Validator Requirements
Everything you need in place before deploying. Meeting it makes an application actionable; the slot is decided later — see How slots are assigned.
Hardware
The recommended validator tier. Running a Node compares all four roles; this is the one that runs consensus.
| Component | Recommended |
|---|---|
| CPU | 16 dedicated cores |
| RAM | 32 GB |
| Storage | 1 TB NVMe SSD |
| Network | 1 Gbit, static IPv4 |
| OS | Ubuntu 24.04 LTS or later |
Storage is sized for default pruning plus the shielded pool's Merkle tree, which only grows: every shielded note inserts leaves that are never removed. An archive node needs considerably more — a validator does not run one.
Ubuntu 22.04 is no longer supported. The install and operating guides are written and tested against 24.04 only.
Orbinum validators verify Groth16 proofs inside block execution. Verification is CPU-bound and arrives in bursts: a block carrying several shielded operations costs far more than an empty one.
Burstable and shared-vCPU instances — the cheap tier at most providers — throttle exactly when a proof-heavy block arrives. A throttled validator misses its slot, and missed slots stall finality for everyone. Use dedicated-vCPU instances or bare metal.
Hosting providers
Use a crypto-friendly provider: one whose acceptable-use policy allows proof-of-stake validation outright, in writing. A validator on a provider that forbids it can be terminated without notice, and a terminated validator misses slots for everyone.
Hetzner and Contabo are not accepted. Hetzner's terms prohibit crypto workloads and its support has confirmed the ban covers PoS validation and node hosting. Contabo is excluded on reliability grounds. Several large clouds sit in between and require written permission for staking — get it before renting, or pick a provider that does not ask. Background on who allows what: Cloud ToS & Crypto: When Your Validator Is Not Welcome.
Region matters. The set is selected for geographic diversity, so the network does not depend on one country or one data-center cluster. A node in a region the set does not cover yet is worth more than a fifth node in the region it already does. The application form asks for provider and region for this reason.
Software
Docker with the Compose plugin, nothing else — see Installation.
Network
Port 30333 must be reachable from the internet, not merely open in ufw — see
Ports and The node has no peers.
Accounts and keys
Four distinct pieces of key material, with different homes and different risk:
| Item | Where it comes from | Notes |
|---|---|---|
| Validator account (SS58) | Any Substrate wallet — Polkadot.js, Talisman, SubWallet | The sole argument to addValidator. Needs a little ORB to sign setKeys |
| Session keys (Aura + GRANDPA) | Generated on the node by author_rotateKeysWithOwner, with a proof of possession | Private halves never leave the server |
| Node key | openssl rand -hex 32 | Your libp2p identity. Keep it stable across restarts |
Relay key (evmr, ECDSA) | Your own key, inserted after approval | Optional for consensus, required to earn |
Must stay on
The shipped validator stack enables three things by default. All three are required for the lifetime of the validator; turning any of them off is grounds for removal from the set.
| Service | What it does | Where it is configured |
|---|---|---|
| Watchtower | Pulls and rolling-restarts the node when a new image ships. Keeps the whole set on one binary | watchtower service in the Compose file — see Updates |
| Orbinum telemetry | Reports sync state and authoring to the dashboard. The only signal the team has that your node is alive | TELEMETRY_URL in .env, at verbosity 1 — see Telemetry |
| Hardware benchmarks | On startup the node measures CPU, memory and disk against the Substrate reference hardware and reports it to telemetry — how the hardware table is verified. A node that reports below reference, or not at all, will not be approved | On by default. Do not add --no-hardware-benchmarks to the command |
How slots are assigned
There are 32 slots and no queue. A node that meets everything on this page is eligible, not selected. The team fills slots on what the node demonstrates over time:
| Criterion | Where it is read |
|---|---|
| Uptime and sync | Telemetry — continuously synced, no gaps |
| Hardware benchmark | sysinfo.hwbench on telemetry, at or above reference |
| Hosting provider | Crypto-friendly, not Hetzner or Contabo — see Hosting providers |
| Geographic diversity | Region not already saturated in the set — see Hosting providers |
| Required services on | Everything in Must stay on, for the lifetime of the node |
A node that is eligible today and not selected stays eligible; slots open when a validator leaves or misbehaves. Keep it running and visible.