Deploy a Contract with the Command Line
After you compile a smart contract you can deploy it to an Oracle Blockchain Platform Besu environment.
The following steps walk through how to deploy the packaged Tokenized Deposit contract project. For other packaged contracts, see the README file that is bundled with the contract package.
Configure the Oracle Blockchain Platform Besu Network
Run the following commands to set the values that are consumed by the project's hardhat.config.ts file.
npx hardhat vars set BESU_CHAIN_ID <chain-id>
npx hardhat vars set BESU_RPC_URL <rpc-proxy-url>
npx hardhat vars set BESU_RPX_PROXY_AUTH_TOKEN "Bearer <rpc-auth-token>"
npx hardhat vars set WALLET_SERVICE_BASE_URL <wallet-service-sign-url>
npx hardhat vars set WALLET_SERVICE_ENABLED true
npx hardhat vars set WALLET_SERVICE_ACCOUNTS '[{"address":"0x<address>","walletId":"0x<address>"}]'
npx hardhat vars set WALLET_SERVICE_AUTH_TOKEN "Bearer <wallet-service-auth-token>"For the Tokenized Deposit project, the BESU_RPC_URL value is the complete configured JSON-RPC proxy endpoint, as shown in the following example.
https://rpcproxy.example.oracle.com/v1/besu/proxyThe WALLET_SERVICE_BASE_URL value is the complete /transaction endpoint, as shown in the following example.
https://rpcproxy.example.oracle.com/v1/besu/transactionDeploy the Inactive Proxy Pair
Run the ERC-5982 deployment script with a stable deployment ID, as shown in the following example. The script deploys or resumes the ERC-20 helper libraries, account proxy, and Tokenized Deposit proxy. It also links the account/token contexts and sets governance context on both proxies.
DEPLOYMENT_ID=<deployment-id> \
GOVERNANCE_ADDRESS=<governance-contract-address> \
GOVERNANCE_UUID=<governance-uuid> \
TOKEN_NAME="DepositToken" \
TOKEN_SYMBOL="DP" \
TOKEN_DESCRIPTION="DepositToken proxy contract" \
ADMIN_USER_ID="platformadmin1" \
ADMIN_ORG_ID="org1" \
CONTRACT_METADATA_SMART_CONTRACT_ID="DP123" \
CONTRACT_METADATA_VERSION="1.0.0" \
CONTRACT_METADATA_DESCRIPTION="DepositToken proxy contract" \
CONTRACT_METADATA_AUTHOR="Oracle" \
CONTRACT_METADATA_TAGS='{"assetType":"tokenized deposit","role":"proxy"}' \
npx hardhat run scripts/deploy/deposittoken/deploy-deposittoken-erc-5982.ts --network obp-besuThe DEPLOYMENT_ID, GOVERNANCE_ADDRESS, and GOVERNANCE_UUID values are required. Reuse the same deployment ID only to resume an interrupted deployment. After a deployment completes successfully, its resume cache is deleted; rerunning with that ID starts a fresh deployment.
The CONTRACT_METADATA_* values describe the Tokenized Deposit proxy in the ERC-7201 deployment registry. CONTRACT_METADATA_TAGS must be a JSON object whose values are strings.
The command completes with the token and account proxies inactive. Preserve the printed DEPLOYMENT_SUMMARY_JSON and record both proxy addresses; they are required for the governance intent.
Submit the Deployment Intent
In the following script, set a future deadline by editing the DEADLINE_SECONDS value if the default one-hour proposal window is not appropriate for your environment. Include every proxy whose governance context was set by the deployment. For the Tokenized Deposit package, typically this means both the token proxy and its account proxy. For an Oracle Blockchain Platform Besu proposal submitted via the RPC proxy and wallet service route, run the following script.
GOVERNANCE_INTENT_MODE=obp-besu \
GOVERNANCE_ADDRESS=<governance-contract-address> \
GOVERNANCE_UUID=<governance-uuid> \
DEPLOY_TARGETS_JSON='["<token-proxy>","<account-proxy>"]' \
DEADLINE_SECONDS=3600 \
DEPLOY_INTENT_MANIFEST=.obp-da/governance/deploy-intent.json \
npx hardhat run scripts/deploy/deposittoken/governance/propose-deploy-intent.ts --network obp-besuThe script validates each target, resolves its EIP-1967 implementation and runtime code hash, submits the proposal, and writes the reviewed components and proposal result to the file speciified by the DEPLOY_INTENT_MANIFEST variable.
For a direct JSON-RPC governance submission, use a Hardhat network with a local signer and change only the proposal transport and network, as shown in the following example.
GOVERNANCE_INTENT_MODE=json-rpc \
GOVERNANCE_ADDRESS=<governance-contract-address> \
GOVERNANCE_UUID=<governance-uuid> \
DEPLOY_TARGETS_JSON='["<token-proxy>","<account-proxy>"]' \
DEADLINE_SECONDS=3600 \
DEPLOY_INTENT_MANIFEST=.obp-da/governance/deploy-intent.json \
npx hardhat run scripts/deploy/deposittoken/governance/propose-deploy-intent.ts --network <direct-json-rpc-network>
The direct network must be configured with an authorized non-custodial signer. Do not use JSON-RPC with a wallet-service-only configuration.
Governance Activation
Submitting deployment intent is a separate process from deploying the proxies.
- No-Op: The included components activate during successful
proposeDeployIntentprocessing. Verify the transaction or Oracle Blockchain Platform response and then query the active state. - Governed: The intent remains pending until the configured policy receives the required approvals before its deadline. The token and account activate automatically only after that policy completes.
The CLI does not bypass governance approvers. If the proposal expires, is rejected, or uses the wrong proxy/code hash, resolve the cause and submit a new intent rather than treating the initial deployment as active.
After governance is activated, verify the deployment. Use the generated Postman or wrapper API assets, or import the project into Blockchain App Builder for Besu and use the Execute panel. Use the proxy addresses from the deployment summary as call targets; do not use helper-library or implementation addresses.
Note:
After you deploy a contract, manifest files are generated in the.openzeppelin folder under the project root. For production networks (not development networks), commit these files to source control. For more information, see Network Files in the OpenZeppelin documentation.
Troubleshooting
| Message or Condition | Resolution |
|---|---|
GOVERNANCE_ADDRESS and GOVERNANCE_UUID are required |
Provide both values to the deploy command and verify the governance address has bytecode on the selected network. |
| Deployment is incomplete | Re-run the same command with the same DEPLOYMENT_ID value before the deployment completes.
|
DEPLOY_TARGETS_JSON is invalid
|
Pass a non-empty JSON array of unique proxy addresses, for example ["0x...token", "0x...account"].
|
| Target is not an EIP-1967 proxy | Use the deployed token and account proxy addresses from the DEPLOYMENT_SUMMARY_JSON file, not an implementation or library address.
|
| Oracle Blockchain Platform intent submission fails because authorization is absent | Confirm that the BESU_RPX_PROXY_AUTH_TOKEN value is set and that the configured Oracle Blockchain Platform network carries it as an Authorization header.
|
| Deployment succeeds but the token remains inactive | Submit the deployment intent. For governed governance, wait for policy approvals; for No-Op governance, confirm that proposal processing succeeded. |