Indexer Archive Node
An archive node that keeps every historical state and serves exactly one client: the indexer writer running beside it. Its RPC listens on loopback only and sits behind no proxy.
Docker and the node-deploy checkout — see Installation.
P2P is outbound only; nothing needs to be open inbound except SSH.
Why this role exists separately
Sharing the public RPC does not work. An indexer backfilling history issues
a continuous stream of state queries. Pointing it at rpc-1 / rpc-2 put that
load on the same endpoint serving wallets — which is what caused the explorer to
take the public RPC down with it. This node exists so that traffic never leaves
the host.
Archive is mandatory, not a preference. The writer must be able to re-read
any block to backfill or re-index. A pruned node discards old state and the
writer fails with State already discarded — which surfaces long after
deployment, midway through a backfill.
Firewall
The stack runs network_mode: host, so every port the node opens is on the host
itself. Only SSH comes in; P2P dials out, and metrics stay closed:
sudo ufw allow 22/tcp # SSH
sudo ufw deny 9615/tcp # Prometheus — or allow only your monitoring IP
sudo ufw enable
Do not open 30333 inbound — see Ports & Endpoints.
--rpc-externalIt would publish an archive node's full state to the internet with no rate limiting in front of it. If you need a public endpoint, run a public RPC node — that role has the protection layers this one deliberately lacks.
Deploy
cd node-deploy/testnet/indexer-rpc
cp .env.example .env # set RPC_NODE_KEY (openssl rand -hex 32)
docker compose pull
docker compose up -d
docker compose logs -f orbinum-indexer-rpc
Everything else in .env has a working default.
Wait for a full sync before pointing the indexer at it. On an archive node that takes considerably longer than on a pruned one, and an indexer started early will read gaps as missing data. Check it from the host:
docker exec orbinum-indexer-rpc curl -s -H 'Content-Type: application/json' \
-d '{"id":1,"jsonrpc":"2.0","method":"system_health"}' \
http://localhost:9944
Once it reports isSyncing: false, point the writer at ws://127.0.0.1:9944.
What makes it different
| Setting | Value | Why |
|---|---|---|
--state-pruning archive | full history | the writer re-reads arbitrary blocks |
--blocks-pruning archive | full history | same |
no --rpc-external | RPC on 127.0.0.1 only | the only client is on this host |
no --public-addr | outbound-only P2P | nothing needs to dial it |
telemetry level 0 | standard | it has no validator address to report |
RPC_MEM_LIMIT=4g, RPC_CPUS=1.5 | lighter caps | it serves one client, not the public |