The transit script is an utility used by node operators to upload and download relevant data before and after a Flow spork. It is used to download the root snapshot after a spork. Additionally, for a consensus node, it is used to upload transit keys and to submit root block votes.
The server token is needed with the -t flag for all commands. It authenticates the script to the server so that only trusted parties with the token may upload their node info and be included in the bootstrap data.
$ transit pull -t ${server-token} -d ${bootstrap-dir} -r ${flow-role}After bootstrapping, running transit pull will:
-
Fetch the following files:
root-block.jsonnode-infos.pub.jsonroot-protocol-snapshot.jsonroot-checkpoint(only for execution nodes)random-beacon.priv.json.<id>.enc(only for consensus nodes)
-
Decrypt
random-beacon.priv.json.<id>.encusing the transit keys (only for consensus nodes)random-beacon.priv.json
The transit script also has wrap for the other end of the connection. This function takes a private random-beacon key and wraps it with the corresponding transit key, which can then be sent back to the node.
$ transit wrap -i ${ID} -r ${flow-role}The wrap function:
- Takes in
random-beacon.priv.jsonand producesrandom-beacon.priv.json.<id>.enc
- Uploads
random-beacon.priv.json.<id>.encto the server
The transit script has four commands applicable to consensus nodes:
$ transit pull-root-block -t ${server-token} -d ${bootstrap-dir}
$ transit generate-root-block-vote -t ${server-token} -d ${bootstrap-dir}
$ transit push-root-block-vote -t ${server-token} -d ${bootstrap-dir} -v ${vote-file}
$ transit push-transit-keys -t ${server-token} -d ${bootstrap-dir}Running transit pull-root-block will perform the following actions:
- Fetch the root block for the upcoming spork and write it to
<bootstrap-dir>/public-root-information/root-block.json - Fetch the random beacon key
random-beacon.priv.json.<id>.encand decrypt it using the transit keys
After the root block and random beacon key have been fetched, running transit generate-root-block-vote will:
- Create a combined signature over the root block using the node's private staking key and private random beacon key.
- Store the resulting vote to the file
<bootstrap-dir>/private-root-information/private-node-info_<node_id>/root-block-vote.json
Once a vote has been generated, running transit push-root-block-vote will upload the vote file to the server.
Transit key is used to encrypt the random beacon key generated for the consensus nodes.
Running transit push-transit-key will perform the following actions:
- Create a Transit Keypair and write it to
transit-key.pub.<id>transit-key.priv.<id>
- Upload the node's public files to the server
transit-key.pub.<id>