17 Commits

Author SHA1 Message Date
5d8aaa769d feat!: Expose consensus debug port, restart EN on config file change (#42)
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
## What 

Subj

## Why 

QoL

## Checklist

<!-- Check your PR fulfills the following items. -->
<!-- For draft PRs check the boxes as you complete them. -->

- [x] PR title corresponds to the body of PR (we generate changelog
entries from PRs).
- [ ] Documentation comments have been added / updated.
2025-04-25 16:54:26 +02:00
17d9ecd1ce feat: (fake release trigger) Bump default EN to v27.2.0 (#41)
## What 

Subj

## Why 

Due to incorrect repo merge settings it was allowed to merge without
squash so commits went to main without semver prefixes and did not
trigger release

## Checklist

<!-- Check your PR fulfills the following items. -->
<!-- For draft PRs check the boxes as you complete them. -->

- [x] PR title corresponds to the body of PR (we generate changelog
entries from PRs).
- [ ] Documentation comments have been added / updated.
2025-04-25 12:23:39 +02:00
5071bb3423 Merge pull request #39 from matter-labs/update_27.2.0
feat: update default EN version to 27.2.0
2025-04-25 12:05:28 +02:00
fa4f00a62d Merge pull request #40 from matter-labs/consensus-debug-port
feat: Consensus debug config
2025-04-25 12:04:08 +02:00
f3ce6ce204 feat: Consensus debug config 2025-04-25 11:51:05 +02:00
cd5df40065 update EN versio to 27.2.0 2025-04-24 13:08:43 +03:00
4bd3805af1 Merge pull request #38 from matter-labs/docs
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
chore(docs): Update link to EN mainnet DB backup
2024-12-16 17:45:26 +07:00
8006ed9328 chore(docs): Update link to EN mainnet backup 2024-12-16 17:38:02 +07:00
c497fc0982 Merge pull request #37 from matter-labs/yorik-patch-1
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
feat: Fake PR to force release
2024-12-04 15:49:30 +01:00
57f3fb74e4 feat: Fake PR to force release 2024-12-04 15:47:39 +01:00
aa018348d8 Merge pull request #36 from matter-labs/gprusak-rate-limit
feat(consensus): bumped inbound connections limit
2024-12-04 15:04:28 +01:00
b8e3b89cf5 bumped inbound connections limit 2024-12-03 17:47:46 +01:00
d276d7b290 Merge pull request #35 from matter-labs/backup-user
Some checks failed
Release / Release (push) Has been cancelled
CI / Lint (push) Has been cancelled
CI / Ansible lint (push) Has been cancelled
feat: Added user with backup permissions only
2024-11-27 15:45:36 +01:00
60333c40da feat: Added user with backup permissions only 2024-11-27 15:24:20 +01:00
2eb2b1f6d4 feat: Added user with backup permissions only 2024-11-27 15:12:12 +01:00
69777ac4e8 feat: Added user with backup permissions only 2024-11-27 15:08:46 +01:00
46e2a6e0e4 feat: Added user with backup permissions only 2024-11-27 14:51:33 +01:00
9 changed files with 91 additions and 33 deletions

View File

@ -99,10 +99,10 @@ Basic auth secret can be generated by `htpasswd` and `sed` for interpolation:
2. Prepare the latest database backup on your host. you can download it from our public GCS buckets:
Skip this step if you are recovering from a snapshot!
* [Era Mainnet latest dump](https://storage.googleapis.com/zksync-era-mainnet-external-node-backups/external_node_latest.pgdump)
* [Era Mainnet latest dump](https://en-backups.matterlabs.dev/)
* [Era Sepolia Testnet latest dump](https://storage.googleapis.com/zksync-era-testnet-sepolia-external-node-backups/external_node_latest.pgdump)
Downloaded dump file should be placed into `{{ storage_directory }}/pg_backups` directory (`/usr/src/en/pg_backups` by default)
Downloaded dump, if needed, should be unarchived and named `external_node_latest.pgdump`. File should be placed into `{{ storage_directory }}/pg_backups` directory (`/usr/src/en/pg_backups` by default).
3. **OPTIONAL**: If you already have running node, you can copy its tree and state directory to a new host's `{{ storage_directory }}/db`. (`/usr/src/en/db` by default)
Skip this step if you are recovering from a snapshot!

View File

@ -11,7 +11,7 @@ docker_compose_version: "v2.23.0"
# Versions of External Node and 3rd party components
traefik_version: 2.11
postgres_version: 14
external_node_version: 24.26.0
external_node_version: 27.2.0
external_node_raw_docker_tag: ""
vmagent_version: 1.100.1
cadvisor_version: 0.47.2
@ -64,6 +64,9 @@ postgres_replica_user_password: ""
postgres_replica_auth_method: "scram-sha-256"
postgres_replication_bind_address: ""
postgres_replica_address: ""
backup_db_user: ""
backup_db_password: ""
backup_db_name: ""
# Enable TLS for traefik
enable_tls: false
@ -86,6 +89,10 @@ enable_consensus: false
consensus_secrets_file: ""
consensus_port: 3054
consensus_outbound: []
consensus_debug_port: 5000
enable_consensus_debug_port: false
expose_consensus_debug_port: false
consensus_debug_port_path_prefix: "/consensus_debug"
# External Node and database options
database_name: ""

View File

@ -8,16 +8,16 @@ To run this playbook, first install dependencies
```shell
ansible-galaxy install -r requirements.yml
```
```
and then you can run the playbook using
```shell
ansible-playbook playbook.yml -i hosts.ini -K
```
```
To see logs you can use
```shell
docker logs en-external_node-1
```
docker logs en-external_node-1
```

View File

@ -8,6 +8,8 @@ roles:
version: "v3.3.0"
collections:
- name: community.docker
version: 4.5.2
- name: community.general
version: 8.4.0
# Collection for the replication only.

8
handlers/main.yml Normal file
View File

@ -0,0 +1,8 @@
---
- name: Restart external-node service
community.docker.docker_compose_v2:
project_src: "{{ configuration_directory }}"
files: "{{ docker_compose_files }}"
state: restarted
services:
- external_node

View File

@ -54,6 +54,13 @@
msg: "Variable '{{ item }}' is empty"
when: vars[item] == ""
with_items: "{{ en_required_variables }}"
- name: "Verify consensus debug port configuration"
ansible.builtin.fail:
msg: "Cannot expose consensus debug port (expose_consensus_debug_port=true) if it is not enabled (enable_consensus_debug_port=false)."
when:
- enable_consensus
- expose_consensus_debug_port
- not enable_consensus_debug_port
- name: Create main configs
ansible.builtin.template:
@ -67,6 +74,8 @@
dest: "{{ configuration_directory }}/external_node.env"
- src: "templates/postgres.env.j2"
dest: "{{ configuration_directory }}/postgres.env"
loop_control:
label: "{{ item.dest }}"
- name: Create restore script
register: restore_dump_script
@ -99,6 +108,7 @@
src: "templates/consensus_config.yaml.j2"
dest: "{{ configuration_directory }}/consensus_config.yaml"
mode: '0644'
notify: Restart external-node service
- name: Decrypt consensus_secrets
when: enable_consensus
@ -107,24 +117,17 @@
dest: "{{ configuration_directory }}/consensus_secrets.yaml"
decrypt: true
mode: '0600'
notify: Restart external-node service
- name: Run docker-compose without monitoring
when: not enable_monitoring
ansible.builtin.shell:
cmd: nohup docker compose -f docker-compose.yaml up -d </dev/null >/dev/null 2>&1 &
chdir: "{{ configuration_directory }}"
changed_when: false
- name: Set docker compose files list
ansible.builtin.set_fact:
docker_compose_files: "{{ ['docker-compose.yaml'] + (['monitoring.yaml'] if enable_monitoring else []) }}"
- name: Run docker-compose with monitoring
when: enable_monitoring and (not restore_dump_script.changed)
ansible.builtin.shell:
cmd: nohup docker compose -f monitoring.yaml -f docker-compose.yaml up -d </dev/null >/dev/null 2>&1 &
chdir: "{{ configuration_directory }}"
changed_when: false
- name: Run docker-compose with monitoring with recreation
when: enable_monitoring and restore_dump_script.changed
ansible.builtin.shell:
cmd: nohup docker compose -f monitoring.yaml -f docker-compose.yaml up -d --force-recreate </dev/null >/dev/null 2>&1 &
chdir: "{{ configuration_directory }}"
changed_when: false
- name: Run docker compose services (non-blocking)
community.docker.docker_compose_v2:
project_src: "{{ configuration_directory }}"
files: "{{ docker_compose_files }}"
state: present
pull: "{{ docker_pull_policy | default('missing') }}"
recreate: "{{ 'always' if restore_dump_script.changed else 'auto' }}"
wait: false

View File

@ -40,3 +40,21 @@
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
query: "SELECT pg_reload_conf()"
- name: Create postgres backup user
community.postgresql.postgresql_user:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
name: "{{ backup_db_user }}"
password: "{{ backup_db_password }}"
- name: Grant role pg_read_all_data to backup user
community.postgresql.postgresql_membership:
login_host: "{{ postgres_replication_bind_address }}"
login_user: "{{ database_username }}"
login_password: "{{ database_password }}"
group: pg_read_all_data
target_roles:
- "{{ backup_db_user }}"
state: present

View File

@ -1,9 +1,13 @@
server_addr: '0.0.0.0:3054'
public_addr: '{{ ansible_default_ipv4.address }}:{{ consensus_port }}'
max_payload_size: 5000000
gossip_dynamic_inbound_limit: 100
gossip_static_outbound:
{% for item in consensus_outbound %}
- key: {{ item.key }}
addr: {{ item.addr }}
{% endfor %}
gossip_dynamic_inbound_limit: 200
{% if enable_consensus_debug_port %}
debug_page_addr: "0.0.0.0:{{ consensus_debug_port }}"
{% endif %}
rpc_config:
get_block_rate:
burst: 5
refresh: # 0.2s
seconds: 0
nanos: 200000000

View File

@ -80,7 +80,6 @@ services:
- "traefik.http.routers.external_node_main.entrypoints=web"
{% endif %}
- "traefik.http.routers.external_node_main.service=external_node_main"
- "traefik.http.services.external_node_health.loadbalancer.server.port={{ healthcheck_port }}"
- "traefik.http.routers.external_node_health.rule=PathPrefix(`/`)"
- "traefik.http.routers.external_node_health.entrypoints=external_node_health"
@ -94,6 +93,20 @@ services:
- "traefik.tcp.routers.external_node_consensus.rule=HostSNI(`*`)"
- "traefik.tcp.routers.external_node_consensus.entrypoints=external_node_consensus"
- "traefik.tcp.routers.external_node_consensus.service=external_node_consensus"
{% endif %}
{% if enable_consensus and expose_consensus_debug_port %}
- "traefik.http.services.external_node_consensus_debug.loadbalancer.server.port={{ consensus_debug_port }}"
- "traefik.http.routers.external_node_consensus_debug.rule=PathPrefix(`{{ consensus_debug_port_path_prefix }}`)"
{% if enable_tls %}
- "traefik.http.routers.external_node_consensus_debug.entrypoints=websecure"
- "traefik.http.routers.external_node_consensus_debug.tls.certresolver=myresolver"
{% else %}
- "traefik.http.routers.external_node_consensus_debug.entrypoints=web"
{% endif %}
- "traefik.http.routers.external_node_consensus_debug.service=external_node_consensus_debug"
{% if enable_basic_auth %}
- "traefik.http.routers.external_node_consensus_debug.middlewares=external_node_auth"
{% endif %}
{% endif %}
expose:
- {{ rpc_http_port }}
@ -102,6 +115,9 @@ services:
- {{ metrics_port }}
{% if enable_consensus %}
- {{ consensus_port }}
{% if expose_consensus_debug_port %}
- {{ consensus_debug_port }}
{% endif %}
{% endif %}
environment:
ZKSYNC_HOME: "/"