Advanced Operations
This guide covers advanced operational topics for running production-grade Shardeum nodes.
Mainnet validator update: Validators should run the currently supported Shardeum EVM mainnet release. Following the September 2026 security update, validators restarting their nodes should use v1.0.2 or later as officially announced. See the [official Shardeum EVM releases] for binaries, Docker images, and checksums.
1. Production Deployment Best Practices
Using systemd Service
Create a systemd service file for automatic restarts and easier management:
Example service file:
Enable and start the service:
Firewall Configuration
For Full Nodes / RPC Nodes:
For Validators:
For validators, consider restricting RPC access to localhost only. Never expose validator RPC endpoints publicly.
2. Monitoring and Alerting
Enable Prometheus Metrics
Edit config.toml:
Monitoring Stack Setup
Recommended tools:
- Prometheus - Metrics collection
- Grafana - Visualization dashboards
- Alertmanager - Alert notifications
Key metrics to monitor:
- Sync status
- Block height
- Validator jail status
- Disk space usage
- Memory usage
- CPU usage
- Missed blocks
- Peer count
- Network latency
Alert Conditions
Set up alerts for:
- Node falls behind by more than 100 blocks
- Validator is jailed
- Disk usage exceeds 80%
- Memory usage exceeds 90%
- Peer count drops below 5
- Node stops producing blocks (for validators)
3. Security Best Practices
Sentry Node Architecture
A recommended production setup for validators:
Benefits:
- Hides validator's IP address
- Absorbs DDoS traffic
- Reduces attack surface
- Improves security
Configuration:
- Run validator on private network
- Connect validator only to sentry nodes
- Configure sentry nodes with public IPs
- Update
persistent_peersto point validator at sentries
Key Management System (KMS)
For enhanced security, consider:
- Tendermint KMS for validator key management
- Hardware Security Modules (HSM) for key storage
- YubiHSM2 integration
- Remote signing capabilities
KMS setup requires advanced configuration. Thoroughly test in a non-production environment first.
Security Checklist
- ✅ Use firewall rules to restrict access
- ✅ Disable SSH password authentication (use keys only)
- ✅ Keep system packages updated
- ✅ Use fail2ban or similar intrusion prevention
- ✅ Implement DDoS protection
- ✅ Regular security audits
- ✅ Monitor logs for suspicious activity
- ✅ Use VPN for administrative access
4. Backup and Recovery
Critical Files to Back Up
Validator-specific:
All nodes:
Wallet keys:
Backup Script Example
Disaster Recovery
If validator key is compromised:
- Immediately unbond and remove validator
- Generate new keys
- Create new validator
- Report incident to network
If node fails:
- Deploy new server with identical configuration
- Restore backup files
- Sync node to current block height
- Unjail validator if necessary
Unjailing a validator
If your validator is jailed, first make sure the node is running correctly and using the currently supported Shardeum mainnet release. Once the underlying issue has been resolved, submit an unjail transaction using your operator key.
To find your operator key:
Note: <home-path> should be the same node home directory used when starting the validator. Use the same keyring backend that was used when the operator key was created.
5. Performance Optimization
Pruning Strategies
Full nodes (custom pruning):
Archive nodes (no pruning):
Validators:
- Use minimal pruning or default settings
- Avoid aggressive pruning to maintain full state
Database Optimization
Enable state sync for faster initial sync:
Edit config.toml:
Hardware Tuning
SSD optimization:
Network tuning:
6. Scaling RPC Infrastructure
Load Balancing
For high-traffic dApps:
- Use Nginx, HAProxy, or AWS ELB
- Run multiple RPC nodes behind a reverse proxy
- Implement rate limiting to avoid overload
- Separate "public RPC" from "private infra RPC"
Example Nginx configuration:
Caching Strategies
- Cache common queries (latest block, chain ID)
- Use Redis for query caching
- Implement CDN for static responses
7. Logging and Debugging
Viewing Logs
If using systemd:
If running manually:
Debug Mode
Enable verbose logging in config.toml:
Common Debug Commands
8. Upgrade Procedures
Coordinated Network Upgrades
Preparation:
- Monitor official Shardeum announcements for the upgrade schedule and any release-specific instructions.
- Back up critical validator files and configuration.
- Review the release notes and any upgrade-specific requirements.
- Confirm that your environment meets any updated requirements before proceeding.
Upgrade steps:
- Confirm the currently supported Shardeum mainnet release from the official Shardeum EVM releases and review any release-specific instructions.
- Stop the validator.
- Back up the existing binary and critical validator files.
- Download the new release or Docker image.
- Verify the provided checksum/digest.
- Replace the existing binary/image.
- Verify the installed version.
- Restart the node.
- Confirm the node is syncing and the validator is operating normally.
- If the validator was jailed, complete the unjail procedure below.
Recovery and Rollback
Do not downgrade to an earlier binary unless the applicable release or network-upgrade instructions explicitly confirm that rollback is supported. Recovery requirements may vary between upgrades.
If an upgrade fails, first review the release-specific recovery instructions and official Shardeum announcements. If rollback is supported, restore the previous binary according to those instructions before restarting the validator.
9. Troubleshooting Advanced Issues
High Memory Usage
Database Corruption
Network Connectivity Issues
10. Important Resources
- Chain ID:
shardeum_8118-1(mainnet) - EVM Chain ID:
8118(hex:0x1fb6) - Official Documentation: docs.shardeum.org
- GitHub: github.com/shardeum
- Discord: Community support and announcements
Advanced operations require careful planning and testing. Always test configuration changes in a non-production environment first.