[Tutorial] Run your own satellite (part 21) - Tag signer (storagenode tag)

What is storagenode tag?

Node tags are arbitrary key=value pairs about a storagenode, signed by an authority. A storagenode presents them to the satellite when it checks in.

If the satellite trusts the signer, it stores the tags and can use them in placement rules.

For example: “only store this data on nodes tagged datacenter=true”.

Who can sign these tags?

tag-signer is the command-line tool that creates and inspects these signed tags.

satellite can sign the tags, a different identity can sign the tags, storagenode can also sign the tags.

What?

If the tag signed using satellite identity, it work out of the box.

If signed by a different entity, satellite could choose to trust it using --tag-authorities flag.

If signed by storagenode identity, when storagenode run, instead of using --contact.tags, storagenode would use --contact.self-signed-tags.


But - there is a different between satellite/another entity signed tag versus storagenode self signed tags:

If storagenode self signed tags, you list the key/value directly, eg:

--contact.self-signed-tags="datacenter=true,region=eu,storage_price=1.5"

But when satellite sign, it should look like this:

--contact.tags="Cs4BCmAKIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAEhIKCmRhdGFjZW50ZXISBHRydWUSDAoGcmVnaW9uEgJldRIUCgdzb21la2V5Eglzb21ldmFsdWUY+MOP1gYaIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAIkgwRgIhAOzXiooze55EsDaujM9MyqYBtH192EJzlaQWJUfVlavvAiEA+9LLg7ppcCyH5hS0EqosYd78q713KbJOBBy0R09cco0="

# --contact.tags="<base64_signer_A>,<another_base64_signer_A>,<base64_signer_B>"

Satellite sign tags workflow

./tag-signer sign --identity-dir id/satellite --node-id <base58_of_storagenode_id> datacenter=true region=eu somekey=somevalue

# result
# Cs4BCmAKIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAEhIKCmRhdGFjZW50ZXISBHRydWUSDAoGcmVnaW9uEgJldRIUCgdzb21la2V5Eglzb21ldmFsdWUY+MOP1gYaIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAIkgwRgIhAOzXiooze55EsDaujM9MyqYBtH192EJzlaQWJUfVlavvAiEA+9LLg7ppcCyH5hS0EqosYd78q713KbJOBBy0R09cco0=

# inspect using tag-signer
./tag-signer inspect Cs4BCmAKIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAEhIKCmRhdGFjZW50ZXISBHRydWUSDAoGcmVnaW9uEgJldRIUCgdzb21la2V5Eglzb21ldmFsdWUY+MOP1gYaIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAIkgwRgIhAOzXiooze55EsDaujM9MyqYBtH192EJzlaQWJUfVlavvAiEA+9LLg7ppcCyH5hS0EqosYd78q713KbJOBBy0R09cco0=

Trusted Node

trusted_node=true is special flag, it lets a brand-new node skip the node ID difficulty check when it first registers with the satellite - will not work with self signed tags.

This is probably for Commercial Selected Node.

Placement

Not sure if it just me but I’d got confused with this string 12Q8q2PofHPwycSwAVCpjNxxzWiDJhi8UV4ceZBo4hmNARpYcR7 in placement templates.

templates:
    SIGNER: 12Q8q2PofHPwycSwAVCpjNxxzWiDJhi8UV4ceZBo4hmNARpYcR7

SIGNER is just a variable name.
12Q8q2PofHPwycSwAVCpjNxxzWiDJhi8UV4ceZBo4hmNARpYcR7 is the base58 of satellite id (if you use satellite identity to sign for storagenode).

1 Like