Skip to main content

Installation

Orbinum nodes run from a pre-built Docker image published to GitHub Container Registry. You do not compile the node from source — pull the image and run it.

Which image

ghcr.io/orbinum/node:testnet-latest — the current testnet image. It already bundles the ZK circuit artifacts, so there is nothing else to download.


Before you start​

Sizing depends on which role you are running — see Running a Node for the table. Everything below is the same for all of them.

  • Docker with the Compose plugin — the only dependency.
  • TCP 30333 open inbound for the public RPC and the validator. The indexer archive only dials out, and a development node needs nothing open. See Ports & Endpoints.

1. Install Docker​

curl -fsSL https://get.docker.com | sh
sudo usermod -aG docker $USER

The script installs the Compose plugin too. Log out and back in for the group change to take effect, then verify:

docker --version
docker compose version

2. Clone the Repository​

The compose files, the chain spec and the .env templates live in the node-deploy repo, one directory per <network>/<role>:

git clone https://github.com/orbinum/node-deploy.git
cd node-deploy/testnet/rpc # or testnet/validator, testnet/indexer-rpc

What's here:

node-deploy/
├── common/ # Shared build assets
│ ├── Dockerfile # Builds the orbinum-node binary
│ ├── Caddy.Dockerfile # Custom Caddy build (rate-limit plugin)
│ └── Caddyfile # RPC reverse proxy: TLS, CORS, rate limits
├── scripts/ # sync-cloudflare-ufw.sh
├── testnet/
│ ├── chainspec/ # testnet-spec.json (genesis + bootNodes)
│ ├── validator/ # Validator (+ Watchtower)
│ ├── rpc/ # Public RPC (+ Caddy, Watchtower)
│ └── indexer-rpc/ # Loopback-only archive node (+ Watchtower)
└── mainnet/ # Same structure, spec pending

The only thing built locally is the public RPC's Caddy image, from Caddy.Dockerfile.


3. Pull the Image​

docker pull ghcr.io/orbinum/node:testnet-latest

This confirms the host can reach the registry. Each role page runs docker compose pull itself, so you do not need to repeat this there.

denied on a host that used to work

ghcr.io/orbinum/node is public — a fresh host needs no credentials. A denied error almost always means a stored credential has expired and Docker keeps sending it instead of falling back to anonymous:

docker logout ghcr.io
docker pull ghcr.io/orbinum/node:testnet-latest

Verification​

Run a throwaway node in development mode to confirm the image works:

docker run --rm ghcr.io/orbinum/node:testnet-latest --dev --tmp

If you see blocks being produced (🏁 Block #1, 🏁 Block #2), the image is healthy. Stop it with Ctrl+C.

Check the version:

docker run --rm ghcr.io/orbinum/node:testnet-latest --version