1 Oracle Blockchain Platform Enterprise Edition Overview
Oracle Blockchain Platform Enterprise Edition 26.3 for Besu provides a Kubernetes-based platform for deploying and managing permissioned Ethereum networks. It includes a Blockchain Platform Manager for provisioning and operating instances, and a Besu data plane for running the services and node roles required by a private Ethereum network.
Key Capabilities
Oracle Blockchain Platform Enterprise Edition 26.3 combines platform management, Besu network operations, secure application integration, wallet services, and digital-asset enablement in one Kubernetes-based deployment.
- Lifecycle management: Provision, configure, scale, upgrade, and monitor Besu instances through Blockchain Platform Manager and Kubernetes operators.
- Permissioned Besu networks: Operate QBFT validator networks with boot nodes for peer discovery, and RPC or archive nodes for specialized access and historical queries.
- Secure blockchain integration: Use the RPC Proxy as the governed application entry point for JSON-RPC, transaction orchestration, contract queries, wallet-backed signing, events, callbacks, and operational status.
- Operational administration: Use the Besu Service Console for node health, logs, block and transaction exploration, contract operations, and wallet-related administration.
- Contract and digital-asset support: Execute Solidity contracts in the EVM, maintain contract metadata, and support digital-asset contracts, SDKs, and sample applications for Besu.
- Rich History and observability: Optionally index blockchain transactions, events, traces, and state in Oracle Database or MySQL.
- Enterprise security: Integrate with OpenLDAP or an external OIDC provider; enforce RBAC; secure service communication.
Universal Wallet as a Service
Universal Wallet as a Service (UWaaS) provides custodial wallet and policy services for the Besu data plane. In this architecture, the UWaaS Wallet Manager is installed as a platform-level service and administered through the Platform Manager experience. The instance-level wallet service, also called the Local Wallet Service or OBP Besu Adapter, performs Besu-specific wallet, signing, reporting, and broadcast operations.
The RPC Proxy is the governed entry point for end-user token and wallet transactions, including signed and unsigned flows. It resolves caller and organization context, applies platform access controls, and coordinates with UWaaS and the local wallet service when signing or policy enforcement is required.
- UWaaS Wallet Manager: Provides platform-level wallet administration, organization and user wallet workflows, policy coordination, and rules-engine integration.
- Local Wallet Service or Oracle Blockchain Platform Besu Adapter: Provides instance-level wallet operations, signing, transaction broadcast, and reporting for a specific Besu network.
- Policy and rules services: Enforce granular roles and policy decisions for activities such as wallet administration, smart-contract deployment, and transaction execution.
- Key management: Integrates with protected secret or vault services for wallet encryption and key protection. Applications should not manage private keys directly.
- Administration and RBAC: Exposes UWaaS administration through the Platform Manager experience and controls it through platform roles. Wallet users do not require access to the UWaaS administration pages.
Architecture
Oracle Blockchain Platform Enterprise Edition 26.3 separates platform management from blockchain execution. The Blockchain Platform Manager provisions and manages Besu instances. Each Besu instance contains the services and node roles required to operate a private Ethereum network.
Architecture Components
| Architectural area | Components | Purpose |
|---|---|---|
| Kubernetes foundation | OKE/Kubernetes, namespaces, ingress, load balancers | Hosts and isolates control-plane and Besu instance components. |
| Control plane | Blockchain Platform Manager UI/API, Kubernetes operators, lifecycle APIs | Provisions, configures, scales, upgrades, and monitors Besu instances. |
| Identity and authorization | Keycloak, OpenLDAP, or external OIDC provider | Provides authentication, group-based RBAC, and user administration. |
| Security and networking | Istio service mesh, TLS/mTLS, cert-manager, Kubernetes Secrets | Secures ingress and internal service communication and manages certificates. |
| Besu access layer | RPC Proxy | Provides authenticated Ethereum JSON-RPC/Web3 access, transaction submission, queries, events, callbacks, and endpoint routing. |
| Operations interface | Besu Service Console | Provides node health, logs, block and transaction exploration, wallet operations, and smart-contract operations. |
| Wallet and transactions | UWaaS Wallet Manager, local wallet service, signing and transaction services | Manages wallets, signing, transaction submission, policy enforcement, and transaction status. |
| Besu network | Validator, boot, RPC, and optional archive nodes | Validators run QBFT consensus; boot nodes provide discovery; RPC nodes serve API traffic; archive nodes support historical queries. |
| Smart contract layer | EVM, Solidity contracts, contract registry | Executes smart contracts and stores contract metadata such as ABI and deployment information. |
| Rich History | Rich History plugin, Oracle Database or MySQL, archive node | Replicates and indexes blockchain transactions, events, traces, and state for SQL-based access. |
| Platform metadata | Shared MySQL with per-instance databases and users | Stores control-plane and instance metadata with logical isolation between instances. |
Runtime Workflow
- Administrators authenticate through the configured identity provider and use Blockchain Platform Manager to create and manage instances.
- Kubernetes operators reconcile instance specifications and lifecycle requests into the required Besu services and node resources.
- Applications and Web3 clients access the blockchain through the RPC Proxy. Direct external access to validator and administrative Besu endpoints is not required.
- The RPC Proxy routes read and transaction requests to appropriate Besu nodes and can invoke wallet services when signing or policy enforcement is required.
- Besu validators use QBFT consensus to agree on blocks. Boot nodes support peer discovery, while RPC and archive nodes provide specialized access patterns.
- Optional Rich History components consume ledger information and expose indexed blockchain data through Oracle Database or MySQL.
Security and Deployment
- Service security: Istio provides ingress routing, authorization policy, and mTLS for internal platform services.
- Certificate management: Certificates are managed by cert-manager, with secrets scoped to the relevant Kubernetes namespace.
- Peer communication: Besu peer-to-peer communication uses the RLPx protocol. The RPC Proxy remains the governed entry point for application-facing blockchain API traffic.
- Metadata isolation: The control plane uses shared platform metadata storage while allocating logical database and credential isolation per instance.
- Optional components: Archive nodes and Rich History storage are optional and should be enabled when historical transaction, event, trace, or state queries are required.
