Running a Private Network
A Rayls Private Network is multiple Rayls Sovereign chains connected together via a central Hyperledger Besu chain, the Private Network Hub. This section is for the institutions that run one: the Private Network operator, which runs the Hub and governs the network, and the participants, which each run a Rayls Sovereign chain (Privacy Node in the code) and join it.
The Private Network Hub is a Hyperledger Besu chain at the centre of every Rayls Private Network, run by the Private Network operator. Every message between Rayls Sovereign chains passes through it. It holds the network's registries for participants, tokens and approved contract templates, the cross-chain messaging contracts, and the Enygma and DvP (delivery-versus-payment) contracts.
Who runs what
| Party | Runs | Main tasks |
|---|---|---|
| Private Network operator | The Private Network Hub; the governance services (API, listener and flagger) and their database; the Auditor Explorer | Deploys the Hub contracts, registers participants, approves tokens and contract templates, freezes participants or tokens, monitors cross-chain activity |
| Each participant | Its Rayls Sovereign chain; a private relayer, which carries messages between its chain and the Hub; a key service (CTS), which holds its keys encrypted with a key management service (KMS) | Deploys its chain's contracts, issues tokens and submits them to the Hub, runs its own applications and clients |
| The network | A proofs API | Generates the zero-knowledge proofs that private relayers need to send Enygma transactions |
Only the operator governs the network as a whole. Each participant keeps full control of its own chain: payments between its own clients never reach the Hub.
What running a network involves
These are the steps the code goes through, in order. The local setup runs all of them for you.
- Set up the Hub. Run a Hyperledger Besu chain and deploy the Hub contracts to it. The deployment registers the operator in the participant registry under the reserved chain ID 999, with the operator's view public key (ML-KEM-768). Its secret half is what lets the operator's governance services decrypt cross-chain traffic. The deploying account becomes the administrator (
ADMIN) of the Hub's access manager. - Assign governance roles. Register the Hub's business roles and grant them to the people or systems that will add participants, approve tokens and freeze tokens. See Private Network roles.
- Start the governance services. The listener indexes the Hub and decrypts cross-chain messages with the operator's view secret key. The flagger checks what the listener stores. The API serves the results to the Auditor Explorer.
- Add participants. For each institution, register its chain ID, its role (issuer or participant) and its status in the Hub's participant registry, and authorise its relayer's signing addresses on the Hub. The participant deploys the contracts on its own chain and starts its key service and private relayer. Its key service then registers its keys on the Hub, including its view private key encrypted to the operator. Registration only works once the operator has set the participant's status to active. See Adding new participants and, for the participant's side, Connecting Rayls Sovereign to a Private Network.
- Seed the standard contract templates in the Hub's template registry. Without them, Enygma transfers can't mint on the receiving chain.
- Approve tokens as issuers submit them. A token can't move between chains until the operator activates it on the Hub. See Approving new tokens.
- Operate the network. Watch cross-chain activity, act on flags, and freeze participants or tokens when needed. Keep the Hub available: if it stops, no message can move between chains.
Local setup and productionThe Rayls CLI runs a whole Private Network on one machine, for development and demonstrations only. The public repositories don't include a production installation package. To run a production network, contact Rayls.
In this section
- A warm introduction to running a Private Network: what an operator and its participants can and can't do.
- Private Network roles: the roles in the code, on the Hub and on each Rayls Sovereign chain.
- Network design options: the choices you make when you set up a network, with two example designs.
- Supported token standards: which token contracts can move between chains, and how.
- Installing a Private Network: the local stack, its services and ports.
- Interacting with a Private Network: the interfaces each party uses.
For day-to-day operations, see Operating a Rayls Private Network: adding participants, approving tokens, freezing participants, freezing tokens, monitoring cross-chain transactions and flagging transactions.
To run Enygma private payments on your network, see Running Rayls Enygma.
Updated about 2 hours ago
