Alert on authority health
Service down, peer loss, finality lag, clock loss, missing authoring, disk pressure, session-key mismatch, and unexpected RPC exposure need actionable alerts.
Permissionless candidacy · competitive election
This path ends at measurable operation: a qualified node, finalized staking intent, election, active-session membership, finalized authorship, credited rewards, and an honest cost ledger.
One authoritative test per state
A local flag or successful transaction is never evidence for a later state. Use one finalized chain head and the local node when custody must also be proved.
| State | Objective evidence | What it does not prove | Next action |
|---|---|---|---|
| Synchronized peer | Correct genesis, peers, isSyncing=false, advancing finalized head, stable peer ID after restart. | Keys, stake, candidacy, or election. | Generate the public enrollment package. |
| Candidate | Bonded ledger, matching session.nextKeys, and staking.validators intent at a finalized head. | An active validator slot. | Keep the node online and watch the election. |
| Queued | Account appears in the finalized queued session keys. | Current-session authority or authorship. | Wait for the stated session boundary. |
| Active | Account appears in finalized session.validators and authority views. | Healthy operation or reward credit. | Prove authorship, finality, and time quality. |
| Rewarded | Finalized reward event or credited staking balance attributable to the validator and era. | Positive net income. | Reconcile the reward receipt against costs. |
| Profitable | Realized revenue minus infrastructure, timing, labor, capital, taxes, fees, downtime, and losses is positive for the chosen period. | Future returns. | Recalculate continuously; no return is guaranteed. |
Node → candidate → authority → measured operator
Normal candidacy needs no incumbent-validator, operator, Tally, or Sudo approval.
Price the host, storage growth, bandwidth, timing hardware or licence, monitoring, backup, incident response, labor, capital, taxes, and a loss reserve. Treat testnet tokens and unissued program terms as zero revenue.
Use the planning worksheetUse the guided installer. Match the configured-testnet genesis, pin a verified release, keep author and unsafe RPC on loopback, expose only reviewed P2P, synchronize completely, then prove finality and identity persistence after restart.
Open guided installKeep the funding account on a separate wallet or offline signer. Encrypt node and session material, keep a tested recovery path, and never paste a seed, secret URI, keystore, node-key bytes, token, licence, or reusable signature into a browser, command line, support form, chat, or agent.
Review custody optionsRun the release-matched roko-validator-enroll command against 127.0.0.1:9944. It verifies genesis, runtime, clock, peers, finality, P2P reachability, non-authoring mode, and local custody of all seven public session identifiers. Inspect the JSON before uploading it.
Import the package and require Package verified. Confirm chain ID 52370, account, genesis, runtime, fees, and effects. Finalize the lock, bond, session.setKeys, and staking.validate calls separately. The current testnet walkthrough uses 50 ROKO plus fees; it is not a mainnet minimum or a profitability claim.
Record rollback, stop the full-node service, prove the process and database lock are gone, load only this node's session keystore, and start the release-matched validator service. Preserve the base path, peer identity, session keys, time configuration, and protected RPC boundary.
Follow the activation gateSelection is competitive and not guaranteed. Watch candidate, queued, and active states at one finalized head. Call the node operational only after active membership, finalized authorship, advancing finality, healthy peers, and non-null temporal evidence are all visible.
Inspect validators without a walletOpen the validator's Agora detail page for finalized payout events, fees, slashes, era claim state, and downloadable JSON or CSV evidence. Use credited rewards—not an advertised APY, block count, pending estimate, or token grant. Record the era, transaction or event, amount, valuation method, every cost, and any slash or downtime loss. Only this ledger can support a profitability claim.
Open finalized validator economicsPlanning tool · local browser calculation
Enter your own realized or conservative values. Nothing is sent or stored. A positive result is historical scenario math, not a promise of future rewards, token price, election, uptime, or profit.
Stay eligible and available
Before stopping a validator, verify that the remaining active authority weight meets the current finality threshold. Candidates do not provide active voting weight. Record the finalized head and independent reference, preserve chain data and identities, and stop the service gracefully before host shutdown.
After startup, wait for storage and clock readiness, peers, and full synchronization. Compare advancing finalized heights and matching hashes with an independent node, then require fresh finalized authorship from an active validator. A historical AUTHORED or readyToAuthor result is insufficient. Successful service restart does not prove cold-boot recovery.
Service down, peer loss, finality lag, clock loss, missing authoring, disk pressure, session-key mismatch, and unexpected RPC exposure need actionable alerts.
Check finalized active membership, authority views, recent authorship, and temporal evidence. A running process can silently cease to be an effective validator.
Record credited rewards, commission, fees, slash/offence events, token valuation basis, and costs. Retain exportable receipts for accounting and review.
Verify signatures and hashes, preserve identity and keys, record rollback, and require active membership, authorship, finality, and timing acceptance before the next rollout.
Generate a fresh package. Keep old keys until replacement keys are active and have authored a finalized block; then retire the old material deliberately.
Restore encrypted backups on an isolated host, verify peer and public session identities, test alert routing and rollback, and update cost and capacity assumptions.
Symptoms → evidence → safe action
| Symptom | Check first | Safe response |
|---|---|---|
| Package rejected | Expiry, exact genesis/runtime/metadata digests, P2P reachability, seven-key order, local keystore proof. | Fix the node evidence and generate a fresh package. Never edit key fields by hand. |
| Candidate, never queued | Finalized bond, intent, keys, election capacity, stake exposure, nomination preference. | Remain online, review competitiveness, and change only public staking preferences or stake. Do not claim activation. |
| Active, no authorship | Local keystore, key tuple, node profile, peers, clock, BABE/GRANDPA/Temporal views, logs. | Protect finality, use the documented rollback/recovery path, and avoid destructive key regeneration. |
| Finality or time degraded | Independent clock sources, root distance, direct authority peers, disk/CPU/network saturation. | Restore stable service; chill before extended maintenance when the finalized state and timing permit. |
| Exit requested | Finalized chill, removal from active session, bonding duration, unlocking chunks. | Stay online until no longer active, then unbond and withdraw only after the chain reports maturity. |
| Revenue below cost | Credited—not pending—rewards, election share, commission, uptime, costs, losses, valuation method. | Update the ledger and operational plan. Chill and exit safely if the risk-adjusted case no longer works. |
The next objective action
Use the installer before touching stake. Use Agora for wallet actions and finalized public evidence. Use the technical runbook for exact commands and custody boundaries.