Skip to content
Tenzro
Documentation menu
Consensus and ledger

Validator lifecycle

Run a Tenzro Network 1 validator on any TPM 2.0 machine: hardware-derived keys, registration, activation, upgrades, exit and unbonding.

Any machine with a TPM 2.0 can validate Tenzro Network 1. This page follows a validator from first boot to exit: how its keys work, how it joins the active set, how to upgrade and move it, and how it leaves.

Keys from hardware

A validator has no key file. Its identity is a hardware key in the TPM 2.0 (or a Secure Enclave on Apple hardware):

  • Signing keys are derived from the hardware on demand, used in memory and wiped.
  • The hardware key signs the handshake of every validator channel, as a composite ML-DSA-65 plus P-256 signature. See Networking.
  • At the start of each epoch the hardware certifies an in-memory session key. The validator signs its consensus votes for that epoch with the session key, so the TPM is not on the hot path of every round.
  • When the epoch ends the session key is discarded and a new one is certified.

Because every vote chains back to a hardware key, a validator's signatures are attributable, and conflicting signatures are evidence for slashing.

States

StateMeaning
CandidateRegistered with a bond; not yet scheduled
PendingActiveAccepted; becomes active at the next epoch boundary
ActiveProposes, votes and signs finality certificates
PendingExitHas asked to leave; still active until the boundary
ExitedOut of the set; bond unbonding
JailedRemoved from the active set after a slashable offence
bash
tenzro validator list --status Active
tenzro validator get 0xValidatorAddress

1. Start the node

Build or install tenzro-node (see Deployment) and start it with the validator role:

bash
tenzro-node \
  --roles validator \
  --data-dir ./data \
  --genesis genesis.toml \
  --bootstrap-dns <zone>

The node derives its keys from the TPM, joins the network as a non-voting peer and syncs. A fresh node syncs from a verified snapshot instead of replaying from genesis; see State and snapshots.

The guided setup does the same and writes the configuration for you:

bash
tenzro setup --path network --mode validate

2. Register

Registration is a signed transaction from the account that owns the stake. It records the validator's hardware key, a withdrawal address for rewards and unbonded stake, and the self-stake. A node can register itself on start with --validator-self-stake, or you can register from the CLI with tenzro validator register.

Validation is permissionless: there is no allowlist and no approval step. The bond requirement is set by governance. One stake can also back other roles the node runs; see Operators and roles.

3. Activate at the epoch boundary

The validator set changes only at epoch boundaries. A registered validator becomes PendingActive, then Active at the next boundary, when its first session key is certified and its channels to the other validators are opened. From then on it proposes a vertex every round and signs checkpoints; see Consensus.

Rewards come from a finite genesis pool and from fees, and are paid to the withdrawal address.

To add stake without re-registering:

bash
tenzro validator increase-stake --from 0xStakeOwner --additional <wei>

Upgrading the binary

An upgrade is a stop and restart against the same data directory. On start, the node checks the chain on disk against the configured genesis. If they match, it keeps its database and carries on; if they differ, it refuses to start with an error, so a node never runs on the wrong chain by mistake.

Moving to new hardware

A validator's identity is its registered hardware key. To move to a new machine, rotate the registered key with tenzro_rotateValidatorKey, signed by the current key. The new key takes over at the next epoch boundary, when every validator picks up the change at once, so there is no window with two live keys.

Bootstrap discovery

Point --bootstrap-dns at a zone that publishes _tenzro-boot._tcp SRV records and _tenzro-id._tcp TXT records with each bootstrap peer's id. Changing the bootstrap set is then a DNS edit rather than a change on every node. See Networking.

4. Exit

To leave, send a signed exit transaction:

bash
tenzro validator exit --from 0xStakeOwner

The validator moves to PendingExit, keeps validating until the next epoch boundary, then becomes Exited. Its bond enters a 7-day unbonding period and is then released to the withdrawal address. Evidence of misbehaviour from its active time can still be submitted during unbonding.

Slashing

A validator is slashed for signing two conflicting checkpoints, proven by its own signatures, or for a provable breach of its own signed operator policy. Slashing burns the offender's bond and removes it from the active set. See Slashing.

Monitoring

bash
curl -s https://rpc.tenzro.xyz \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tenzro_listActiveValidators","params":[]}'

Your own node reports its state, roles, height and peers at GET /status on its Web API, and exports Prometheus metrics at /metrics.