询可消耗的最大 gas。
# 如果设置为零,查询可消耗无限制数量的 gas。
query-gas-limit = "0"
# default:保留最近 362880 个状态,每 10 个区块修剪一次
# nothing:保存所有历史状态,不删除任何内容(即归档节点)
# everything:保留最新 2 个状态;每 10 个区块修剪一次。
# custom:允许通过 'pruning-keep-recent' 和 'pruning-interval' 手动指定修剪选项
pruning = "default"
# 仅当修剪策略为 custom 时才会应用这些设置。
pruning-keep-recent = "0"
pruning-interval = "0"
# HaltHeight 包含一个非零区块高度,节点将在该高度优雅停止并关闭,
# 可用于协助升级和测试。
#
# 注意:将在对应区块上尝试提交状态。
halt-height = 0
# HaltTime 包含一个非零的最小区块时间(Unix 秒),节点将在该时间优雅停止并关闭,
# 可用于协助升级和测试。
#
# 注意:将在对应区块上尝试提交状态。
halt-time = 0
# MinRetainBlocks 定义相对于当前正在提交区块的最小区块高度偏移量,
# 超过该偏移量的所有区块都会从 CometBFT 中被修剪。
# 它用于在 ABCI Commit 期间确定 ResponseCommit.RetainHeight 值的过程。
# 值为 0 表示不应修剪任何区块。
#
# 这个配置项只负责修剪 CometBFT 区块。
# 它不会影响应用状态修剪,后者由
# "pruning-*" 配置决定。
#
# 注意:CometBFT 区块修剪依赖此参数,并结合解绑期(安全阈值)、
# 状态修剪以及状态同步快照参数,来确定
# ResponseCommit.RetainHeight 的正确最小值。
min-retain-blocks = 0
# InterBlockCache 启用区块间缓存。
inter-block-cache = true
# IndexEvents 定义事件集合,格式为 {eventType}.{attributeKey},
# 用于告知 CometBFT 要建立索引的内容。如果为空,则会索引所有事件。
#
# 示例:
# ["message.sender", "message.recipient"]
index-events = []
# IavlCacheSize 设置 iavl 树缓存的大小(以节点数量计)。
iavl-cache-size = 781250
# IAVLDisableFastNode 启用或禁用 IAVL 的 fast node 功能。
# 默认值为 false。
iavl-disable-fastnode = false
# AppDBBackend 定义应用和快照数据库使用的数据库后端类型。
# 空字符串表示将使用回退值。
# 回退值为 CometBFT 的 config.toml 中设置的 db_backend 值。
app-db-backend = ""
###############################################################################
### 遥测配置 ###
###############################################################################
[telemetry]
# 使用键前缀来区分服务。
service-name = ""
# Enabled 启用应用遥测功能。启用后,
# 默认还会启用一个内存 sink。操作员也可以启用
# 其他 sink,例如 Prometheus。
enabled = true
# 启用以主机名为 gauge 值添加前缀。
enable-hostname = false
# 启用将主机名添加到标签中。
enable-hostname-label = false
# 启用将服务添加到标签中。
enable-service-label = false
# PrometheusRetentionTime 为正值时,会启用 Prometheus 指标 sink。
prometheus-retention-time = 1000000000000
# GlobalLabels 定义一组全局名称/值标签元组,
# 会应用到使用 telemetry 包中封装函数发出的所有指标。
#
# 示例:
# [["chain_id", "cosmoshub-1"]]
global-labels = [
]
# MetricsSink 定义要使用的指标 sink 类型。
metrics-sink = ""
# StatsdAddr 定义发送指标到 statsd 服务器的地址。
# 仅当 MetricsSink 设置为 "statsd" 或 "dogstatsd" 时使用。
statsd-addr = ""
# DatadogHostname 定义向 Datadog 发送指标时使用的主机名。
# 仅当 MetricsSink 设置为 "dogstatsd" 时使用。
datadog-hostname = ""
###############################################################################
### API 配置 ###
###############################################################################
[api]
# Enable 定义是否启用 API 服务器。
enable = true
# Swagger 定义是否自动注册 swagger 文档。
swagger = false
# Address 定义 API 服务器监听的地址。
address = "tcp://localhost:1317"
# MaxOpenConnections 定义最大打开连接数。
max-open-connections = 1000
# RPCReadTimeout 定义 CometBFT RPC 读取超时时间(秒)。
rpc-read-timeout = 10
# RPCWriteTimeout 定义 CometBFT RPC 写入超时时间(秒)。
rpc-write-timeout = 0
# RPCMaxBodyBytes 定义 CometBFT 最大请求体大小(字节)。
rpc-max-body-bytes = 1000000
# EnableUnsafeCORS 定义是否启用 CORS(不安全,请自行承担风险)。
enabled-unsafe-cors = false
###############################################################################
### gRPC 配置 ###
###############################################################################
[grpc]
# Enable 定义是否启用 gRPC 服务器。
enable = true
# Address 定义 gRPC 服务器要绑定的地址。
address = "localhost:9090"
# MaxRecvMsgSize 定义服务器可接收的最大消息大小(字节)。
# 默认值为 10MB。
max-recv-msg-size = "10485760"
# MaxSendMsgSize 定义服务器可发送的最大消息大小(字节)。
# 默认值为 math.MaxInt32。
max-send-msg-size = "2147483647"
###############################################################################
### gRPC Web 配置 ###
###############################################################################
[grpc-web]
# GRPCWebEnable 定义是否启用 gRPC-web。
# 注意:还必须启用 gRPC,否则此配置不会生效。
# 注意:gRPC-Web 使用与 API 服务器相同的地址。
enable = true
###############################################################################
### 状态同步配置 ###
###############################################################################
# 状态同步快照允许其他节点无需重放历史区块即可快速加入网络,
# 而是下载并应用某个高度的应用状态快照。
[state-sync]
# snapshot-interval 指定创建本地状态同步快照的区块间隔
# (0 表示禁用)。
snapshot-interval = 0
# snapshot-keep-recent 指定要保留并提供的最近快照数量
# (0 表示全部保留)。
snapshot-keep-recent = 2
###############################################################################
### 状态流式传输 ###
###############################################################################
# Streaming 允许节点将状态流式传输到外部系统。
[streaming]
# streaming.abci 指定 ABCI Listener 流式服务的配置。
[streaming.abci]
# 通过 gRPC 流式输出的 kv store 键列表。
# 这些 store 键名称必须与模块的 StoreKey 名称完全匹配。
#
# 示例:
# ["acc", "bank", "gov", "staking", "mint"[,...]]
# 使用 ["*"] 可暴露所有键。
keys = []
# 用于通过 gRPC 进行流式传输的插件名称。
# 仅在设置此项时才会启用流式传输。
# 支持的插件:abci
plugin = ""
# stop-node-on-err 指定在消息传递出错时是否停止节点。
stop-node-on-err = true
###############################################################################
### 内存池 ###
###############################################################################
[mempool]
# 将 max-txs 设置为 0 时,内存池中允许存在无限数量的交易。
# 将 max_txs 设置为负 1(-1)时,将禁用交易插入内存池(no-op mempool)。
# 将 max_txs 设置为正数(> 0)时,将按指定数量限制内存池中的交易数。
#
# 注意,此配置仅适用于 SDK 内置的应用侧内存池实现。
max-txs = -1
###############################################################################
### EVM 配置 ###
###############################################################################
[evm]
# Tracer 定义节点以调试模式运行时,EVM 使用的 'vm.Tracer' 类型。
# 要启用跟踪,请在启动节点时使用 '--evm.tracer' 标志。
# 有效类型为:json|struct|access_list|markdown
tracer = ""
MaxTxGasWanted 定义了在 check tx 模式下,ante handler 为每个返回的 eth 交易所声明的 gas 需求量。
max-tx-gas-wanted = 0EnablePreimageRecording 启用在 VM 中跟踪 SHA3 原像
cache-preimage = falseEVMChainID 是与 EIP-155 兼容的重放保护链 ID。它与 Cosmos 链 ID 分离。
evm-chain-id = 262144MinTip 定义内存池的最小优先费。
min-tip = 0Geth 指标服务器地址
geth-metrics-address = “127.0.0.1:8100”EVM 交易的内存池配置
[evm.mempool]PriceLimit 是进入交易池所要求的最小 gas price(单位:wei)
price-limit = 1PriceBump 是替换已存在交易(nonce)所需的最小价格提升百分比
price-bump = 10AccountSlots 是为每个账户保证的可执行交易槽位数量
account-slots = 16GlobalSlots 是所有账户可执行交易槽位的最大数量
global-slots = 5120AccountQueue 是每个账户允许的不可执行交易槽位最大数量
account-queue = 64GlobalQueue 是所有账户允许的不可执行交易槽位最大数量
global-queue = 1024Lifetime 是不可执行交易在队列中保留的最长时间
lifetime = “3h0m0s”###############################################################################JSON RPC 配置
###############################################################################[json-rpc]Enable 定义是否启用 JSONRPC 服务器。
enable = trueAddress 定义 EVM RPC HTTP 服务器绑定的地址。
address = “127.0.0.1:8545”Address 定义 EVM WebSocket 服务器绑定的地址。
ws-address = “127.0.0.1:8546”WSOrigins 定义 WebSocket 连接允许的来源。
示例:[“localhost”, “127.0.0.1”, “myapp.example.com”]
ws-origins = [“127.0.0.1”, “localhost”]API 定义应启用的 JSON-RPC 命名空间列表
示例:“eth,txpool,personal,net,debug,web3”
api = “eth,net,web3”GasCap 为 eth_call/estimateGas 可使用的 gas 设置上限(0=无限)。默认值:25,000,000。
gas-cap = 25000000当通过 http 暴露账户相关 RPC 时,允许不安全的账户解锁
allow-insecure-unlock = trueEVMTimeout 是 eth_call 的全局超时时间。默认值:5s。
evm-timeout = “5s”TxFeeCap 是发送交易的全局交易费上限。默认值:1eth。
txfee-cap = 1FilterCap 设置可创建过滤器总数的全局上限
filter-cap = 200FeeHistoryCap 设置可获取区块总数的全局上限
feehistory-cap = 100LogsCap 定义单次 eth_getLogs 查询可返回结果的最大数量。
logs-cap = 10000BlockRangeCap 定义 eth_getLogs 查询允许的最大区块范围。
block-range-cap = 10000HTTPTimeout 是 http json-rpc 服务器的读写超时时间。
http-timeout = ”30s”HTTPIdleTimeout 是 http json-rpc 服务器的空闲超时时间。
http-idle-timeout = “2m0s”当全局参数禁用时,AllowUnprotectedTxs 限制未受保护的(非 EIP155 签名)交易
只能通过节点的 RPC 提交。
allow-unprotected-txs = falseMaxOpenConnections 设置服务器监听器允许的最大并发连接数。
max-open-connections = 0EnableIndexer 为 EVM(以太坊交易)启用自定义交易索引器。
enable-indexer = falseMetricsAddress 定义 EVM 指标服务器绑定的地址。在 CLI 中传入 —metrics 以启用
Prometheus 指标路径:/debug/metrics/prometheus
metrics-address = “127.0.0.1:6065”单个批量请求中的最大请求数。
batch-request-limit = 1000批量调用可返回的最大字节数。
batch-response-max-size = 25000000在 debug 命名空间中启用性能分析
enable-profiling = false###############################################################################TLS 配置
###############################################################################[tls]Certificate path 定义 TLS 配置中 cert.pem 文件的路径。
certificate-path = ""Key path 定义 TLS 配置中 key.pem 文件的路径。
key-path = ""
<Note>
**第 130-260 行:** 为 Cosmos EVM 添加的 EVM 专用配置段
**第 1-129 行:** 为基础 Cosmos SDK 参数
**关键 EVM 段:**
- `[evm]`:EVM 运行时设置(第 645-670 行)
- `[evm.mempool]`:内存池配置(第 672-694 行,**v0.5.0 中新增**)
- `[json-rpc]`:以太坊 JSON-RPC 服务器(第 700-747 行)
- `[tls]`:TLS 配置(第 753-760 行)
**模板来源:**
- SDK 配置:`cosmos-sdk/server/config/toml.go`
- EVM 配置:`evm/server/config/toml.go`
</Note>
</Tab>
<Tab title="创世配置">
在链创世期间设置的区块链初始化参数。这些 EVM 专用参数用于配置 EVM 模块的初始状态和行为。
<Note>
**上下文**:这些参数会在链初始化时设置一次,通常无法在没有治理提案或网络升级的情况下更改。它们控制着 EVM 的基础行为和兼容性。
</Note>
```json 创世配置示例 expandable
{
"chain_id": "mychain-1",
"app_state": {
"evm": {
"params": {
"evm_denom": "atest",
"history_serve_window": 8192,
"active_static_precompiles": [
"0x0000000000000000000000000000000000000100",
"0x0000000000000000000000000000000000000400",
"0x0000000000000000000000000000000000000800",
"0x0000000000000000000000000000000000000801",
"0x0000000000000000000000000000000000000802",
"0x0000000000000000000000000000000000000804",
"0x0000000000000000000000000000000000000805"
],
"access_control": {
"create": {"access_type": "ACCESS_TYPE_PERMISSIONLESS"},
"call": {"access_type": "ACCESS_TYPE_PERMISSIONLESS"}
}
}
},
"feemarket": {
"params": {
"no_base_fee": false,
"base_fee_change_denominator": 8,
"elasticity_multiplier": 2,
"base_fee": "1000000000",
"min_gas_price": "0",
"min_gas_multiplier": "0.5"
}
}
},
"consensus": {
"params": {
"block": {
"max_bytes": "22020096",
"max_gas": "100000000"
}
}
}
}
evm_denom:用于 EVM 操作和 gas 支付的基础计价单位history_serve_window:要存储的历史区块哈希数量(EIP-2935)active_static_precompiles:已启用的预编译合约地址access_control:合约创建与执行的权限
base_fee:初始 EIP-1559 base fee 值base_fee_change_denominator:base fee 的调整速率elasticity_multiplier:触发费用变化的区块利用率阈值
max_gas:每个区块允许的最大 gas(对内存池配置至关重要)
生产环境验证者节点配置与安全注意事项。为什么这很重要:
关键安全提示: 验证者节点绝不能对公网暴露 RPC/API 端口。只有专用 RPC 节点(非验证者)才应对外提供公共流量服务。
验证者与 RPC 节点架构
生产网络应采用双层架构:验证者节点(私有)
用途: 仅用于出块和参与共识配置要求:- 禁用所有面向公网的服务
- 通过 persistent peers 将网络访问限制为仅允许其他验证者
- 不要启用 JSON-RPC 服务器
- 不要对公网暴露 API/gRPC 端口
- 使用防火墙规则阻止外部访问
app.toml 设置:[api]
enable = false # 禁用 REST API
[grpc]
enable = false # 禁用 gRPC,或仅绑定到 localhost
address = "localhost:9090"
[json-rpc]
enable = false # 关键:在验证者节点上保持 JSON-RPC 关闭
[evm]
max-tx-gas-wanted = 50000000 # 设置合理的 gas 上限
- DDoS 防护: 公开的 RPC 访问可能压垮验证者资源
- 资源耗尽: 高强度查询负载会影响区块生产
- 可用性: 验证者必须优先参与共识,而不是处理外部请求
- 安全性: 缩小攻击面可降低漏洞利用风险
- 罚没风险: 过载导致的停机可能引发罚没惩罚
RPC 节点(公开)
用途: 在不参与共识的情况下,对外提供公共 API/RPC 请求服务配置要求:- 启用 JSON-RPC、API 和 WebSocket 端点
- 使用负载均衡器分发流量
- 设置合适的速率限制和上限
- 可运行多个 RPC 节点以实现冗余
- 不存储验证者密钥
app.toml 设置:[api]
enable = true
address = "tcp://0.0.0.0:1317" # 绑定到所有网络接口
max-open-connections = 1000
[grpc]
enable = true
address = "0.0.0.0:9090"
[json-rpc]
enable = true
address = "0.0.0.0:8545"
ws-address = "0.0.0.0:8546"
api = "eth,net,web3,txpool"
# 设置资源限制
gas-cap = 50000000
filter-cap = 200
logs-cap = 10000
block-range-cap = 10000
max-open-connections = 500
batch-request-limit = 100
验证者安全检查清单
- 验证者节点已禁用 JSON-RPC
- 验证者节点的 API/gRPC 端点未对公网暴露
- 防火墙规则将验证者访问限制为仅允许已知对等节点
- 已部署独立的 RPC 节点用于公共访问
- 已为 RPC 节点冗余配置负载均衡器
- 已为验证者停机配置监控告警
- 已定期审计网络架构安全性
- 验证者密钥已安全存储(最好使用 HSM)
- SSH 访问已受限,并且仅允许基于密钥的登录
网络拓扑示例
公网
│
├─── 负载均衡器
│ │
│ ┌────┴────┬────────┐
│ │ │ │
│ RPC 节点 RPC 节点 RPC 节点
│ │ │ │
└────┴─────────┴────────┘
│
═══════════════════════════
私有验证者网络
═══════════════════════════
│
┌──────────┼──────────┐
│ │ │
验证者 1 验证者 2 验证者 3
(RPC 已禁用) (RPC 已禁用) (RPC 已禁用)
State Sync 注意事项: 如果验证者需要通过 state sync 快速同步,它们可以在私有网络分段中临时启用 RPC,以便彼此提供快照服务。这应当在独立的内部接口上完成,绝不能对公网暴露。
Configure EVM-specific settings in
~/.evmd/config/app.toml. This guide covers parameters unique to the EVM implementation.
- EVM
- Mempool
- JSON-RPC
- Runtime Flags
- Application Config
- Genesis Config
- Validator Nodes
EVM execution environment configuration.
Controls VM execution tracing for debugging.Valid Options:
""- Disabled (default)"json"- Full execution trace in JSON format, used by debug_traceTransaction RPC"struct"- Go struct format for programmatic processing"access_list"- Generates EIP-2930 access lists for gas optimization"markdown"- Human-readable format for manual analysis
server/config/config.go:139
Implementation: x/vm/keeper/state_transition.go:150-157Limits gas for transactions in CheckTx mode to prevent DoS attacks.When set to 0, any gas amount is accepted which can lead to mempool spam.Source:
server/config/config.go:141
Testnet Default: Set by evmd/cmd/evmd/cmd/testnet.go:303Enables SHA3 preimage recording in the VM for debugging tools to reverse hash lookups.Increases memory usage when enabled.Source:
server/config/config.go:143EIP-155 replay protection chain ID.Must match the expected network chain ID. Used for transaction signing validation.Source:
server/config/config.go:145
Used in: x/vm/genesis.go:22Minimum priority fee (tip) required for transaction inclusion in mempool.Transactions with tips below this value may be rejected. Set to 0 to disable filtering.Flag:
EVMMinTip
Source: server/config/config.go:150
Type: Converted to uint256.Int internallyAddress for go-ethereum metrics server.Emits EVM-specific metrics in Prometheus format on a separate server from Cosmos SDK metrics.Source:
server/config/config.go:152
New in: v0.5.0EVM mempool configuration for transaction pool management.Low-Resource Node:Strict Spam Protection:
New in v0.5.0: Mempool configuration is now fully exposed in
app.toml and can be adjusted without code changes. Previously, these settings were hardcoded.Minimum gas price to enforce for acceptance into the pool (in wei).Transactions with gas prices below this value are rejected from the mempool.Source:
server/config/config.go:160
Validation: Must be at least 1Minimum price bump percentage to replace an already existing transaction (nonce).When replacing a transaction with the same nonce, the new transaction must have a gas price at least this percentage higher.Source:
server/config/config.go:162
Example: 10 = require 10% higher gas price
Validation: Must be at least 1Number of executable transaction slots guaranteed per account.Each account is guaranteed to have this many pending transactions in the executable queue.Source:
server/config/config.go:164
Validation: Must be at least 1Maximum number of executable transaction slots for all accounts.Total capacity for all pending executable transactions across all accounts (4096 + 1024 = 5120).Source:
server/config/config.go:166
Validation: Must be at least 1Maximum number of non-executable transaction slots permitted per account.For transactions with gaps in nonce sequence (future transactions).Source:
server/config/config.go:168
Validation: Must be at least 1Maximum number of non-executable transaction slots for all accounts.Total capacity for queued (non-executable) transactions across all accounts.Source:
server/config/config.go:170
Validation: Must be at least 1Maximum amount of time non-executable transactions are queued.Transactions that remain non-executable longer than this duration are removed from the mempool.Source:
server/config/config.go:172
Format: Go duration string (e.g., "1h30m", "30m0s", "24h0m0s")
Validation: Must be at least 1nsConfiguration Examples
High-Throughput Chain:[evm.mempool]
global-slots = 10240
global-queue = 2048
price-limit = 100000000 # 0.1 gwei minimum
lifetime = "6h0m0s"
[evm.mempool]
global-slots = 2048
global-queue = 512
lifetime = "1h0m0s"
account-slots = 8
[evm.mempool]
price-limit = 1000000000 # 1 gwei minimum
price-bump = 25 # 25% replacement cost
lifetime = "30m0s"
account-slots = 4
Ethereum JSON-RPC server configuration.
Core Settings
Enable the JSON-RPC server.Must be
true for Ethereum compatibility.Source: server/config/config.go:169
Testnet configuration: evmd/cmd/evmd/cmd/testnet.go:303HTTP server bind address using standard Ethereum RPC port.Source:
server/config/config.go:153WebSocket server address for eth_subscribe methods.Source:
server/config/config.go:155
Implementation: rpc/stream/rpc.goJSON-RPC namespaces to enable.Available namespaces:
web3, eth, personal, net, txpool, debug, minerSource: server/config/config.go:151
Namespace implementations: rpc/namespaces/Allowed CORS origins for WebSocket connections.Source:
server/config/config.go:195Resource Limits
Gas limit for eth_call/estimateGas operations (25M gas).Set to 0 for unlimited.Source:
server/config/config.go:157
Enforced: rpc/namespaces/ethereum/eth/api.go:1039Maximum transaction fee cap in ether for eth_sendTransaction.Source:
server/config/config.go:163
Enforced: rpc/namespaces/ethereum/eth/api.go:1586Maximum concurrent filters per connection.Source:
server/config/config.go:165
Implementation: rpc/namespaces/ethereum/eth/filters/Maximum blocks that can be fetched for eth_feeHistory.Source:
server/config/config.go:167Maximum logs returned from a single eth_getLogs query.Source:
server/config/config.go:171
Enforced: rpc/namespaces/ethereum/eth/filters/api.go:442Maximum block range allowed for eth_getLogs queries.Source:
server/config/config.go:173
Enforced: rpc/namespaces/ethereum/eth/filters/filter.go:268Connection Settings
Maximum number of requests in a batch (go-ethereum standard).Source:
server/config/config.go:182Maximum bytes returned from a batched call (25MB).Source:
server/config/config.go:184Read/write timeout for HTTP JSON-RPC server.Source:
server/config/config.go:175Idle timeout for HTTP connections.Source:
server/config/config.go:177Maximum simultaneous connections for the server listener.Set to 0 for unlimited.Source:
server/config/config.go:187Global timeout for eth_call operations.Source:
server/config/config.go:161Features
Enable custom transaction indexer for EVM transactions.Required for:
eth_getLogs, eth_getTransactionReceiptSource: server/config/config.go:189
Testnet default: evmd/cmd/evmd/cmd/testnet.go:303Enable pprof endpoints in debug namespace.Source:
server/config/config.go:197Prometheus metrics server address.Metrics path:
/debug/metrics/prometheusSource: server/config/config.go:191Security
Allow non-EIP155 signed transactions to be submitted.Source:
server/config/config.go:180Allow insecure account unlocking when personal namespace is enabled.Source:
server/config/config.go:159CLI flags and environment variables for runtime configuration. These parameters can be set via command line or environment variables to override configuration file settings.
Context: These are EVM-specific runtime parameters that complement the standard Cosmos SDK flags. They control chain initialization and runtime behavior specific to EVM functionality.
Cosmos SDK chain identifier for transaction signing and network identification.CLI Flag:
--chain-id
Environment: EVMD_CHAIN_ID
Usage: evmd start --chain-id mychain-1EIP-155 replay protection chain ID for Ethereum compatibility. Must be unique across all EVM networks.CLI Flag:
--evm.evm-chain-id
Environment: EVMD_EVM_CHAIN_ID
Usage: evmd start --evm.evm-chain-id 9000
Config Alternative: Set in app.toml under [evm] evm-chain-idBase denomination for native token transactions and staking.CLI Flag:
--denom
Environment: EVMD_DENOM
Usage: evmd init mynode --denom mytokenMinimum priority fee (in wei) required for mempool inclusion.CLI Flag:
--evm.min-tip
Environment: EVMD_EVM_MIN_TIP
Usage: evmd start --evm.min-tip 1000000000
Config Alternative: Set in app.toml under [evm] min-tipMaximum gas limit for transactions in CheckTx validation mode.CLI Flag:
--evm.max-tx-gas-wanted
Environment: EVMD_MAX_TX_GAS_WANTED
Usage: evmd start --evm.max-tx-gas-wanted 50000000
Config Alternative: Set in app.toml under [evm] max-tx-gas-wantedComplete
app.toml with EVM-specific sections highlighted.Complete Application Configuration
# This is a TOML config file.
# For more information, see https://github.com/toml-lang/toml
###############################################################################
### Base Configuration ###
###############################################################################
# The minimum gas prices a validator is willing to accept for processing a
# transaction. A transaction's fees must meet the minimum of any denomination
# specified in this config (e.g. 0.25token1,0.0001token2).
minimum-gas-prices = "0atest"
# The maximum gas a query coming over rest/grpc may consume.
# If this is set to zero, the query can consume an unbounded amount of gas.
query-gas-limit = "0"
# default: the last 362880 states are kept, pruning at 10 block intervals
# nothing: all historic states will be saved, nothing will be deleted (i.e. archiving node)
# everything: 2 latest states will be kept; pruning at 10 block intervals.
# custom: allow pruning options to be manually specified through 'pruning-keep-recent', and 'pruning-interval'
pruning = "default"
# These are applied if and only if the pruning strategy is custom.
pruning-keep-recent = "0"
pruning-interval = "0"
# HaltHeight contains a non-zero block height at which a node will gracefully
# halt and shutdown that can be used to assist upgrades and testing.
#
# Note: Commitment of state will be attempted on the corresponding block.
halt-height = 0
# HaltTime contains a non-zero minimum block time (in Unix seconds) at which
# a node will gracefully halt and shutdown that can be used to assist upgrades
# and testing.
#
# Note: Commitment of state will be attempted on the corresponding block.
halt-time = 0
# MinRetainBlocks defines the minimum block height offset from the current
# block being committed, such that all blocks past this offset are pruned
# from CometBFT. It is used as part of the process of determining the
# ResponseCommit.RetainHeight value during ABCI Commit. A value of 0 indicates
# that no blocks should be pruned.
#
# This configuration value is only responsible for pruning CometBFT blocks.
# It has no bearing on application state pruning which is determined by the
# "pruning-*" configurations.
#
# Note: CometBFT block pruning is dependant on this parameter in conjunction
# with the unbonding (safety threshold) period, state pruning and state sync
# snapshot parameters to determine the correct minimum value of
# ResponseCommit.RetainHeight.
min-retain-blocks = 0
# InterBlockCache enables inter-block caching.
inter-block-cache = true
# IndexEvents defines the set of events in the form {eventType}.{attributeKey},
# which informs CometBFT what to index. If empty, all events will be indexed.
#
# Example:
# ["message.sender", "message.recipient"]
index-events = []
# IavlCacheSize set the size of the iavl tree cache (in number of nodes).
iavl-cache-size = 781250
# IAVLDisableFastNode enables or disables the fast node feature of IAVL.
# Default is false.
iavl-disable-fastnode = false
# AppDBBackend defines the database backend type to use for the application and snapshots DBs.
# An empty string indicates that a fallback will be used.
# The fallback is the db_backend value set in CometBFT's config.toml.
app-db-backend = ""
###############################################################################
### Telemetry Configuration ###
###############################################################################
[telemetry]
# Prefixed with keys to separate services.
service-name = ""
# Enabled enables the application telemetry functionality. When enabled,
# an in-memory sink is also enabled by default. Operators may also enabled
# other sinks such as Prometheus.
enabled = true
# Enable prefixing gauge values with hostname.
enable-hostname = false
# Enable adding hostname to labels.
enable-hostname-label = false
# Enable adding service to labels.
enable-service-label = false
# PrometheusRetentionTime, when positive, enables a Prometheus metrics sink.
prometheus-retention-time = 1000000000000
# GlobalLabels defines a global set of name/value label tuples applied to all
# metrics emitted using the wrapper functions defined in telemetry package.
#
# Example:
# [["chain_id", "cosmoshub-1"]]
global-labels = [
]
# MetricsSink defines the type of metrics sink to use.
metrics-sink = ""
# StatsdAddr defines the address of a statsd server to send metrics to.
# Only utilized if MetricsSink is set to "statsd" or "dogstatsd".
statsd-addr = ""
# DatadogHostname defines the hostname to use when emitting metrics to
# Datadog. Only utilized if MetricsSink is set to "dogstatsd".
datadog-hostname = ""
###############################################################################
### API Configuration ###
###############################################################################
[api]
# Enable defines if the API server should be enabled.
enable = true
# Swagger defines if swagger documentation should automatically be registered.
swagger = false
# Address defines the API server to listen on.
address = "tcp://localhost:1317"
# MaxOpenConnections defines the number of maximum open connections.
max-open-connections = 1000
# RPCReadTimeout defines the CometBFT RPC read timeout (in seconds).
rpc-read-timeout = 10
# RPCWriteTimeout defines the CometBFT RPC write timeout (in seconds).
rpc-write-timeout = 0
# RPCMaxBodyBytes defines the CometBFT maximum request body (in bytes).
rpc-max-body-bytes = 1000000
# EnableUnsafeCORS defines if CORS should be enabled (unsafe - use it at your own risk).
enabled-unsafe-cors = false
###############################################################################
### gRPC Configuration ###
###############################################################################
[grpc]
# Enable defines if the gRPC server should be enabled.
enable = true
# Address defines the gRPC server address to bind to.
address = "localhost:9090"
# MaxRecvMsgSize defines the max message size in bytes the server can receive.
# The default value is 10MB.
max-recv-msg-size = "10485760"
# MaxSendMsgSize defines the max message size in bytes the server can send.
# The default value is math.MaxInt32.
max-send-msg-size = "2147483647"
###############################################################################
### gRPC Web Configuration ###
###############################################################################
[grpc-web]
# GRPCWebEnable defines if the gRPC-web should be enabled.
# NOTE: gRPC must also be enabled, otherwise, this configuration is a no-op.
# NOTE: gRPC-Web uses the same address as the API server.
enable = true
###############################################################################
### State Sync Configuration ###
###############################################################################
# State sync snapshots allow other nodes to rapidly join the network without replaying historical
# blocks, instead downloading and applying a snapshot of the application state at a given height.
[state-sync]
# snapshot-interval specifies the block interval at which local state sync snapshots are
# taken (0 to disable).
snapshot-interval = 0
# snapshot-keep-recent specifies the number of recent snapshots to keep and serve (0 to keep all).
snapshot-keep-recent = 2
###############################################################################
### State Streaming ###
###############################################################################
# Streaming allows nodes to stream state to external systems.
[streaming]
# streaming.abci specifies the configuration for the ABCI Listener streaming service.
[streaming.abci]
# List of kv store keys to stream out via gRPC.
# The store key names MUST match the module's StoreKey name.
#
# Example:
# ["acc", "bank", "gov", "staking", "mint"[,...]]
# ["*"] to expose all keys.
keys = []
# The plugin name used for streaming via gRPC.
# Streaming is only enabled if this is set.
# Supported plugins: abci
plugin = ""
# stop-node-on-err specifies whether to stop the node on message delivery error.
stop-node-on-err = true
###############################################################################
### Mempool ###
###############################################################################
[mempool]
# Setting max-txs to 0 will allow for a unbounded amount of transactions in the mempool.
# Setting max_txs to negative 1 (-1) will disable transactions from being inserted into the mempool (no-op mempool).
# Setting max_txs to a positive number (> 0) will limit the number of transactions in the mempool, by the specified amount.
#
# Note, this configuration only applies to SDK built-in app-side mempool
# implementations.
max-txs = -1
###############################################################################
### EVM Configuration ###
###############################################################################
[evm]
# Tracer defines the 'vm.Tracer' type that the EVM will use when the node is run in
# debug mode. To enable tracing use the '--evm.tracer' flag when starting your node.
# Valid types are: json|struct|access_list|markdown
tracer = ""
# MaxTxGasWanted defines the gas wanted for each eth tx returned in ante handler in check tx mode.
max-tx-gas-wanted = 0
# EnablePreimageRecording enables tracking of SHA3 preimages in the VM
cache-preimage = false
# EVMChainID is the EIP-155 compatible replay protection chain ID. This is separate from the Cosmos chain ID.
evm-chain-id = 262144
# MinTip defines the minimum priority fee for the mempool.
min-tip = 0
# Geth metrics server address
geth-metrics-address = "127.0.0.1:8100"
# Mempool configuration for EVM transactions
[evm.mempool]
# PriceLimit is the minimum gas price to enforce for acceptance into the pool (in wei)
price-limit = 1
# PriceBump is the minimum price bump percentage to replace an already existing transaction (nonce)
price-bump = 10
# AccountSlots is the number of executable transaction slots guaranteed per account
account-slots = 16
# GlobalSlots is the maximum number of executable transaction slots for all accounts
global-slots = 5120
# AccountQueue is the maximum number of non-executable transaction slots permitted per account
account-queue = 64
# GlobalQueue is the maximum number of non-executable transaction slots for all accounts
global-queue = 1024
# Lifetime is the maximum amount of time non-executable transaction are queued
lifetime = "3h0m0s"
###############################################################################
### JSON RPC Configuration ###
###############################################################################
[json-rpc]
# Enable defines if the JSONRPC server should be enabled.
enable = true
# Address defines the EVM RPC HTTP server address to bind to.
address = "127.0.0.1:8545"
# Address defines the EVM WebSocket server address to bind to.
ws-address = "127.0.0.1:8546"
# WSOrigins defines the allowed origins for WebSocket connections.
# Example: ["localhost", "127.0.0.1", "myapp.example.com"]
ws-origins = ["127.0.0.1", "localhost"]
# API defines a list of JSON-RPC namespaces that should be enabled
# Example: "eth,txpool,personal,net,debug,web3"
api = "eth,net,web3"
# GasCap sets a cap on gas that can be used in eth_call/estimateGas (0=infinite). Default: 25,000,000.
gas-cap = 25000000
# Allow insecure account unlocking when account-related RPCs are exposed by http
allow-insecure-unlock = true
# EVMTimeout is the global timeout for eth_call. Default: 5s.
evm-timeout = "5s"
# TxFeeCap is the global tx-fee cap for send transaction. Default: 1eth.
txfee-cap = 1
# FilterCap sets the global cap for total number of filters that can be created
filter-cap = 200
# FeeHistoryCap sets the global cap for total number of blocks that can be fetched
feehistory-cap = 100
# LogsCap defines the max number of results can be returned from single 'eth_getLogs' query.
logs-cap = 10000
# BlockRangeCap defines the max block range allowed for 'eth_getLogs' query.
block-range-cap = 10000
# HTTPTimeout is the read/write timeout of http json-rpc server.
http-timeout = "30s"
# HTTPIdleTimeout is the idle timeout of http json-rpc server.
http-idle-timeout = "2m0s"
# AllowUnprotectedTxs restricts unprotected (non EIP155 signed) transactions to be submitted via
# the node's RPC when the global parameter is disabled.
allow-unprotected-txs = false
# MaxOpenConnections sets the maximum number of simultaneous connections
# for the server listener.
max-open-connections = 0
# EnableIndexer enables the custom transaction indexer for the EVM (ethereum transactions).
enable-indexer = false
# MetricsAddress defines the EVM Metrics server address to bind to. Pass --metrics in CLI to enable
# Prometheus metrics path: /debug/metrics/prometheus
metrics-address = "127.0.0.1:6065"
# Maximum number of requests in a batch.
batch-request-limit = 1000
# Maximum number of bytes returned from a batched call.
batch-response-max-size = 25000000
# Enabled profiling in the debug namespace
enable-profiling = false
###############################################################################
### TLS Configuration ###
###############################################################################
[tls]
# Certificate path defines the cert.pem file path for the TLS configuration.
certificate-path = ""
# Key path defines the key.pem file path for the TLS configuration.
key-path = ""
Lines (130-260): are EVM-specific configuration sections added by Cosmos EVMLines (1-129): are Base Cosmos SDK parametersKey EVM sections:
[evm]: EVM runtime settings (lines 645-670)[evm.mempool]: Mempool configuration (lines 672-694, new in v0.5.0)[json-rpc]: Ethereum JSON-RPC server (lines 700-747)[tls]: TLS configuration (lines 753-760)
- SDK config:
cosmos-sdk/server/config/toml.go - EVM config:
evm/server/config/toml.go
Blockchain initialization parameters set during chain genesis. These EVM-specific parameters configure the initial state and behavior of the EVM module.EVM-Specific Parameters:
Context: These parameters are set once during chain initialization and typically cannot be changed without governance proposals or network upgrades. They control fundamental EVM behavior and compatibility.
Genesis Configuration Example
{
"chain_id": "mychain-1",
"app_state": {
"evm": {
"params": {
"evm_denom": "atest",
"history_serve_window": 8192,
"active_static_precompiles": [
"0x0000000000000000000000000000000000000100",
"0x0000000000000000000000000000000000000400",
"0x0000000000000000000000000000000000000800",
"0x0000000000000000000000000000000000000801",
"0x0000000000000000000000000000000000000802",
"0x0000000000000000000000000000000000000804",
"0x0000000000000000000000000000000000000805"
],
"access_control": {
"create": {"access_type": "ACCESS_TYPE_PERMISSIONLESS"},
"call": {"access_type": "ACCESS_TYPE_PERMISSIONLESS"}
}
}
},
"feemarket": {
"params": {
"no_base_fee": false,
"base_fee_change_denominator": 8,
"elasticity_multiplier": 2,
"base_fee": "1000000000",
"min_gas_price": "0",
"min_gas_multiplier": "0.5"
}
}
},
"consensus": {
"params": {
"block": {
"max_bytes": "22020096",
"max_gas": "100000000"
}
}
}
}
evm_denom: Base denomination for EVM operations and gas paymentshistory_serve_window: Number of historical block hashes to store (EIP-2935)active_static_precompiles: Enabled precompile contract addressesaccess_control: Permissions for contract creation and execution
base_fee: Initial EIP-1559 base fee valuebase_fee_change_denominator: Rate of base fee adjustmentelasticity_multiplier: Block utilization threshold for fee changes
max_gas: Maximum gas per block (critical for mempool configuration)
Production validator node configuration and security considerations.Why this matters:
Critical Security Notice: Validator nodes should NEVER expose RPC/API ports publicly. Only dedicated RPC nodes (non-validators) should serve public traffic.
Validator vs RPC Node Architecture
Production networks should use a two-tier architecture:Validator Nodes (Private)
Purpose: Block production and consensus participation onlyConfiguration Requirements:- Disable all public-facing services
- Restrict network access to other validators via persistent peers
- Do NOT enable JSON-RPC server
- Do NOT expose API/gRPC ports publicly
- Use firewall rules to block external access
app.toml settings:[api]
enable = false # Disable REST API
[grpc]
enable = false # Disable gRPC or bind to localhost only
address = "localhost:9090"
[json-rpc]
enable = false # CRITICAL: Keep JSON-RPC disabled on validators
[evm]
max-tx-gas-wanted = 50000000 # Set reasonable gas limits
- DDoS Protection: Public RPC access can overwhelm validator resources
- Resource Exhaustion: Heavy query load impacts block production
- Uptime: Validators must prioritize consensus participation over serving requests
- Security: Reduced attack surface for exploits
- Slashing Risk: Downtime from overload can lead to slashing penalties
RPC Nodes (Public)
Purpose: Serve public API/RPC requests without participating in consensusConfiguration Requirements:- Enable JSON-RPC, API, and WebSocket endpoints
- Use load balancers for distribution
- Set appropriate rate limits and caps
- Can run multiple RPC nodes for redundancy
- No validator keys stored
app.toml settings:[api]
enable = true
address = "tcp://0.0.0.0:1317" # Bind to all interfaces
max-open-connections = 1000
[grpc]
enable = true
address = "0.0.0.0:9090"
[json-rpc]
enable = true
address = "0.0.0.0:8545"
ws-address = "0.0.0.0:8546"
api = "eth,net,web3,txpool"
# Set resource limits
gas-cap = 50000000
filter-cap = 200
logs-cap = 10000
block-range-cap = 10000
max-open-connections = 500
batch-request-limit = 100
Validator Security Checklist
- JSON-RPC is disabled on validator nodes
- API/gRPC endpoints not exposed publicly on validators
- Firewall rules restrict validator access to known peers only
- Separate RPC nodes deployed for public access
- Load balancers configured for RPC node redundancy
- Monitoring alerts for validator downtime
- Regular security audits of network architecture
- Validator keys stored securely (preferably HSM)
- SSH access restricted and key-based only
Network Topology Example
Public Internet
│
├─── Load Balancer
│ │
│ ┌────┴────┬────────┐
│ │ │ │
│ RPC Node RPC Node RPC Node
│ │ │ │
└────┴─────────┴────────┘
│
═══════════════════════════
Private Validator Network
═══════════════════════════
│
┌──────────┼──────────┐
│ │ │
Validator 1 Validator 2 Validator 3
(RPC disabled) (RPC disabled) (RPC disabled)
State Sync Consideration: If validators need to quickly sync using state sync, they may temporarily enable RPC on a private network segment to serve snapshots to each other. This should be done on a separate internal interface, never exposed publicly.