Validator lifecycle
Run a Tenzro Network 1 validator on any TPM 2.0 machine: hardware-derived keys, registration, activation, upgrades, exit and unbonding.
Any machine with a TPM 2.0 can validate Tenzro Network 1. This page follows a validator from first boot to exit: how its keys work, how it joins the active set, how to upgrade and move it, and how it leaves.
Keys from hardware
A validator has no key file. Its identity is a hardware key in the TPM 2.0 (or a Secure Enclave on Apple hardware):
- Signing keys are derived from the hardware on demand, used in memory and wiped.
- The hardware key signs the handshake of every validator channel, as a composite ML-DSA-65 plus P-256 signature. See Networking.
- At the start of each epoch the hardware certifies an in-memory session key. The validator signs its consensus votes for that epoch with the session key, so the TPM is not on the hot path of every round.
- When the epoch ends the session key is discarded and a new one is certified.
Because every vote chains back to a hardware key, a validator's signatures are attributable, and conflicting signatures are evidence for slashing.
States
| State | Meaning |
|---|---|
Candidate | Registered with a bond; not yet scheduled |
PendingActive | Accepted; becomes active at the next epoch boundary |
Active | Proposes, votes and signs finality certificates |
PendingExit | Has asked to leave; still active until the boundary |
Exited | Out of the set; bond unbonding |
Jailed | Removed from the active set after a slashable offence |
tenzro validator list --status Active
tenzro validator get 0xValidatorAddress1. Start the node
Build or install tenzro-node (see Deployment) and start it with the validator role:
tenzro-node \
--roles validator \
--data-dir ./data \
--genesis genesis.toml \
--bootstrap-dns <zone>The node derives its keys from the TPM, joins the network as a non-voting peer and syncs. A fresh node syncs from a verified snapshot instead of replaying from genesis; see State and snapshots.
The guided setup does the same and writes the configuration for you:
tenzro setup --path network --mode validate2. Register
Registration is a signed transaction from the account that owns the stake. It records the validator's hardware key, a withdrawal address for rewards and unbonded stake, and the self-stake. A node can register itself on start with --validator-self-stake, or you can register from the CLI with tenzro validator register.
Validation is permissionless: there is no allowlist and no approval step. The bond requirement is set by governance. One stake can also back other roles the node runs; see Operators and roles.
3. Activate at the epoch boundary
The validator set changes only at epoch boundaries. A registered validator becomes PendingActive, then Active at the next boundary, when its first session key is certified and its channels to the other validators are opened. From then on it proposes a vertex every round and signs checkpoints; see Consensus.
Rewards come from a finite genesis pool and from fees, and are paid to the withdrawal address.
To add stake without re-registering:
tenzro validator increase-stake --from 0xStakeOwner --additional <wei>Upgrading the binary
An upgrade is a stop and restart against the same data directory. On start, the node checks the chain on disk against the configured genesis. If they match, it keeps its database and carries on; if they differ, it refuses to start with an error, so a node never runs on the wrong chain by mistake.
Moving to new hardware
A validator's identity is its registered hardware key. To move to a new machine, rotate the registered key with tenzro_rotateValidatorKey, signed by the current key. The new key takes over at the next epoch boundary, when every validator picks up the change at once, so there is no window with two live keys.
Bootstrap discovery
Point --bootstrap-dns at a zone that publishes _tenzro-boot._tcp SRV records and _tenzro-id._tcp TXT records with each bootstrap peer's id. Changing the bootstrap set is then a DNS edit rather than a change on every node. See Networking.
4. Exit
To leave, send a signed exit transaction:
tenzro validator exit --from 0xStakeOwnerThe validator moves to PendingExit, keeps validating until the next epoch boundary, then becomes Exited. Its bond enters a 7-day unbonding period and is then released to the withdrawal address. Evidence of misbehaviour from its active time can still be submitted during unbonding.
Slashing
A validator is slashed for signing two conflicting checkpoints, proven by its own signatures, or for a provable breach of its own signed operator policy. Slashing burns the offender's bond and removes it from the active set. See Slashing.
Monitoring
curl -s https://rpc.tenzro.xyz \
-H 'content-type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tenzro_listActiveValidators","params":[]}'Your own node reports its state, roles, height and peers at GET /status on its Web API, and exports Prometheus metrics at /metrics.