Running a Private Network

A Rayls Private Network is multiple Rayls Sovereign chains connected together via a central Hyperledger Besu chain, the Private Network Hub. This section is for the institutions that run one: the Private Network operator, which runs the Hub and governs the network, and the participants, which each run a Rayls Sovereign chain (Privacy Node in the code) and join it.

The Private Network Hub is a Hyperledger Besu chain at the centre of every Rayls Private Network, run by the Private Network operator. Every message between Rayls Sovereign chains passes through it. It holds the network's registries for participants, tokens and approved contract templates, the cross-chain messaging contracts, and the Enygma and DvP (delivery-versus-payment) contracts.

Who runs what

PartyRunsMain tasks
Private Network operatorThe Private Network Hub; the governance services (API, listener and flagger) and their database; the Auditor ExplorerDeploys the Hub contracts, registers participants, approves tokens and contract templates, freezes participants or tokens, monitors cross-chain activity
Each participantIts Rayls Sovereign chain; a private relayer, which carries messages between its chain and the Hub; a key service (CTS), which holds its keys encrypted with a key management service (KMS)Deploys its chain's contracts, issues tokens and submits them to the Hub, runs its own applications and clients
The networkA proofs APIGenerates the zero-knowledge proofs that private relayers need to send Enygma transactions

Only the operator governs the network as a whole. Each participant keeps full control of its own chain: payments between its own clients never reach the Hub.

What running a network involves

These are the steps the code goes through, in order. The local setup runs all of them for you.

  1. Set up the Hub. Run a Hyperledger Besu chain and deploy the Hub contracts to it. The deployment registers the operator in the participant registry under the reserved chain ID 999, with the operator's view public key (ML-KEM-768). Its secret half is what lets the operator's governance services decrypt cross-chain traffic. The deploying account becomes the administrator (ADMIN) of the Hub's access manager.
  2. Assign governance roles. Register the Hub's business roles and grant them to the people or systems that will add participants, approve tokens and freeze tokens. See Private Network roles.
  3. Start the governance services. The listener indexes the Hub and decrypts cross-chain messages with the operator's view secret key. The flagger checks what the listener stores. The API serves the results to the Auditor Explorer.
  4. Add participants. For each institution, register its chain ID, its role (issuer or participant) and its status in the Hub's participant registry, and authorise its relayer's signing addresses on the Hub. The participant deploys the contracts on its own chain and starts its key service and private relayer. Its key service then registers its keys on the Hub, including its view private key encrypted to the operator. Registration only works once the operator has set the participant's status to active. See Adding new participants and, for the participant's side, Connecting Rayls Sovereign to a Private Network.
  5. Seed the standard contract templates in the Hub's template registry. Without them, Enygma transfers can't mint on the receiving chain.
  6. Approve tokens as issuers submit them. A token can't move between chains until the operator activates it on the Hub. See Approving new tokens.
  7. Operate the network. Watch cross-chain activity, act on flags, and freeze participants or tokens when needed. Keep the Hub available: if it stops, no message can move between chains.
🚧

Local setup and production

The Rayls CLI runs a whole Private Network on one machine, for development and demonstrations only. The public repositories don't include a production installation package. To run a production network, contact Rayls.

In this section

For day-to-day operations, see Operating a Rayls Private Network: adding participants, approving tokens, freezing participants, freezing tokens, monitoring cross-chain transactions and flagging transactions.

To run Enygma private payments on your network, see Running Rayls Enygma.


Did this page help you?