Skip to main content

Remote Validators

Name-Routed Proxies​

Splice validators deployed with Docker Compose put the participant APIs behind nginx on a single port and route by name. Point canton-deploy at that port and set the routing names:

KeyPurpose
grpcAuthoritygRPC :authority for the Ledger API (Splice default: grpc-ledger-api.localhost)
adminGrpcAuthoritySame for the Admin API (grpc-admin-api.localhost)
httpHostHTTP Host header for the JSON API (json-ledger-api.localhost)

dpm script connects to the grpcAuthority name directly, so that name must resolve to the proxy on ledgerPort. See Scripts.

SSH Tunnel​

When the validator runs on a remote host (for example Splice Docker Compose with nginx on 127.0.0.1:80), canton-deploy can open local port forwards before any network command and tear them down on exit:

host: '127.0.0.1',
ledgerPort: 5001,
httpPort: 7575,
grpcAuthority: 'grpc-ledger-api.localhost',
httpHost: 'json-ledger-api.localhost',
tunnel: {
ssh: {
host: 'dev-server.example.com',
user: 'ubuntu',
forwards: [
{ localPort: 5001, remoteHost: '127.0.0.1', remotePort: 80 },
{ localPort: 7575, remoteHost: '127.0.0.1', remotePort: 80 },
],
},
},

Multiple forwards to the same remote :80 are intentional: nginx routes by gRPC :authority and HTTP Host. See examples/devnet-compose-remote.

Admin API on Splice Validators​

Splice ships with the Admin gRPC route commented out in nginx, so status reports the Admin API as unreachable (for example HTTP 405). That is expected. The default ledger upload path needs only the Ledger and JSON APIs; use deploy --vet to vet during upload.