6 Create an Instance
Deploying the stack creates Blockchain Platform Manager, which you can use to provision, configure, and manage instances of Oracle Blockchain Platform Enterprise Edition for Besu. Instance nodes run on a set of available Kubernetes worker nodes.
You use Blockchain Platform Manager to complete the following tasks:
- Create, start, stop, and delete instances of Oracle Blockchain Platform Enterprise Edition for Besu.
- View details about all instances and activity records for all instances.
- Configure, activate, and use the LDAP service or configure your own OIDC provider for the installation.
- Create and save user accounts (OpenLDAP users only).
To create an instance:
- Open Blockchain Platform Manager
(
https://controlplane.domainname/console/index.html) - Log in to Blockchain Platform Manager by using your Instance Admin role user you have created in your identity provider.
- On the Instances page, click Create
Instance to create an instance of the Besu network.The Besu Create Instance dialog is displayed.
- Complete the following fields:The instance creation process runs, creating the pods for the nodes and services that make up the Besu network.
Field Description Instance Name Enter a name for your Oracle Blockchain Platform instance.
The service instance name:
- Must contain one or more characters.
- Must not exceed 15 characters.
- Must start with an ASCII letter:
atoz. - Must contain only lower case ASCII letters or numbers.
- Must not contain a hyphen.
- Must not contain any other special characters.
- Must be unique within the identity domain.
Description Optional.
Enter a short description of the Oracle Blockchain Platform instance.
Domain Name Enter the domain name for the cluster that you specified when installing. This must contain only lower case ASCII letters.
The hostnames generated for the Blockchain Instance services make use of the domain name and the instance name as parent domain and sub domain respectively.
Role Select Founder to create a complete blockchain environment. This instance becomes the founder organization and you can onboard new participants in the network later.
Select Participant to create an instance that will join an existing blockchain network created elsewhere before this instance can be used.
Instance Access Group The group name created in the identity provider containing users who are allowed to access and operate with this instance.
Configuration Select a provisioning shape which meets the needs of your deployment. Only Enterprise is currently supported for Oracle Blockchain Platform Enterprise Edition for Besu.
Chain ID (Founder instance only) Enter your Ethereum chain ID. The default is
1500.Provide a unique numeric identifier for this network avoiding common public IDs like 1, 137, 1337, or 56, to ensure transaction signatures are valid only on this specific Besu deployment and protected from replay attacks.
Third Party Root CA If you want to use certificates from your own certificate authority and use the Oracle Blockchain Platform certificate authority as an intermediary CA, you can upload your CA archive. The certificate that you upload will be used to sign the intermediary certificates for Oracle Blockchain Platform nodes, thus including them under your root CA chain.
The archive is a.zipfile which contains the following files:- CA chain: This file must be named
ca-chain.pem. The entire CA file sequence from the signing CA to the top-level CA must be present. - key: This file must be named
ca-key.pem. A 256-bit key that uses theprime256v1curve is recommended. The key file must be an unencrypted private key in the PKCS #8 format. - certificate: This file must be named
ca-cert.pem. The certificate file must be in Base64 format and must include the subject key identifier extension.
.ziparchive such that when the archive (.zip) is extracted, the files are visible in the current directory at the same level as the archive (.zip) file. The files must not be inside a nested directory inside the archive.The product was tested with an X.509 v3 certificate with the following properties.
Key type: Elliptic curve cryptography (ECC)
Curve name:
prime256v1Certificate signing algorithm:
ecdsa-with-SHA256Block Period (Founder instance only) Minimum time (in seconds) between new block creation. Validator Node Count (Founder instance only) Number of nodes responsible for validating and proposing blocks. BootNode Count (Founder instance only) Number of nodes used for initial peer discovery. RPC Node Count (Founder instance only) Number of nodes providing APIs for external communication. Archive Node Count (Founder instance only) Number of archive nodes to provision. Smart Contract Governance Mode Select Governed to manage smart contracts through a Digital Assets administrative user. Select NoOp to deploy smart contracts without governance controls. Rich History Oracle DB Profile Select your rich history database profile. It must be created and configured before creating the instance. Upload Genesis File (Participant instance only) Upload the genesis metadata .zipfile from the founder instance. Select Export Genesis Metadata from the founder instance Actions menu to download the genesis metadata file from the founder. - Once the instance is listed in the
Upstate, add theHostsentries to yourHostsfile.
You can retrieve the domain name from the Application Information pane in OCI: Application Information.<ingress-ip> console.<instance-name>.<instance-domain> rpcproxy.<instance-name>.<instance-domain> wrapper.<instance-name>.<instance-domain> auth.<instance-name>.<instance-domain>