Installing a Private Network
You can run a complete Rayls Private Network on one machine with the Rayls CLI: a Private Network Hub; two to six participants, each with a Rayls Sovereign chain (Privacy Node in the code), a private relayer and a key service (CTS); the proofs API; the governance services; and the Auditor Explorer. It is a development and demonstration setup. This page shows how to start it, what it runs, and what a production network needs instead.
Development and demonstration onlyThe local stack uses development settings throughout. Don't use it for production or for anything of value:
- The Hub is a single Hyperledger Besu node with peer-to-peer networking off and a minimum gas price of zero.
- Each Rayls Sovereign chain is a single Axyl node in development mode, with no gas fees.
- One deployer key controls every chain. By default it is a publicly known development key.
- The key services store keys unencrypted, with no key management service (KMS).
- The proving keys come from a single-party setup, not a multi-party ceremony.
Prerequisites
- Docker and Docker Compose v2.24 or newer.
- The Rayls CLI: download a pre-built binary, or build it from source with Go 1.25.4 or newer.
A Private Network started with --full needs no funded account: its chains run inside the stack.
Install the CLI
Download the binary for your platform, for example on macOS with Apple Silicon:
curl -fL https://cli.rayls.com/rayls-darwin-arm64 -o rayls
chmod +x rayls
sudo mv rayls /usr/local/bin/The other builds are rayls-darwin-amd64, rayls-linux-amd64 and rayls-linux-arm64. To build from source instead:
git clone https://github.com/raylsnetwork/rayls-sovereign-cli.git
cd rayls-sovereign-cli
go build -o rayls .Start a Private Network
rayls init --full # two participants
rayls init --full --members 4 # two to six participantsThe first run pulls the images one at a time from a public Amazon Elastic Container Registry, which can take several minutes. The contracts service then deploys and configures every contract before the relayers start.
Use--fullA bare
rayls initdoesn't start a Private Network. It starts a single Rayls Sovereign chain, with no Hub.rayls init --with-hubadds a minimal Hub for a single participant, without governance services. Only--fullruns several participants connected through the Hub.
Options
| Option | Effect |
|---|---|
--members N | Number of participants, from 2 to 6 (default 2). They are named a to f. |
--local | Build the Rayls components from source instead of pulling them. The proofs API's keys are stored with Git Large File Storage (LFS), which a source build doesn't fetch: run rayls dev gnark first, or Enygma won't work. |
--monitoring | Add Grafana, Loki, Prometheus, Tempo and Pyroscope, with an OpenTelemetry collector. Grafana is at http://localhost:3300. |
--no-blockscout, --blockscout a,b | Turn off, or limit, the block explorer for each Rayls Sovereign chain. |
What --full runs
--full runsEvery port listens on 127.0.0.1 only, so the stack isn't reachable from other machines. Ports for participants go up by one for each participant after a.
| Service | What it is | Address on your machine |
|---|---|---|
private-network-hub | The Private Network Hub: one Hyperledger Besu node, chain ID 1337 | JSON-RPC (remote procedure call) at http://localhost:3445 |
privacy-node-a, -b, … | Each participant's Rayls Sovereign chain: one Axyl node, chain IDs 12345, 12346, … | JSON-RPC at http://localhost:8545, 8546, … |
relayer-a, … | Each participant's private relayer | Health check at localhost:9000, 9001, … |
kos-a, … | Each participant's key service (CTS) | gRPC at localhost:8080, 8081, …; HTTP at localhost:8090, 8091, …; both use mutual TLS (Transport Layer Security) |
proofs-api | The proofs API, which generates Enygma proofs | http://localhost:3003 |
governance-api | The governance API | http://localhost:9100, with Swagger at /swagger/index.html |
governance-listener | Indexes the Hub and decrypts cross-chain messages | Port 9101 |
governance-flagger | Flags anomalies | Port 9102 |
audit-explorer | The Auditor Explorer | http://localhost:8181 |
contracts | Deploys and configures the contracts, then stays up | Deployment status at localhost:7000 |
postgres | Shared database for the relayers, key services and governance services | localhost:5432 |
nats | Message bus between the services, with mutual TLS | localhost:4222, monitoring at 8222 |
| Blockscout | A block explorer for each Rayls Sovereign chain | http://localhost:10004 for a, 10104 for b, … |
The Hub and the Rayls Sovereign chains are ordinary EVM (Ethereum Virtual Machine) chains: point any Ethereum tool at their JSON-RPC addresses.
What the deployment sets up
The contracts service runs the same steps a real network goes through (see Running a Private Network):
- Deploys the Hub contracts and generates the operator's view key pair. It registers the operator's entry (chain ID 999) and registers every participant as an active issuer.
- Registers the Hub's business roles.
- Deploys each Rayls Sovereign chain's contracts and registers its business roles.
- Authorises each participant's relayer addresses on its own chain and on the Hub.
- Seeds the standard contract templates in the Hub's template registry.
The deployer key (PRIVATE_KEY_SYSTEM) holds ADMIN on every chain. To use your own, set it before the first init:
PRIVATE_KEY_SYSTEM=0x<your key> rayls init --fullManage the stack
rayls ps # list the services
rayls logs relayer-a -f # follow one service's logs
rayls stop # stop, keeping the containers
rayls start # start again
rayls down # remove containers, keep data
rayls down -v # remove containers and dataNext steps
- Bring an Enygma token into service and send it: Running Rayls Enygma.
- Watch the transfers in the Auditor Explorer at
http://localhost:8181. - Explore the governance API's Swagger page at
http://localhost:9100/swagger/index.html. - See the other interfaces in Interacting with a Private Network.
Production networks
The public repositories contain every component the local stack runs, each with its configuration documented in its README and .env.example:
| Repository | Components |
|---|---|
| rayls-sovereign-contracts | The Hub and Rayls Sovereign chain contracts, and the Hardhat deployment tasks the local stack uses: deploy:private-hub, deploy:privacy-node, activate-business-roles-pnh, activate-business-roles-pn, add-authorized-relayers-pnh, add-authorized-relayers and seed-standard-templates |
| rayls-sovereign-relayer | The private relayer and the key service (CTS) |
| rayls-sovereign-gnark-api | The proofs API |
| rayls-sovereign-pnh-governance | The governance API, listener and flagger |
| rayls-sovereign-pnh-auditor-ui | The Auditor Explorer |
They don't include a production installation package, or tooling for sizing, high availability or disaster recovery. To run a production network, contact Rayls. Compared with the local stack, a production network needs at least:
- its own keys for each chain's administrator, held securely;
- key services that encrypt keys with a KMS: the key service supports Amazon Web Services (AWS) KMS and Google Cloud KMS;
- proving keys from a multi-party setup ceremony (see Cryptographic foundations);
- a Hub network and Besu configuration chosen by the operator;
- the governance API reachable only from the operator's own network (see Interacting with a Private Network).
Updated about 2 hours ago
