Installation
Orbinum nodes run from a pre-built Docker image published to GitHub Container Registry. You do not compile the node from source — pull the image and run it.
ghcr.io/orbinum/node:testnet-latest — the current testnet image. It already
bundles the ZK circuit artifacts, so there is nothing else to download.
Before you start
Sizing depends on which role you are running — see Running a Node for the table. Everything below is the same for all of them.
- Docker with the Compose plugin — the only dependency.
- TCP
30333open inbound for the public RPC and the validator. The indexer archive only dials out, and a development node needs nothing open. See Ports & Endpoints.
1. Install Docker
curl -fsSL https://get.docker.com | sh
sudo usermod -aG docker $USER
The script installs the Compose plugin too. Log out and back in for the group change to take effect, then verify:
docker --version
docker compose version
2. Clone the Repository
The compose files, the chain spec and the .env templates live in the
node-deploy repo, one directory per
<network>/<role>:
git clone https://github.com/orbinum/node-deploy.git
cd node-deploy/testnet/rpc # or testnet/validator, testnet/indexer-rpc
What's here:
node-deploy/
├── common/ # Shared build assets
│ ├── Dockerfile # Builds the orbinum-node binary
│ ├── Caddy.Dockerfile # Custom Caddy build (rate-limit plugin)
│ └── Caddyfile # RPC reverse proxy: TLS, CORS, rate limits
├── scripts/ # sync-cloudflare-ufw.sh
├── testnet/
│ ├── chainspec/ # testnet-spec.json (genesis + bootNodes)
│ ├── validator/ # Validator (+ Watchtower)
│ ├── rpc/ # Public RPC (+ Caddy, Watchtower)
│ └── indexer-rpc/ # Loopback-only archive node (+ Watchtower)
└── mainnet/ # Same structure, spec pending
The only thing built locally is the public RPC's Caddy image, from
Caddy.Dockerfile.
3. Pull the Image
docker pull ghcr.io/orbinum/node:testnet-latest
This confirms the host can reach the registry. Each role page runs
docker compose pull itself, so you do not need to repeat this there.
denied on a host that used to workghcr.io/orbinum/node is public — a fresh host needs no credentials. A
denied error almost always means a stored credential has expired and Docker
keeps sending it instead of falling back to anonymous:
docker logout ghcr.io
docker pull ghcr.io/orbinum/node:testnet-latest
Verification
Run a throwaway node in development mode to confirm the image works:
docker run --rm ghcr.io/orbinum/node:testnet-latest --dev --tmp
If you see blocks being produced (🏁 Block #1, 🏁 Block #2), the image is
healthy. Stop it with Ctrl+C.
Check the version:
docker run --rm ghcr.io/orbinum/node:testnet-latest --version