diff --git a/samples/deployment/fablo/README.md b/samples/deployment/fablo/README.md new file mode 100644 index 000000000..e48f42715 --- /dev/null +++ b/samples/deployment/fablo/README.md @@ -0,0 +1,189 @@ +# FPC with Fablo - Deployment Sample + +This sample demonstrates how to deploy and run Fabric Private Chaincode (FPC) using [Fablo](https://github.com/hyperledger-labs/fablo) for network management. It uses the `echo-go` chaincode and the `simple-cli-go` client application. + +## Overview + +[Fablo](https://github.com/hyperledger-labs/fablo) is a tool that simplifies the process of setting up Hyperledger Fabric networks. This sample shows how to: + +1. Configure a Fablo network with FPC-specific requirements (SGX support) +2. Deploy the FPC Enclave Registry Chaincode (ERCC) +3. Deploy the echo-go FPC chaincode +4. Interact with the chaincode using the simple-cli-go client + +## Prerequisites + +### Required Software + +- **Docker** (v20.x or later) +- **Docker Compose** (v1.29 or later) +- **Fablo** (v1.2.0 or later) - Will be downloaded by setup script +- **FPC** - This repository must be built (see main [README](../../../README.md)) +- **Intel SGX** drivers and PSW (for hardware mode) + - For simulation mode, SGX hardware is not required +- **curl** - For downloading Fablo + +### Environment Setup + +Make sure you have built FPC and set the `FPC_PATH` environment variable: + +```bash +export FPC_PATH=/path/to/fabric-private-chaincode +``` + +For SGX hardware mode, also set: + +```bash +export SGX_MODE=HW +export SGX_CREDENTIALS_PATH=$FPC_PATH/config/ias +``` + +For simulation mode (no SGX hardware required): + +```bash +export SGX_MODE=SIM +``` + +## Quick Start + +### 1. Build FPC Components + +First, build the echo-go chaincode and ERCC: + +```bash +# Build echo-go chaincode +make -C $FPC_PATH/samples/chaincode/echo-go build docker + +# Build ERCC +make -C $FPC_PATH/ercc all docker + +# Build FPC chaincode environment +make -C $FPC_PATH/utils/docker pull +# or build from scratch: +# make -C $FPC_PATH/utils/docker build +``` + +### 2. Setup and Start Network + +Run the setup script to install Fablo (if needed) and start the network: + +```bash +cd $FPC_PATH/samples/deployment/fablo +./scripts/setup.sh +``` + +This script will: +- Install Fablo if not already installed +- Generate the Fabric network using Fablo +- Start the network +- Deploy ERCC +- Deploy the echo-go chaincode +- Initialize the FPC enclave + +### 3. Interact with the Chaincode + +Use the simple-cli-go client to interact with the chaincode: + +```bash +# Source environment variables +source ./config/fpcclient-env.sh + +# Initialize the enclave (first time only) +cd $FPC_PATH/samples/application/simple-cli-go +./fpcclient init peer0.org1.example.com + +# Invoke the chaincode +./fpcclient invoke "Hello FPC with Fablo!" + +# Query the chaincode +./fpcclient query +``` + +### 4. Shutdown + +To stop and clean up the network: + +```bash +cd $FPC_PATH/samples/deployment/fablo +./scripts/teardown.sh +``` + +## Directory Structure + +``` +fablo/ +├── README.md # This file +├── fablo-config.json # Fablo network configuration +├── fablo-config.yaml # Alternative YAML format +├── docker-compose-fpc-override.yaml # FPC-specific Docker overrides +├── scripts/ +│ ├── setup.sh # Main setup script +│ ├── deploy-ercc.sh # Deploy ERCC +│ ├── deploy-chaincode.sh # Deploy echo-go chaincode +│ ├── init-enclave.sh # Initialize FPC enclave +│ ├── teardown.sh # Cleanup script +│ └── validate.sh # Validation checks +├── config/ +│ ├── connection-org1.yaml # Connection profile for Org1 +│ ├── connection-org2.yaml # Connection profile for Org2 +│ └── fpcclient-env.sh # Environment variables for client +├── compose/ +│ ├── ercc-compose.yaml # ERCC container configuration +│ └── ecc-compose.yaml # Echo chaincode container configuration +└── docs/ + ├── SETUP.md # Detailed setup instructions + ├── USAGE.md # Usage guide + └── TROUBLESHOOTING.md # Common issues and solutions +``` + +## Network Topology + +The Fablo configuration creates a network with: + +- **2 Organizations**: Org1 and Org2 +- **2 Peers**: One peer per organization (with SGX support) +- **1 Orderer**: Solo orderer for simplicity +- **1 Channel**: `mychannel` +- **2 Chaincodes**: + - `ercc` - FPC Enclave Registry Chaincode + - `echo-go` - FPC Echo chaincode + +## Key Features + +### FPC-Specific Configurations + +This sample includes several FPC-specific configurations: + +1. **SGX Device Mounting**: Peers have access to `/dev/sgx` device +2. **AESM Service**: Volume mount for SGX AESM service +3. **FPC Environment Variables**: Proper configuration for FPC runtime +4. **Chaincode as a Service**: FPC chaincodes run as external services +5. **ERCC First**: ERCC is deployed before application chaincodes + +### Differences from Test-Network Sample + +Compared to the `test-network` sample, this Fablo-based sample: + +- Uses Fablo for network generation (no fabric-samples dependency) +- Provides declarative YAML configuration +- Generates its own crypto materials +- Simplifies network management with Fablo commands +- Demonstrates integration with a different network setup tool + +## Documentation + +For more detailed information, see: + +- [SETUP.md](docs/SETUP.md) - Detailed setup instructions +- [USAGE.md](docs/USAGE.md) - Usage examples and workflows +- [TROUBLESHOOTING.md](docs/TROUBLESHOOTING.md) - Common issues and solutions + +## References + +- [FPC Documentation](https://github.com/hyperledger/fabric-private-chaincode) +- [Fablo Documentation](https://github.com/hyperledger-labs/fablo/wiki) +- [Hyperledger Fabric Documentation](https://hyperledger-fabric.readthedocs.io/) + +## License + +This sample is part of the Fabric Private Chaincode project and follows the same license (Apache-2.0). \ No newline at end of file diff --git a/samples/deployment/fablo/compose/ecc-compose.yaml b/samples/deployment/fablo/compose/ecc-compose.yaml new file mode 100644 index 000000000..79d810263 --- /dev/null +++ b/samples/deployment/fablo/compose/ecc-compose.yaml @@ -0,0 +1,54 @@ +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Docker Compose file for FPC Echo Chaincode (ECC) containers + +version: '2.1' + +networks: + fablo-network: + external: true + name: fablo_default + +services: + echo-go.peer0.org1.example.com: + container_name: echo-go.peer0.org1.example.com + image: fpc/echo-go:${CC_VER} + environment: + - CHAINCODE_PKG_ID=${CC_PKG_ID_ORG1} + - CHAINCODE_SERVER_ADDRESS=0.0.0.0:9999 + - FABRIC_LOGGING_SPEC=chaincode=debug:ecc=debug + - CORE_CHAINCODE_ID_NAME=${CC_PKG_ID_ORG1} + - SGX_MODE=${SGX_MODE:-HW} + devices: + - /dev/sgx_enclave:/dev/sgx_enclave + - /dev/sgx_provision:/dev/sgx_provision + volumes: + - /var/run/aesmd:/var/run/aesmd + working_dir: /opt/gopath/src/github.com/hyperledger/fabric-private-chaincode/samples/chaincode/echo-go + networks: + - fablo-network + restart: unless-stopped + + echo-go.peer0.org2.example.com: + container_name: echo-go.peer0.org2.example.com + image: fpc/echo-go:${CC_VER} + environment: + - CHAINCODE_PKG_ID=${CC_PKG_ID_ORG2} + - CHAINCODE_SERVER_ADDRESS=0.0.0.0:9999 + - FABRIC_LOGGING_SPEC=chaincode=debug:ecc=debug + - CORE_CHAINCODE_ID_NAME=${CC_PKG_ID_ORG2} + - SGX_MODE=${SGX_MODE:-HW} + devices: + - /dev/sgx_enclave:/dev/sgx_enclave + - /dev/sgx_provision:/dev/sgx_provision + volumes: + - /var/run/aesmd:/var/run/aesmd + working_dir: /opt/gopath/src/github.com/hyperledger/fabric-private-chaincode/samples/chaincode/echo-go + networks: + - fablo-network + restart: unless-stopped + +# Made with Bob diff --git a/samples/deployment/fablo/compose/ercc-compose.yaml b/samples/deployment/fablo/compose/ercc-compose.yaml new file mode 100644 index 000000000..dc92c28bc --- /dev/null +++ b/samples/deployment/fablo/compose/ercc-compose.yaml @@ -0,0 +1,42 @@ +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Docker Compose file for FPC Enclave Registry Chaincode (ERCC) containers + +version: '2.1' + +networks: + fablo-network: + external: true + name: fablo_default + +services: + ercc.peer0.org1.example.com: + container_name: ercc.peer0.org1.example.com + image: fpc/ercc:${FPC_VERSION:-latest} + environment: + - CHAINCODE_PKG_ID=${ERCC_PKG_ID_ORG1} + - CHAINCODE_SERVER_ADDRESS=0.0.0.0:9999 + - FABRIC_LOGGING_SPEC=chaincode=debug:ercc=debug + - CORE_CHAINCODE_ID_NAME=${ERCC_PKG_ID_ORG1} + working_dir: /opt/gopath/src/github.com/hyperledger/fabric-private-chaincode/ercc + networks: + - fablo-network + restart: unless-stopped + + ercc.peer0.org2.example.com: + container_name: ercc.peer0.org2.example.com + image: fpc/ercc:${FPC_VERSION:-latest} + environment: + - CHAINCODE_PKG_ID=${ERCC_PKG_ID_ORG2} + - CHAINCODE_SERVER_ADDRESS=0.0.0.0:9999 + - FABRIC_LOGGING_SPEC=chaincode=debug:ercc=debug + - CORE_CHAINCODE_ID_NAME=${ERCC_PKG_ID_ORG2} + working_dir: /opt/gopath/src/github.com/hyperledger/fabric-private-chaincode/ercc + networks: + - fablo-network + restart: unless-stopped + +# Made with Bob diff --git a/samples/deployment/fablo/config/connection-org1.yaml b/samples/deployment/fablo/config/connection-org1.yaml new file mode 100644 index 000000000..04529f4b7 --- /dev/null +++ b/samples/deployment/fablo/config/connection-org1.yaml @@ -0,0 +1,89 @@ +--- +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Connection profile for Org1 +# This file is used by the FPC client to connect to the Fabric network + +name: "fpc-fablo-network-org1" +version: "1.0" + +client: + organization: Org1 + connection: + timeout: + peer: + endorser: 300 + orderer: 300 + +channels: + mychannel: + orderers: + - orderer0.group1.orderer.example.com + peers: + peer0.org1.example.com: + endorsingPeer: true + chaincodeQuery: true + ledgerQuery: true + eventSource: true + peer0.org2.example.com: + endorsingPeer: true + chaincodeQuery: true + ledgerQuery: true + eventSource: true + +organizations: + Org1: + mspid: Org1MSP + peers: + - peer0.org1.example.com + certificateAuthorities: + - ca.org1.example.com + cryptoPath: ../target/fabric-config/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp + + Org2: + mspid: Org2MSP + peers: + - peer0.org2.example.com + +orderers: + orderer0.group1.orderer.example.com: + url: grpcs://localhost:7030 + grpcOptions: + ssl-target-name-override: orderer0.group1.orderer.example.com + grpc-max-send-message-length: 15 + tlsCACerts: + path: ../target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt + +peers: + peer0.org1.example.com: + url: grpcs://localhost:7041 + grpcOptions: + ssl-target-name-override: peer0.org1.example.com + grpc.keepalive_time_ms: 600000 + tlsCACerts: + path: ../target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt + + peer0.org2.example.com: + url: grpcs://localhost:7061 + grpcOptions: + ssl-target-name-override: peer0.org2.example.com + grpc.keepalive_time_ms: 600000 + tlsCACerts: + path: ../target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt + +certificateAuthorities: + ca.org1.example.com: + url: https://localhost:7020 + httpOptions: + verify: false + tlsCACerts: + path: ../target/fabric-config/crypto-config/peerOrganizations/org1.example.com/ca/ca.org1.example.com-cert.pem + registrar: + - enrollId: admin + enrollSecret: adminpw + caName: ca.org1.example.com + +# Made with Bob diff --git a/samples/deployment/fablo/config/connection-org2.yaml b/samples/deployment/fablo/config/connection-org2.yaml new file mode 100644 index 000000000..ba7bb3bcd --- /dev/null +++ b/samples/deployment/fablo/config/connection-org2.yaml @@ -0,0 +1,89 @@ +--- +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Connection profile for Org2 +# This file is used by the FPC client to connect to the Fabric network + +name: "fpc-fablo-network-org2" +version: "1.0" + +client: + organization: Org2 + connection: + timeout: + peer: + endorser: 300 + orderer: 300 + +channels: + mychannel: + orderers: + - orderer0.group1.orderer.example.com + peers: + peer0.org1.example.com: + endorsingPeer: true + chaincodeQuery: true + ledgerQuery: true + eventSource: true + peer0.org2.example.com: + endorsingPeer: true + chaincodeQuery: true + ledgerQuery: true + eventSource: true + +organizations: + Org1: + mspid: Org1MSP + peers: + - peer0.org1.example.com + + Org2: + mspid: Org2MSP + peers: + - peer0.org2.example.com + certificateAuthorities: + - ca.org2.example.com + cryptoPath: ../target/fabric-config/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp + +orderers: + orderer0.group1.orderer.example.com: + url: grpcs://localhost:7030 + grpcOptions: + ssl-target-name-override: orderer0.group1.orderer.example.com + grpc-max-send-message-length: 15 + tlsCACerts: + path: ../target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt + +peers: + peer0.org1.example.com: + url: grpcs://localhost:7041 + grpcOptions: + ssl-target-name-override: peer0.org1.example.com + grpc.keepalive_time_ms: 600000 + tlsCACerts: + path: ../target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt + + peer0.org2.example.com: + url: grpcs://localhost:7061 + grpcOptions: + ssl-target-name-override: peer0.org2.example.com + grpc.keepalive_time_ms: 600000 + tlsCACerts: + path: ../target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt + +certificateAuthorities: + ca.org2.example.com: + url: https://localhost:7040 + httpOptions: + verify: false + tlsCACerts: + path: ../target/fabric-config/crypto-config/peerOrganizations/org2.example.com/ca/ca.org2.example.com-cert.pem + registrar: + - enrollId: admin + enrollSecret: adminpw + caName: ca.org2.example.com + +# Made with Bob diff --git a/samples/deployment/fablo/config/fpcclient-env.sh b/samples/deployment/fablo/config/fpcclient-env.sh new file mode 100644 index 000000000..78e28f814 --- /dev/null +++ b/samples/deployment/fablo/config/fpcclient-env.sh @@ -0,0 +1,63 @@ +#!/bin/bash + +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Environment variables for FPC client (simple-cli-go) +# Source this file before using the fpcclient: +# source config/fpcclient-env.sh + +# Get the sample directory +SAMPLE_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" + +# FPC Configuration +export FPC_PATH="${FPC_PATH:-}" +if [ -z "$FPC_PATH" ]; then + echo "Warning: FPC_PATH is not set. Please set it to your FPC repository path." + echo "Example: export FPC_PATH=/path/to/fabric-private-chaincode" +fi + +# Chaincode Configuration +export CC_ID="${CC_ID:-echo-go}" +export CHANNEL_NAME="${CHANNEL_NAME:-mychannel}" + +# SGX Configuration +export SGX_MODE="${SGX_MODE:-SIM}" + +# Peer Configuration (Org1) +export CORE_PEER_ID="peer0.org1.example.com" +export CORE_PEER_ADDRESS="localhost:7041" +export CORE_PEER_LOCALMSPID="Org1MSP" +export CORE_PEER_TLS_ENABLED=true +export CORE_PEER_TLS_ROOTCERT_FILE="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" +export CORE_PEER_MSPCONFIGPATH="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp" + +# Gateway Configuration +export GATEWAY_CONFIG="$SAMPLE_DIR/config/connection-org1.yaml" + +# Orderer Configuration +export ORDERER_ADDR="localhost:7030" +export ORDERER_CA="$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" + +# SGX Credentials Path (for hardware mode) +if [ "$SGX_MODE" = "HW" ]; then + export SGX_CREDENTIALS_PATH="${SGX_CREDENTIALS_PATH:-$FPC_PATH/config/ias}" +fi + +# Display configuration +echo "FPC Client Environment Variables:" +echo " FPC_PATH: $FPC_PATH" +echo " CC_ID: $CC_ID" +echo " CHANNEL_NAME: $CHANNEL_NAME" +echo " SGX_MODE: $SGX_MODE" +echo " CORE_PEER_ID: $CORE_PEER_ID" +echo " CORE_PEER_ADDRESS: $CORE_PEER_ADDRESS" +echo " GATEWAY_CONFIG: $GATEWAY_CONFIG" +echo "" +echo "Ready to use fpcclient!" +echo "Navigate to: cd \$FPC_PATH/samples/application/simple-cli-go" +echo "Then run: ./fpcclient init $CORE_PEER_ID" + +# Made with Bob diff --git a/samples/deployment/fablo/docker-compose-fpc-override.yaml b/samples/deployment/fablo/docker-compose-fpc-override.yaml new file mode 100644 index 000000000..777785596 --- /dev/null +++ b/samples/deployment/fablo/docker-compose-fpc-override.yaml @@ -0,0 +1,32 @@ +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# This file provides FPC-specific Docker Compose overrides for the Fablo-generated network. +# It adds SGX device support and FPC environment variables to peer containers. + +version: '2.1' + +services: + peer0.org1.example.com: + devices: + - /dev/sgx_enclave:/dev/sgx_enclave + - /dev/sgx_provision:/dev/sgx_provision + environment: + - CORE_PEER_FPC_ENABLED=true + - SGX_MODE=${SGX_MODE:-HW} + volumes: + - /var/run/aesmd:/var/run/aesmd + + peer0.org2.example.com: + devices: + - /dev/sgx_enclave:/dev/sgx_enclave + - /dev/sgx_provision:/dev/sgx_provision + environment: + - CORE_PEER_FPC_ENABLED=true + - SGX_MODE=${SGX_MODE:-HW} + volumes: + - /var/run/aesmd:/var/run/aesmd + +# Made with Bob diff --git a/samples/deployment/fablo/docs/SETUP.md b/samples/deployment/fablo/docs/SETUP.md new file mode 100644 index 000000000..8d205714d --- /dev/null +++ b/samples/deployment/fablo/docs/SETUP.md @@ -0,0 +1,287 @@ +# FPC with Fablo - Detailed Setup Guide + +This guide provides detailed instructions for setting up and running Fabric Private Chaincode (FPC) with Fablo network management. + +## Table of Contents + +- [Prerequisites](#prerequisites) +- [System Requirements](#system-requirements) +- [Installation Steps](#installation-steps) +- [Configuration](#configuration) +- [Verification](#verification) +- [Next Steps](#next-steps) + +## Prerequisites + +### Required Software + +1. **Docker** (v20.x or later) + ```bash + docker --version + ``` + +2. **Docker Compose** (v1.29 or later) + ```bash + docker-compose --version + ``` + +3. **curl** - Required for downloading Fablo + ```bash + curl --version + ``` + +4. **Go** (v1.19 or later) - Required for building FPC components + ```bash + go version + ``` + +5. **Git** + ```bash + git --version + ``` + +### Intel SGX (Optional for Hardware Mode) + +For running in SGX hardware mode, you need: + +- Intel SGX-capable CPU +- SGX drivers installed +- SGX Platform Software (PSW) installed +- AESM service running + +To check if your system supports SGX: +```bash +cpuid | grep SGX +``` + +For development and testing, you can use **simulation mode** which doesn't require SGX hardware. + +## System Requirements + +### Minimum Requirements + +- **CPU**: 4 cores (8 cores recommended) +- **RAM**: 8 GB (16 GB recommended) +- **Disk**: 20 GB free space +- **OS**: Linux (Ubuntu 20.04 or later recommended) + +### Supported Operating Systems + +- Ubuntu 20.04 LTS or later +- Other Linux distributions with Docker support +- macOS (with Docker Desktop) - Simulation mode only +- Windows with WSL2 (with Docker Desktop) - Simulation mode only + +## Installation Steps + +### Step 1: Clone and Build FPC Repository + +1. Clone the FPC repository: + ```bash + git clone https://github.com/hyperledger/fabric-private-chaincode.git + cd fabric-private-chaincode + ``` + +2. Set the FPC_PATH environment variable: + ```bash + export FPC_PATH=$(pwd) + echo "export FPC_PATH=$FPC_PATH" >> ~/.bashrc + ``` + +3. Build FPC components: + ```bash + # Build ERCC (Enclave Registry Chaincode) + make -C $FPC_PATH/ercc all docker + + # Build echo-go chaincode + make -C $FPC_PATH/samples/chaincode/echo-go build docker + + # Build or pull FPC chaincode environment + make -C $FPC_PATH/utils/docker pull + # Or build from scratch: + # make -C $FPC_PATH/utils/docker build + ``` + +### Step 2: Install Fablo + +Fablo will be automatically downloaded by the setup script, but you can also install it manually: + +```bash +# Download Fablo script (recommended method from official repository) +curl -Lf https://github.com/hyperledger-labs/fablo/releases/download/1.2.0/fablo.sh -o ./fablo && chmod +x ./fablo +``` + +Verify installation: +```bash +./fablo --version +``` + +For more installation options, see the [official Fablo repository](https://github.com/hyperledger-labs/fablo). + +### Step 3: Configure SGX Mode + +Choose your SGX mode based on your hardware: + +**For Simulation Mode (No SGX hardware required):** +```bash +export SGX_MODE=SIM +echo "export SGX_MODE=SIM" >> ~/.bashrc +``` + +**For Hardware Mode (Requires SGX-capable CPU):** +```bash +export SGX_MODE=HW +echo "export SGX_MODE=HW" >> ~/.bashrc + +# Set SGX credentials path (if using IAS attestation) +export SGX_CREDENTIALS_PATH=$FPC_PATH/config/ias +``` + +### Step 4: Navigate to Fablo Sample + +```bash +cd $FPC_PATH/samples/deployment/fablo +``` + +### Step 5: Run Setup Script + +The setup script will: +- Install Fablo (if not already installed) +- Generate and start the Fabric network +- Deploy ERCC +- Deploy echo-go chaincode +- Initialize the FPC enclave + +```bash +./scripts/setup.sh +``` + +This process takes approximately 5-10 minutes depending on your system. + +## Configuration + +### Network Configuration + +The network is configured in `fablo-config.yaml`: + +- **2 Organizations**: Org1 and Org2 +- **2 Peers**: One per organization +- **1 Orderer**: Solo orderer +- **1 Channel**: mychannel + +To modify the network topology, edit `fablo-config.yaml` and regenerate: +```bash +fablo generate +``` + +### FPC-Specific Configuration + +FPC-specific Docker configurations are in `docker-compose-fpc-override.yaml`: + +- SGX device mounting +- AESM service volume +- FPC environment variables + +### Chaincode Configuration + +The echo-go chaincode is configured in `compose/ecc-compose.yaml`: + +- Chaincode as a Service (CaaS) deployment +- SGX device access +- Network connectivity + +## Verification + +### 1. Check Docker Containers + +Verify all containers are running: +```bash +docker ps +``` + +You should see containers for: +- peer0.org1.example.com +- peer0.org2.example.com +- orderer0.group1.orderer.example.com +- ercc.peer0.org1.example.com +- ercc.peer0.org2.example.com +- echo-go.peer0.org1.example.com +- echo-go.peer0.org2.example.com + +### 2. Run Validation Script + +```bash +./scripts/validate.sh +``` + +This script checks: +- Container status +- Network connectivity +- ERCC deployment +- Chaincode deployment +- Enclave registration +- Basic chaincode operations + +### 3. Check Logs + +View logs for specific containers: +```bash +# Peer logs +docker logs peer0.org1.example.com + +# ERCC logs +docker logs ercc.peer0.org1.example.com + +# Echo-go chaincode logs +docker logs echo-go.peer0.org1.example.com +``` + +## Troubleshooting + +### Common Issues + +1. **Port conflicts**: Ensure ports 7020-7061 and 7030 are available +2. **Docker permissions**: User must be in the docker group +3. **SGX device access**: Check `/dev/sgx_enclave` and `/dev/sgx_provision` exist (HW mode) +4. **Memory issues**: Ensure sufficient RAM is available + +For detailed troubleshooting, see [TROUBLESHOOTING.md](TROUBLESHOOTING.md). + +## Next Steps + +After successful setup: + +1. **Source environment variables**: + ```bash + source config/fpcclient-env.sh + ``` + +2. **Use the FPC client**: + ```bash + cd $FPC_PATH/samples/application/simple-cli-go + ./fpcclient init peer0.org1.example.com + ./fpcclient invoke "Hello FPC!" + ./fpcclient query + ``` + +3. **Explore the sample**: See [USAGE.md](USAGE.md) for detailed usage examples + +4. **Tear down when done**: + ```bash + cd $FPC_PATH/samples/deployment/fablo + ./scripts/teardown.sh + ``` + +## Additional Resources + +- [FPC Documentation](https://github.com/hyperledger/fabric-private-chaincode) +- [Fablo Documentation](https://github.com/hyperledger-labs/fablo/wiki) +- [Hyperledger Fabric Documentation](https://hyperledger-fabric.readthedocs.io/) +- [Intel SGX Documentation](https://www.intel.com/content/www/us/en/developer/tools/software-guard-extensions/overview.html) + +## Support + +For issues and questions: +- FPC: [GitHub Issues](https://github.com/hyperledger/fabric-private-chaincode/issues) +- Fablo: [GitHub Issues](https://github.com/hyperledger-labs/fablo/issues) +- Hyperledger Fabric: [Discord](https://discord.gg/hyperledger) \ No newline at end of file diff --git a/samples/deployment/fablo/docs/TROUBLESHOOTING.md b/samples/deployment/fablo/docs/TROUBLESHOOTING.md new file mode 100644 index 000000000..1246709ea --- /dev/null +++ b/samples/deployment/fablo/docs/TROUBLESHOOTING.md @@ -0,0 +1,546 @@ +# FPC with Fablo - Troubleshooting Guide + +This guide helps you diagnose and resolve common issues when using FPC with Fablo. + +## Table of Contents + +- [General Troubleshooting Steps](#general-troubleshooting-steps) +- [Setup Issues](#setup-issues) +- [Network Issues](#network-issues) +- [Chaincode Issues](#chaincode-issues) +- [Enclave Issues](#enclave-issues) +- [Client Issues](#client-issues) +- [Performance Issues](#performance-issues) +- [SGX-Specific Issues](#sgx-specific-issues) + +## General Troubleshooting Steps + +### 1. Check Container Status + +```bash +docker ps -a +``` + +Look for: +- Containers in "Exited" state +- Containers constantly restarting +- Missing containers + +### 2. Check Logs + +```bash +# View all logs +docker-compose -f target/fabric-docker/docker-compose.yaml logs + +# View specific container logs +docker logs + +# Follow logs in real-time +docker logs -f +``` + +### 3. Verify Environment Variables + +```bash +echo $FPC_PATH +echo $SGX_MODE +echo $CHANNEL_NAME +echo $CC_ID +``` + +### 4. Clean and Restart + +```bash +./scripts/teardown.sh --prune +./scripts/setup.sh +``` + +## Setup Issues + +### Issue: "FPC_PATH is not set" + +**Symptom**: Setup script fails with FPC_PATH error + +**Solution**: +```bash +export FPC_PATH=/path/to/fabric-private-chaincode +echo "export FPC_PATH=$FPC_PATH" >> ~/.bashrc +source ~/.bashrc +``` + +### Issue: "Fablo command not found" + +**Symptom**: Setup script cannot find Fablo + +**Solution**: +```bash +# Download Fablo script (official method) +curl -Lf https://github.com/hyperledger-labs/fablo/releases/download/1.2.0/fablo.sh -o ./fablo +chmod +x ./fablo + +# Verify installation +./fablo --version + +# Or let the setup script download it automatically +./scripts/setup.sh +``` + +### Issue: "Docker permission denied" + +**Symptom**: Cannot connect to Docker daemon + +**Solution**: +```bash +# Add user to docker group +sudo usermod -aG docker $USER + +# Log out and log back in, or run: +newgrp docker + +# Verify +docker ps +``` + +### Issue: "Port already in use" + +**Symptom**: Setup fails with "address already in use" + +**Solution**: +```bash +# Check which process is using the port +sudo lsof -i :7041 # Replace with the conflicting port + +# Stop conflicting services or change ports in fablo-config.yaml +``` + +### Issue: "ERCC not built" + +**Symptom**: Setup fails because ERCC binary is missing + +**Solution**: +```bash +cd $FPC_PATH/ercc +make clean +make all docker +``` + +### Issue: "Echo-go chaincode not built" + +**Symptom**: Setup fails because echo-go is not built + +**Solution**: +```bash +cd $FPC_PATH/samples/chaincode/echo-go +make clean +make build docker +``` + +## Network Issues + +### Issue: "Cannot connect to peer" + +**Symptom**: Client or scripts cannot reach peer + +**Solution**: +```bash +# Check if peer is running +docker ps | grep peer + +# Check peer logs +docker logs peer0.org1.example.com + +# Verify network connectivity +docker network inspect fablo_default + +# Restart peer +docker restart peer0.org1.example.com +``` + +### Issue: "TLS handshake failed" + +**Symptom**: TLS certificate errors + +**Solution**: +```bash +# Regenerate network +./scripts/teardown.sh +fablo generate +fablo up + +# Verify certificate paths +ls -la target/fabric-config/crypto-config/ +``` + +### Issue: "Channel not found" + +**Symptom**: Operations fail with "channel does not exist" + +**Solution**: +```bash +# Check if channel exists +peer channel list + +# Recreate channel +./scripts/teardown.sh +./scripts/setup.sh +``` + +## Chaincode Issues + +### Issue: "Chaincode not installed" + +**Symptom**: Chaincode operations fail + +**Solution**: +```bash +# Check installed chaincodes +peer lifecycle chaincode queryinstalled + +# Reinstall if needed +cd $FPC_PATH/samples/deployment/fablo +./scripts/deploy-chaincode.sh +``` + +### Issue: "Chaincode container not starting" + +**Symptom**: Chaincode container exits immediately + +**Solution**: +```bash +# Check chaincode logs +docker logs echo-go.peer0.org1.example.com + +# Common causes: +# 1. Missing package ID environment variable +source config/chaincode-env.sh + +# 2. Image not built +cd $FPC_PATH/samples/chaincode/echo-go +make docker + +# 3. Network connectivity +docker network inspect fablo_default +``` + +### Issue: "Chaincode endorsement failed" + +**Symptom**: Invoke operations fail with endorsement error + +**Solution**: +```bash +# Check endorsement policy +peer lifecycle chaincode querycommitted -C mychannel -n echo-go + +# Verify all required peers are running +docker ps | grep peer + +# Check peer logs for errors +docker logs peer0.org1.example.com +docker logs peer0.org2.example.com +``` + +### Issue: "Chaincode definition not agreed" + +**Symptom**: Cannot commit chaincode + +**Solution**: +```bash +# Check approval status +peer lifecycle chaincode checkcommitreadiness \ + --channelID mychannel \ + --name echo-go \ + --version 1.0 \ + --sequence 1 + +# Reapprove for all organizations +./scripts/deploy-chaincode.sh +``` + +## Enclave Issues + +### Issue: "Enclave initialization failed" + +**Symptom**: init-enclave.sh fails + +**Solution**: +```bash +# Check ERCC is running +docker ps | grep ercc +docker logs ercc.peer0.org1.example.com + +# Verify ERCC is committed +peer lifecycle chaincode querycommitted -C mychannel -n ercc + +# Retry initialization +./scripts/init-enclave.sh +``` + +### Issue: "Enclave not registered" + +**Symptom**: Chaincode works but enclave not in registry + +**Solution**: +```bash +# Check enclave registration +peer chaincode query -C mychannel -n ercc -c '{"Args":["queryListEnclaves"]}' + +# Re-register +./scripts/init-enclave.sh + +# Verify +peer chaincode query -C mychannel -n ercc -c '{"Args":["queryListEnclaves"]}' +``` + +### Issue: "Cannot retrieve enclave credentials" + +**Symptom**: Client cannot get encryption keys + +**Solution**: +```bash +# Check if enclave is initialized +peer chaincode query -C mychannel -n ercc \ + -c '{"Args":["queryChaincodeEncryptionKey","echo-go"]}' + +# If empty, reinitialize +./scripts/init-enclave.sh + +# For simulation mode, this is expected behavior +echo $SGX_MODE # Should be SIM or HW +``` + +## Client Issues + +### Issue: "fpcclient: command not found" + +**Symptom**: Cannot run fpcclient + +**Solution**: +```bash +# Build the client +cd $FPC_PATH/samples/application/simple-cli-go +make + +# Verify binary exists +ls -la fpcclient + +# Make executable (if needed) +chmod +x fpcclient +``` + +### Issue: "Client connection timeout" + +**Symptom**: Client cannot connect to network + +**Solution**: +```bash +# Source environment variables +source $FPC_PATH/samples/deployment/fablo/config/fpcclient-env.sh + +# Verify peer is reachable +peer channel list + +# Check connection profile +cat $GATEWAY_CONFIG +``` + +### Issue: "Client initialization fails" + +**Symptom**: fpcclient init command fails + +**Solution**: +```bash +# Ensure enclave is initialized first +cd $FPC_PATH/samples/deployment/fablo +./scripts/init-enclave.sh + +# Verify ERCC is accessible +peer chaincode query -C mychannel -n ercc -c '{"Args":["queryChaincodes"]}' + +# Retry client init +cd $FPC_PATH/samples/application/simple-cli-go +./fpcclient init peer0.org1.example.com +``` + +## Performance Issues + +### Issue: "Slow chaincode invocations" + +**Symptom**: Operations take too long + +**Solution**: +```bash +# Check system resources +docker stats + +# Increase Docker resources (Docker Desktop) +# Settings -> Resources -> Increase CPU/Memory + +# Check for network latency +ping localhost + +# Review peer logs for bottlenecks +docker logs peer0.org1.example.com | grep -i "slow\|timeout" +``` + +### Issue: "High memory usage" + +**Symptom**: System running out of memory + +**Solution**: +```bash +# Check memory usage +free -h +docker stats + +# Reduce number of containers +# Edit fablo-config.yaml to use fewer peers + +# Clean up unused Docker resources +docker system prune -a +``` + +## SGX-Specific Issues + +### Issue: "SGX device not found" + +**Symptom**: /dev/sgx_enclave or /dev/sgx_provision missing + +**Solution**: +```bash +# Check if SGX is enabled in BIOS +# Reboot and enable Intel SGX in BIOS settings + +# Install SGX drivers +# Follow: https://github.com/intel/linux-sgx-driver + +# Verify devices +ls -la /dev/sgx* + +# Use simulation mode if no SGX hardware +export SGX_MODE=SIM +``` + +### Issue: "AESM service not running" + +**Symptom**: Enclave operations fail in HW mode + +**Solution**: +```bash +# Check AESM service status +sudo systemctl status aesmd + +# Start AESM service +sudo systemctl start aesmd + +# Enable on boot +sudo systemctl enable aesmd + +# Verify +sudo systemctl status aesmd +``` + +### Issue: "SGX attestation failed" + +**Symptom**: Enclave attestation errors in HW mode + +**Solution**: +```bash +# For development, use simulation mode +export SGX_MODE=SIM + +# For production, configure IAS credentials +export SGX_CREDENTIALS_PATH=$FPC_PATH/config/ias +# Add your IAS API key and SPID to the credentials path + +# Verify attestation configuration +cat $SGX_CREDENTIALS_PATH/api_key.txt +``` + +### Issue: "Enclave out of memory" + +**Symptom**: Enclave operations fail with OOM + +**Solution**: +```bash +# Increase enclave heap size +# Edit chaincode Makefile and increase ENCLAVE_HEAP_SIZE + +# Rebuild chaincode +cd $FPC_PATH/samples/chaincode/echo-go +make clean +make build docker + +# Redeploy +cd $FPC_PATH/samples/deployment/fablo +./scripts/deploy-chaincode.sh +``` + +## Diagnostic Commands + +### Network Health Check + +```bash +# Run validation script +./scripts/validate.sh + +# Check all containers +docker ps -a + +# Check networks +docker network ls + +# Check volumes +docker volume ls +``` + +### Detailed Logging + +```bash +# Enable debug logging +export FABRIC_LOGGING_SPEC=DEBUG + +# View detailed peer logs +docker logs peer0.org1.example.com 2>&1 | grep -i error + +# View chaincode logs with timestamps +docker logs --timestamps echo-go.peer0.org1.example.com +``` + +### Resource Monitoring + +```bash +# Monitor in real-time +docker stats + +# Check disk usage +df -h +docker system df + +# Check network connections +netstat -tulpn | grep -E "7041|7061|7030" +``` + +## Getting Help + +If you cannot resolve your issue: + +1. **Check logs** thoroughly for error messages +2. **Run validation** script: `./scripts/validate.sh` +3. **Search existing issues**: + - [FPC Issues](https://github.com/hyperledger/fabric-private-chaincode/issues) + - [Fablo Issues](https://github.com/hyperledger-labs/fablo/issues) +4. **Ask for help**: + - [Hyperledger Discord](https://discord.gg/hyperledger) + - [FPC Mailing List](https://lists.hyperledger.org/g/fabric-private-chaincode) +5. **Create an issue** with: + - Error messages + - Logs + - Steps to reproduce + - Environment details (OS, Docker version, SGX mode) + +## Additional Resources + +- [FPC Documentation](https://github.com/hyperledger/fabric-private-chaincode) +- [Fablo Documentation](https://github.com/hyperledger-labs/fablo/wiki) +- [Hyperledger Fabric Troubleshooting](https://hyperledger-fabric.readthedocs.io/en/latest/troubleshooting.html) +- [Intel SGX Documentation](https://www.intel.com/content/www/us/en/developer/tools/software-guard-extensions/overview.html) \ No newline at end of file diff --git a/samples/deployment/fablo/docs/USAGE.md b/samples/deployment/fablo/docs/USAGE.md new file mode 100644 index 000000000..4cab93800 --- /dev/null +++ b/samples/deployment/fablo/docs/USAGE.md @@ -0,0 +1,372 @@ +# FPC with Fablo - Usage Guide + +This guide demonstrates how to use the FPC with Fablo deployment sample, including chaincode interactions and common operations. + +## Table of Contents + +- [Quick Start](#quick-start) +- [Using the FPC Client](#using-the-fpc-client) +- [Chaincode Operations](#chaincode-operations) +- [Network Management](#network-management) +- [Advanced Usage](#advanced-usage) +- [Examples](#examples) + +## Quick Start + +### 1. Start the Network + +```bash +cd $FPC_PATH/samples/deployment/fablo +./scripts/setup.sh +``` + +### 2. Configure Client Environment + +```bash +source config/fpcclient-env.sh +``` + +### 3. Use the Client + +```bash +cd $FPC_PATH/samples/application/simple-cli-go + +# Initialize (first time only) +./fpcclient init peer0.org1.example.com + +# Invoke chaincode +./fpcclient invoke "Hello FPC with Fablo!" + +# Query chaincode +./fpcclient query +``` + +## Using the FPC Client + +### Client Overview + +The `simple-cli-go` client (`fpcclient`) provides a command-line interface for interacting with FPC chaincodes. + +### Available Commands + +```bash +./fpcclient --help +``` + +Commands: +- `init` - Initialize the enclave +- `invoke` - Invoke chaincode (write operation) +- `query` - Query chaincode (read operation) + +### Initialize Enclave + +The `init` command must be run once before using the chaincode: + +```bash +./fpcclient init +``` + +Example: +```bash +./fpcclient init peer0.org1.example.com +``` + +This command: +1. Connects to the specified peer +2. Retrieves enclave credentials +3. Establishes a secure channel with the enclave + +### Invoke Chaincode + +The `invoke` command performs write operations: + +```bash +./fpcclient invoke +``` + +Example: +```bash +./fpcclient invoke "This is a private message" +``` + +The message is: +1. Encrypted by the client +2. Sent to the enclave +3. Processed inside the secure enclave +4. Stored on the ledger (encrypted) + +### Query Chaincode + +The `query` command performs read operations: + +```bash +./fpcclient query +``` + +This retrieves the last stored message from the enclave. + +## Chaincode Operations + +### Echo-Go Chaincode Functions + +The echo-go chaincode provides the following functions: + +1. **storeAsset** - Store a message + ```bash + ./fpcclient invoke "Your message here" + ``` + +2. **retrieveAsset** - Retrieve the last message + ```bash + ./fpcclient query + ``` + +### Direct Peer Commands + +You can also interact with the chaincode using peer commands: + +#### Setup Environment + +```bash +source config/fpcclient-env.sh + +# Set peer environment for Org1 +export CORE_PEER_LOCALMSPID="Org1MSP" +export CORE_PEER_ADDRESS="localhost:7041" +export CORE_PEER_TLS_ENABLED=true +export CORE_PEER_TLS_ROOTCERT_FILE="$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" +export CORE_PEER_MSPCONFIGPATH="$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp" +``` + +#### Invoke Chaincode + +```bash +peer chaincode invoke \ + -o localhost:7030 \ + --ordererTLSHostnameOverride orderer0.group1.orderer.example.com \ + --tls \ + --cafile "$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + -C mychannel \ + -n echo-go \ + -c '{"Args":["storeAsset","Test message"]}' \ + --waitForEvent \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" +``` + +#### Query Chaincode + +```bash +peer chaincode query \ + -C mychannel \ + -n echo-go \ + -c '{"Args":["retrieveAsset"]}' +``` + +### Query ERCC + +Check enclave registration: + +```bash +peer chaincode query \ + -C mychannel \ + -n ercc \ + -c '{"Args":["queryListEnclaves"]}' +``` + +Query chaincode encryption key: + +```bash +peer chaincode query \ + -C mychannel \ + -n ercc \ + -c '{"Args":["queryChaincodeEncryptionKey","echo-go"]}' +``` + +## Network Management + +### Start Network + +```bash +cd $FPC_PATH/samples/deployment/fablo +./scripts/setup.sh +``` + +### Stop Network + +```bash +./scripts/teardown.sh +``` + +### Restart Network + +```bash +./scripts/teardown.sh +./scripts/setup.sh +``` + +### Validate Deployment + +```bash +./scripts/validate.sh +``` + +### View Logs + +```bash +# All containers +docker-compose -f target/fabric-docker/docker-compose.yaml logs -f + +# Specific container +docker logs -f peer0.org1.example.com +docker logs -f echo-go.peer0.org1.example.com +docker logs -f ercc.peer0.org1.example.com +``` + +### Check Container Status + +```bash +docker ps +``` + +### Access Container Shell + +```bash +# Peer container +docker exec -it peer0.org1.example.com bash + +# Chaincode container +docker exec -it echo-go.peer0.org1.example.com bash +``` + +## Advanced Usage + +### Using Different Organizations + +Switch to Org2: + +```bash +export CORE_PEER_LOCALMSPID="Org2MSP" +export CORE_PEER_ADDRESS="localhost:7061" +export CORE_PEER_TLS_ROOTCERT_FILE="$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt" +export CORE_PEER_MSPCONFIGPATH="$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp" +``` + +### Upgrading Chaincode + +1. Build new version: + ```bash + cd $FPC_PATH/samples/chaincode/echo-go + make build docker + ``` + +2. Update version in scripts: + ```bash + export CC_VERSION="2.0" + export CC_SEQUENCE="2" + ``` + +3. Redeploy: + ```bash + cd $FPC_PATH/samples/deployment/fablo + ./scripts/deploy-chaincode.sh + ./scripts/init-enclave.sh + ``` + +### Monitoring Performance + +Use Docker stats: +```bash +docker stats +``` + +Monitor specific containers: +```bash +docker stats peer0.org1.example.com echo-go.peer0.org1.example.com +``` + +## Examples + +### Example 1: Basic Echo Operation + +```bash +# Start network +cd $FPC_PATH/samples/deployment/fablo +./scripts/setup.sh + +# Configure environment +source config/fpcclient-env.sh + +# Use client +cd $FPC_PATH/samples/application/simple-cli-go +./fpcclient init peer0.org1.example.com +./fpcclient invoke "Hello from FPC!" +./fpcclient query +``` + +Expected output: +``` +Hello from FPC! +``` + +### Example 2: Multiple Invocations + +```bash +./fpcclient invoke "Message 1" +./fpcclient invoke "Message 2" +./fpcclient invoke "Message 3" +./fpcclient query # Returns "Message 3" +``` + +### Example 3: Verify Encryption + +The data on the ledger is encrypted. To verify: + +```bash +# Query the ledger directly (shows encrypted data) +peer chaincode query -C mychannel -n echo-go -c '{"Args":["retrieveAsset"]}' + +# Query through FPC client (shows decrypted data) +./fpcclient query +``` + +### Example 4: Multi-Org Endorsement + +Invoke with endorsements from both organizations: + +```bash +peer chaincode invoke \ + -o localhost:7030 \ + --ordererTLSHostnameOverride orderer0.group1.orderer.example.com \ + --tls \ + --cafile "$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + -C mychannel \ + -n echo-go \ + -c '{"Args":["storeAsset","Multi-org message"]}' \ + --waitForEvent \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" \ + --peerAddresses localhost:7061 \ + --tlsRootCertFiles "$FPC_PATH/samples/deployment/fablo/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt" +``` + +## Best Practices + +1. **Always initialize the enclave** before first use +2. **Source environment variables** before running commands +3. **Check logs** if operations fail +4. **Run validation** after setup to ensure everything works +5. **Clean up** with teardown script when done +6. **Use simulation mode** for development and testing +7. **Monitor resources** to ensure sufficient capacity + +## Troubleshooting + +For common issues and solutions, see [TROUBLESHOOTING.md](TROUBLESHOOTING.md). + +## Additional Resources + +- [FPC Documentation](https://github.com/hyperledger/fabric-private-chaincode) +- [Simple CLI Go Client](../../../application/simple-cli-go/README.md) +- [Echo-Go Chaincode](../../../chaincode/echo-go/README.md) +- [Fablo Documentation](https://github.com/hyperledger-labs/fablo/wiki) \ No newline at end of file diff --git a/samples/deployment/fablo/fablo-config.json b/samples/deployment/fablo/fablo-config.json new file mode 100644 index 000000000..4d757fb7f --- /dev/null +++ b/samples/deployment/fablo/fablo-config.json @@ -0,0 +1,66 @@ +{ + "$schema": "https://github.com/hyperledger-labs/fablo/releases/download/1.2.0/schema.json", + "global": { + "fabricVersion": "2.4.7", + "tls": true, + "engine": "docker", + "monitoring": { + "loglevel": "info" + } + }, + "orgs": [ + { + "organization": { + "name": "Orderer", + "domain": "orderer.example.com" + }, + "orderers": [ + { + "groupName": "group1", + "type": "solo", + "instances": 1 + } + ] + }, + { + "organization": { + "name": "Org1", + "domain": "org1.example.com" + }, + "peer": { + "instances": 1, + "db": "LevelDb" + } + }, + { + "organization": { + "name": "Org2", + "domain": "org2.example.com" + }, + "peer": { + "instances": 1, + "db": "LevelDb" + } + } + ], + "channels": [ + { + "name": "mychannel", + "orgs": [ + { + "name": "Org1", + "peers": [ + "peer0" + ] + }, + { + "name": "Org2", + "peers": [ + "peer0" + ] + } + ] + } + ], + "chaincodes": [] +} \ No newline at end of file diff --git a/samples/deployment/fablo/fablo-config.yaml b/samples/deployment/fablo/fablo-config.yaml new file mode 100644 index 000000000..c44b30196 --- /dev/null +++ b/samples/deployment/fablo/fablo-config.yaml @@ -0,0 +1,43 @@ +global: + fabricVersion: 2.4.7 + tls: true + engine: docker + monitoring: + loglevel: info + +orgs: + - organization: + name: Orderer + domain: orderer.example.com + orderers: + - groupName: group1 + type: solo + instances: 1 + + - organization: + name: Org1 + domain: org1.example.com + peer: + instances: 1 + db: LevelDb + + - organization: + name: Org2 + domain: org2.example.com + peer: + instances: 1 + db: LevelDb + +channels: + - name: mychannel + orgs: + - name: Org1 + peers: + - peer0 + - name: Org2 + peers: + - peer0 + +chaincodes: [] + +# Made with Bob diff --git a/samples/deployment/fablo/scripts/deploy-chaincode.sh b/samples/deployment/fablo/scripts/deploy-chaincode.sh new file mode 100644 index 000000000..a81a0897b --- /dev/null +++ b/samples/deployment/fablo/scripts/deploy-chaincode.sh @@ -0,0 +1,266 @@ +#!/bin/bash + +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Script to deploy FPC echo-go chaincode + +set -euo pipefail + +# Color codes for output +RED='\033[0;31m' +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +# Script directory +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +SAMPLE_DIR="$(dirname "$SCRIPT_DIR")" + +# Configuration +CHANNEL_NAME="${CHANNEL_NAME:-mychannel}" +CC_ID="${CC_ID:-echo-go}" +CC_VERSION="${CC_VERSION:-1.0}" +CC_SEQUENCE="${CC_SEQUENCE:-1}" +CC_VER="${CC_VER:-latest}" + +# Logging functions +log_info() { + echo -e "${BLUE}[INFO]${NC} $1" +} + +log_success() { + echo -e "${GREEN}[SUCCESS]${NC} $1" +} + +log_error() { + echo -e "${RED}[ERROR]${NC} $1" +} + +# Set peer environment for Org1 +set_peer_org1() { + export CORE_PEER_LOCALMSPID="Org1MSP" + export CORE_PEER_TLS_ENABLED=true + export CORE_PEER_TLS_ROOTCERT_FILE="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" + export CORE_PEER_MSPCONFIGPATH="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp" + export CORE_PEER_ADDRESS="localhost:7041" +} + +# Set peer environment for Org2 +set_peer_org2() { + export CORE_PEER_LOCALMSPID="Org2MSP" + export CORE_PEER_TLS_ENABLED=true + export CORE_PEER_TLS_ROOTCERT_FILE="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt" + export CORE_PEER_MSPCONFIGPATH="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp" + export CORE_PEER_ADDRESS="localhost:7061" +} + +# Package echo-go chaincode +package_chaincode() { + log_info "Packaging echo-go chaincode..." + + cd "$FPC_PATH/samples/chaincode/echo-go" + + # Create connection.json for chaincode as a service + cat > connection.json < metadata.json <> "$SAMPLE_DIR/config/chaincode-env.sh" +} + +# Install chaincode on Org2 peer +install_chaincode_org2() { + log_info "Installing echo-go chaincode on Org2 peer..." + + set_peer_org2 + + cd "$FPC_PATH/samples/chaincode/echo-go" + + peer lifecycle chaincode install "${CC_ID}.tar.gz" + + # Get package ID + export CC_PKG_ID_ORG2=$(peer lifecycle chaincode queryinstalled | grep "${CC_ID}_${CC_VERSION}" | awk '{print $3}' | sed 's/,$//') + + if [ -z "$CC_PKG_ID_ORG2" ]; then + log_error "Failed to get chaincode package ID for Org2" + exit 1 + fi + + log_success "Echo-go chaincode installed on Org2: $CC_PKG_ID_ORG2" + + # Save package ID for docker-compose + echo "export CC_PKG_ID_ORG2=$CC_PKG_ID_ORG2" >> "$SAMPLE_DIR/config/chaincode-env.sh" +} + +# Start chaincode containers +start_chaincode_containers() { + log_info "Starting echo-go chaincode containers..." + + # Source the package IDs + source "$SAMPLE_DIR/config/chaincode-env.sh" + + # Export CC_VER for docker-compose + export CC_VER + + # Start chaincode containers using docker-compose + cd "$SAMPLE_DIR" + docker-compose -f compose/ecc-compose.yaml up -d + + # Wait for containers to be ready + sleep 5 + + log_success "Echo-go chaincode containers started" +} + +# Approve chaincode for Org1 +approve_chaincode_org1() { + log_info "Approving echo-go chaincode for Org1..." + + set_peer_org1 + source "$SAMPLE_DIR/config/chaincode-env.sh" + + peer lifecycle chaincode approveformyorg \ + --channelID "$CHANNEL_NAME" \ + --name "$CC_ID" \ + --version "$CC_VERSION" \ + --package-id "$CC_PKG_ID_ORG1" \ + --sequence "$CC_SEQUENCE" \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + --signature-policy "OR('Org1MSP.member','Org2MSP.member')" + + log_success "Echo-go chaincode approved for Org1" +} + +# Approve chaincode for Org2 +approve_chaincode_org2() { + log_info "Approving echo-go chaincode for Org2..." + + set_peer_org2 + source "$SAMPLE_DIR/config/chaincode-env.sh" + + peer lifecycle chaincode approveformyorg \ + --channelID "$CHANNEL_NAME" \ + --name "$CC_ID" \ + --version "$CC_VERSION" \ + --package-id "$CC_PKG_ID_ORG2" \ + --sequence "$CC_SEQUENCE" \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + --signature-policy "OR('Org1MSP.member','Org2MSP.member')" + + log_success "Echo-go chaincode approved for Org2" +} + +# Commit chaincode +commit_chaincode() { + log_info "Committing echo-go chaincode to channel..." + + set_peer_org1 + + peer lifecycle chaincode commit \ + --channelID "$CHANNEL_NAME" \ + --name "$CC_ID" \ + --version "$CC_VERSION" \ + --sequence "$CC_SEQUENCE" \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" \ + --peerAddresses localhost:7061 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt" \ + --signature-policy "OR('Org1MSP.member','Org2MSP.member')" + + log_success "Echo-go chaincode committed to channel" +} + +# Verify chaincode deployment +verify_chaincode() { + log_info "Verifying echo-go chaincode deployment..." + + set_peer_org1 + + # Query committed chaincode + peer lifecycle chaincode querycommitted --channelID "$CHANNEL_NAME" --name "$CC_ID" + + log_success "Echo-go chaincode deployment verified" +} + +# Main execution +main() { + log_info "Starting echo-go chaincode deployment..." + + # Create config directory if it doesn't exist + mkdir -p "$SAMPLE_DIR/config" + + # Clear previous chaincode environment file + > "$SAMPLE_DIR/config/chaincode-env.sh" + + package_chaincode + install_chaincode_org1 + install_chaincode_org2 + start_chaincode_containers + + # Wait for containers to be fully ready + sleep 10 + + approve_chaincode_org1 + approve_chaincode_org2 + commit_chaincode + + # Wait for commit to complete + sleep 5 + + verify_chaincode + + log_success "Echo-go chaincode deployment completed successfully" +} + +# Run main function +main "$@" + +# Made with Bob diff --git a/samples/deployment/fablo/scripts/deploy-ercc.sh b/samples/deployment/fablo/scripts/deploy-ercc.sh new file mode 100644 index 000000000..195db0c23 --- /dev/null +++ b/samples/deployment/fablo/scripts/deploy-ercc.sh @@ -0,0 +1,262 @@ +#!/bin/bash + +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Script to deploy FPC Enclave Registry Chaincode (ERCC) + +set -euo pipefail + +# Color codes for output +RED='\033[0;31m' +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +# Script directory +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +SAMPLE_DIR="$(dirname "$SCRIPT_DIR")" + +# Configuration +CHANNEL_NAME="${CHANNEL_NAME:-mychannel}" +ERCC_ID="ercc" +ERCC_VERSION="${ERCC_VERSION:-1.0}" +ERCC_SEQUENCE="${ERCC_SEQUENCE:-1}" + +# Logging functions +log_info() { + echo -e "${BLUE}[INFO]${NC} $1" +} + +log_success() { + echo -e "${GREEN}[SUCCESS]${NC} $1" +} + +log_error() { + echo -e "${RED}[ERROR]${NC} $1" +} + +# Set peer environment for Org1 +set_peer_org1() { + export CORE_PEER_LOCALMSPID="Org1MSP" + export CORE_PEER_TLS_ENABLED=true + export CORE_PEER_TLS_ROOTCERT_FILE="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" + export CORE_PEER_MSPCONFIGPATH="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp" + export CORE_PEER_ADDRESS="localhost:7041" +} + +# Set peer environment for Org2 +set_peer_org2() { + export CORE_PEER_LOCALMSPID="Org2MSP" + export CORE_PEER_TLS_ENABLED=true + export CORE_PEER_TLS_ROOTCERT_FILE="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt" + export CORE_PEER_MSPCONFIGPATH="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp" + export CORE_PEER_ADDRESS="localhost:7061" +} + +# Package ERCC +package_ercc() { + log_info "Packaging ERCC..." + + cd "$FPC_PATH/ercc" + + # Create connection.json for chaincode as a service + cat > connection.json < metadata.json <> "$SAMPLE_DIR/config/ercc-env.sh" +} + +# Install ERCC on Org2 peer +install_ercc_org2() { + log_info "Installing ERCC on Org2 peer..." + + set_peer_org2 + + cd "$FPC_PATH/ercc" + + peer lifecycle chaincode install "${ERCC_ID}.tar.gz" + + # Get package ID + export ERCC_PKG_ID_ORG2=$(peer lifecycle chaincode queryinstalled | grep "${ERCC_ID}_${ERCC_VERSION}" | awk '{print $3}' | sed 's/,$//') + + if [ -z "$ERCC_PKG_ID_ORG2" ]; then + log_error "Failed to get ERCC package ID for Org2" + exit 1 + fi + + log_success "ERCC installed on Org2: $ERCC_PKG_ID_ORG2" + + # Save package ID for docker-compose + echo "export ERCC_PKG_ID_ORG2=$ERCC_PKG_ID_ORG2" >> "$SAMPLE_DIR/config/ercc-env.sh" +} + +# Start ERCC containers +start_ercc_containers() { + log_info "Starting ERCC containers..." + + # Source the package IDs + source "$SAMPLE_DIR/config/ercc-env.sh" + + # Start ERCC containers using docker-compose + cd "$SAMPLE_DIR" + docker-compose -f compose/ercc-compose.yaml up -d + + # Wait for containers to be ready + sleep 5 + + log_success "ERCC containers started" +} + +# Approve ERCC for Org1 +approve_ercc_org1() { + log_info "Approving ERCC for Org1..." + + set_peer_org1 + source "$SAMPLE_DIR/config/ercc-env.sh" + + peer lifecycle chaincode approveformyorg \ + --channelID "$CHANNEL_NAME" \ + --name "$ERCC_ID" \ + --version "$ERCC_VERSION" \ + --package-id "$ERCC_PKG_ID_ORG1" \ + --sequence "$ERCC_SEQUENCE" \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + --signature-policy "OR('Org1MSP.member','Org2MSP.member')" + + log_success "ERCC approved for Org1" +} + +# Approve ERCC for Org2 +approve_ercc_org2() { + log_info "Approving ERCC for Org2..." + + set_peer_org2 + source "$SAMPLE_DIR/config/ercc-env.sh" + + peer lifecycle chaincode approveformyorg \ + --channelID "$CHANNEL_NAME" \ + --name "$ERCC_ID" \ + --version "$ERCC_VERSION" \ + --package-id "$ERCC_PKG_ID_ORG2" \ + --sequence "$ERCC_SEQUENCE" \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + --signature-policy "OR('Org1MSP.member','Org2MSP.member')" + + log_success "ERCC approved for Org2" +} + +# Commit ERCC +commit_ercc() { + log_info "Committing ERCC to channel..." + + set_peer_org1 + + peer lifecycle chaincode commit \ + --channelID "$CHANNEL_NAME" \ + --name "$ERCC_ID" \ + --version "$ERCC_VERSION" \ + --sequence "$ERCC_SEQUENCE" \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" \ + --peerAddresses localhost:7061 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt" \ + --signature-policy "OR('Org1MSP.member','Org2MSP.member')" + + log_success "ERCC committed to channel" +} + +# Verify ERCC deployment +verify_ercc() { + log_info "Verifying ERCC deployment..." + + set_peer_org1 + + # Query committed chaincode + peer lifecycle chaincode querycommitted --channelID "$CHANNEL_NAME" --name "$ERCC_ID" + + log_success "ERCC deployment verified" +} + +# Main execution +main() { + log_info "Starting ERCC deployment..." + + # Create config directory if it doesn't exist + mkdir -p "$SAMPLE_DIR/config" + + # Clear previous ERCC environment file + > "$SAMPLE_DIR/config/ercc-env.sh" + + package_ercc + install_ercc_org1 + install_ercc_org2 + start_ercc_containers + + # Wait for containers to be fully ready + sleep 10 + + approve_ercc_org1 + approve_ercc_org2 + commit_ercc + + # Wait for commit to complete + sleep 5 + + verify_ercc + + log_success "ERCC deployment completed successfully" +} + +# Run main function +main "$@" + +# Made with Bob diff --git a/samples/deployment/fablo/scripts/init-enclave.sh b/samples/deployment/fablo/scripts/init-enclave.sh new file mode 100644 index 000000000..8945e61c1 --- /dev/null +++ b/samples/deployment/fablo/scripts/init-enclave.sh @@ -0,0 +1,228 @@ +#!/bin/bash + +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Script to initialize FPC enclave for echo-go chaincode + +set -euo pipefail + +# Color codes for output +RED='\033[0;31m' +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +# Script directory +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +SAMPLE_DIR="$(dirname "$SCRIPT_DIR")" + +# Configuration +CHANNEL_NAME="${CHANNEL_NAME:-mychannel}" +CC_ID="${CC_ID:-echo-go}" +ERCC_ID="ercc" + +# Logging functions +log_info() { + echo -e "${BLUE}[INFO]${NC} $1" +} + +log_success() { + echo -e "${GREEN}[SUCCESS]${NC} $1" +} + +log_error() { + echo -e "${RED}[ERROR]${NC} $1" +} + +log_warning() { + echo -e "${YELLOW}[WARNING]${NC} $1" +} + +# Set peer environment for Org1 +set_peer_org1() { + export CORE_PEER_LOCALMSPID="Org1MSP" + export CORE_PEER_TLS_ENABLED=true + export CORE_PEER_TLS_ROOTCERT_FILE="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" + export CORE_PEER_MSPCONFIGPATH="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp" + export CORE_PEER_ADDRESS="localhost:7041" +} + +# Initialize enclave +init_enclave() { + log_info "Initializing FPC enclave for $CC_ID..." + + set_peer_org1 + + # Call initEnclave function via ERCC + local INIT_CMD='{"Args":["initEnclave"]}' + + peer chaincode invoke \ + -o localhost:7030 \ + --ordererTLSHostnameOverride orderer0.group1.orderer.example.com \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + -C "$CHANNEL_NAME" \ + -n "$ERCC_ID" \ + -c "$INIT_CMD" \ + --waitForEvent \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" + + log_success "Enclave initialization invoked" + + # Wait for enclave to initialize + log_info "Waiting for enclave to initialize..." + sleep 10 +} + +# Get enclave credentials +get_enclave_credentials() { + log_info "Retrieving enclave credentials..." + + set_peer_org1 + + # Query for enclave credentials + local QUERY_CMD='{"Args":["queryChaincodeEncryptionKey","'$CC_ID'"]}' + + local CREDENTIALS=$(peer chaincode query \ + -C "$CHANNEL_NAME" \ + -n "$ERCC_ID" \ + -c "$QUERY_CMD" 2>&1) + + if [ $? -eq 0 ] && [ -n "$CREDENTIALS" ]; then + log_success "Enclave credentials retrieved" + + # Save credentials to file + mkdir -p "$SAMPLE_DIR/config/credentials" + echo "$CREDENTIALS" > "$SAMPLE_DIR/config/credentials/${CC_ID}_credentials.json" + + log_info "Credentials saved to: $SAMPLE_DIR/config/credentials/${CC_ID}_credentials.json" + else + log_warning "Could not retrieve enclave credentials yet. This is normal if using simulation mode." + fi +} + +# Register enclave with ERCC +register_enclave() { + log_info "Registering enclave with ERCC..." + + set_peer_org1 + + # Call registerEnclave function via ERCC + local REGISTER_CMD='{"Args":["registerEnclave"]}' + + peer chaincode invoke \ + -o localhost:7030 \ + --ordererTLSHostnameOverride orderer0.group1.orderer.example.com \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + -C "$CHANNEL_NAME" \ + -n "$ERCC_ID" \ + -c "$REGISTER_CMD" \ + --waitForEvent \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" + + log_success "Enclave registration invoked" + + # Wait for registration to complete + sleep 5 +} + +# Verify enclave registration +verify_enclave_registration() { + log_info "Verifying enclave registration..." + + set_peer_org1 + + # Query list of registered enclaves + local QUERY_CMD='{"Args":["queryListEnclaves"]}' + + local ENCLAVES=$(peer chaincode query \ + -C "$CHANNEL_NAME" \ + -n "$ERCC_ID" \ + -c "$QUERY_CMD" 2>&1) + + if echo "$ENCLAVES" | grep -q "$CC_ID"; then + log_success "Enclave successfully registered for $CC_ID" + echo "$ENCLAVES" + else + log_error "Enclave not found in registry" + log_info "Registered enclaves:" + echo "$ENCLAVES" + exit 1 + fi +} + +# Test basic chaincode invocation +test_chaincode() { + log_info "Testing chaincode invocation..." + + set_peer_org1 + + # Try a simple echo invocation + local TEST_MSG="Test message from init-enclave script" + local INVOKE_CMD='{"Args":["storeAsset","'$TEST_MSG'"]}' + + peer chaincode invoke \ + -o localhost:7030 \ + --ordererTLSHostnameOverride orderer0.group1.orderer.example.com \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + -C "$CHANNEL_NAME" \ + -n "$CC_ID" \ + -c "$INVOKE_CMD" \ + --waitForEvent \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" + + if [ $? -eq 0 ]; then + log_success "Chaincode invocation successful" + + # Query the result + sleep 2 + local QUERY_CMD='{"Args":["retrieveAsset"]}' + local RESULT=$(peer chaincode query \ + -C "$CHANNEL_NAME" \ + -n "$CC_ID" \ + -c "$QUERY_CMD" 2>&1) + + log_info "Query result: $RESULT" + else + log_warning "Chaincode invocation failed. This might be expected if additional setup is needed." + fi +} + +# Main execution +main() { + log_info "Starting FPC enclave initialization for $CC_ID..." + echo "" + + init_enclave + echo "" + + get_enclave_credentials + echo "" + + register_enclave + echo "" + + verify_enclave_registration + echo "" + + test_chaincode + echo "" + + log_success "FPC enclave initialization completed successfully" + echo "" + log_info "You can now use the simple-cli-go client to interact with the chaincode" +} + +# Run main function +main "$@" + +# Made with Bob diff --git a/samples/deployment/fablo/scripts/setup.sh b/samples/deployment/fablo/scripts/setup.sh new file mode 100644 index 000000000..15ce90138 --- /dev/null +++ b/samples/deployment/fablo/scripts/setup.sh @@ -0,0 +1,274 @@ +#!/bin/bash + +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Main setup script for FPC with Fablo deployment +# This script orchestrates the complete setup process + +set -euo pipefail + +# Color codes for output +RED='\033[0;31m' +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +# Script directory +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +SAMPLE_DIR="$(dirname "$SCRIPT_DIR")" + +# Source common functions if available +if [ -f "$SCRIPT_DIR/common.sh" ]; then + source "$SCRIPT_DIR/common.sh" +fi + +# Logging functions +log_info() { + echo -e "${BLUE}[INFO]${NC} $1" +} + +log_success() { + echo -e "${GREEN}[SUCCESS]${NC} $1" +} + +log_warning() { + echo -e "${YELLOW}[WARNING]${NC} $1" +} + +log_error() { + echo -e "${RED}[ERROR]${NC} $1" +} + +# Check prerequisites +check_prerequisites() { + log_info "Checking prerequisites..." + + # Check Docker + if ! command -v docker &> /dev/null; then + log_error "Docker is not installed. Please install Docker first." + exit 1 + fi + log_success "Docker found: $(docker --version)" + + # Check Docker Compose + if ! command -v docker-compose &> /dev/null; then + log_error "Docker Compose is not installed. Please install Docker Compose first." + exit 1 + fi + log_success "Docker Compose found: $(docker-compose --version)" + + # Check FPC_PATH + if [ -z "${FPC_PATH:-}" ]; then + log_error "FPC_PATH environment variable is not set." + log_error "Please set it to your FPC repository path: export FPC_PATH=/path/to/fabric-private-chaincode" + exit 1 + fi + + if [ ! -d "$FPC_PATH" ]; then + log_error "FPC_PATH directory does not exist: $FPC_PATH" + exit 1 + fi + log_success "FPC_PATH is set: $FPC_PATH" + + # Check SGX_MODE + if [ -z "${SGX_MODE:-}" ]; then + log_warning "SGX_MODE not set, defaulting to SIM mode" + export SGX_MODE=SIM + fi + log_info "SGX_MODE: $SGX_MODE" + + # Check if FPC is built + if [ ! -f "$FPC_PATH/ercc/ercc" ]; then + log_error "FPC ERCC not built. Please run: make -C $FPC_PATH/ercc all" + exit 1 + fi + log_success "FPC ERCC is built" + + if [ ! -f "$FPC_PATH/samples/chaincode/echo-go/_build/lib/enclave.signed.so" ]; then + log_error "Echo-go chaincode not built. Please run: make -C $FPC_PATH/samples/chaincode/echo-go" + exit 1 + fi + log_success "Echo-go chaincode is built" +} + +# Install Fablo if not present +install_fablo() { + log_info "Checking Fablo installation..." + + # Check if fablo exists in current directory or PATH + if [ -f "./fablo" ]; then + log_success "Fablo found in current directory" + return 0 + fi + + if command -v fablo &> /dev/null; then + log_success "Fablo is already installed: $(fablo --version)" + return 0 + fi + + log_info "Installing Fablo..." + + # Download Fablo script from official repository + # Using the recommended installation method from https://github.com/hyperledger-labs/fablo + FABLO_VERSION="${FABLO_VERSION:-1.2.0}" + + curl -Lf "https://github.com/hyperledger-labs/fablo/releases/download/${FABLO_VERSION}/fablo.sh" -o ./fablo + + if [ $? -ne 0 ]; then + log_error "Failed to download Fablo" + log_info "Please check your internet connection or download manually from:" + log_info "https://github.com/hyperledger-labs/fablo/releases" + exit 1 + fi + + chmod +x ./fablo + log_success "Fablo installed successfully (version ${FABLO_VERSION})" +} + +# Generate and start Fablo network +start_fablo_network() { + log_info "Generating Fablo network configuration..." + + cd "$SAMPLE_DIR" + + # Generate network + fablo generate + + log_info "Starting Fablo network..." + fablo up + + # Apply FPC-specific overrides + log_info "Applying FPC-specific Docker Compose overrides..." + docker-compose -f "$SAMPLE_DIR/target/fabric-docker/docker-compose.yaml" \ + -f "$SAMPLE_DIR/docker-compose-fpc-override.yaml" \ + up -d + + log_success "Fablo network started successfully" + + # Wait for network to be ready + log_info "Waiting for network to be ready..." + sleep 10 +} + +# Deploy ERCC +deploy_ercc() { + log_info "Deploying ERCC (Enclave Registry Chaincode)..." + + if [ -f "$SCRIPT_DIR/deploy-ercc.sh" ]; then + bash "$SCRIPT_DIR/deploy-ercc.sh" + else + log_error "deploy-ercc.sh script not found" + exit 1 + fi + + log_success "ERCC deployed successfully" +} + +# Deploy echo-go chaincode +deploy_chaincode() { + log_info "Deploying echo-go chaincode..." + + if [ -f "$SCRIPT_DIR/deploy-chaincode.sh" ]; then + bash "$SCRIPT_DIR/deploy-chaincode.sh" + else + log_error "deploy-chaincode.sh script not found" + exit 1 + fi + + log_success "Echo-go chaincode deployed successfully" +} + +# Initialize FPC enclave +init_enclave() { + log_info "Initializing FPC enclave..." + + if [ -f "$SCRIPT_DIR/init-enclave.sh" ]; then + bash "$SCRIPT_DIR/init-enclave.sh" + else + log_error "init-enclave.sh script not found" + exit 1 + fi + + log_success "FPC enclave initialized successfully" +} + +# Validate deployment +validate_deployment() { + log_info "Validating deployment..." + + if [ -f "$SCRIPT_DIR/validate.sh" ]; then + bash "$SCRIPT_DIR/validate.sh" + else + log_warning "validate.sh script not found, skipping validation" + return 0 + fi + + log_success "Deployment validated successfully" +} + +# Print next steps +print_next_steps() { + echo "" + echo -e "${GREEN}========================================${NC}" + echo -e "${GREEN} FPC with Fablo Setup Complete!${NC}" + echo -e "${GREEN}========================================${NC}" + echo "" + echo "Next steps:" + echo "" + echo "1. Source the environment variables:" + echo -e " ${BLUE}source $SAMPLE_DIR/config/fpcclient-env.sh${NC}" + echo "" + echo "2. Navigate to the simple-cli-go client:" + echo -e " ${BLUE}cd \$FPC_PATH/samples/application/simple-cli-go${NC}" + echo "" + echo "3. Initialize the client (first time only):" + echo -e " ${BLUE}./fpcclient init peer0.org1.example.com${NC}" + echo "" + echo "4. Invoke the chaincode:" + echo -e " ${BLUE}./fpcclient invoke \"Hello FPC with Fablo!\"${NC}" + echo "" + echo "5. Query the chaincode:" + echo -e " ${BLUE}./fpcclient query${NC}" + echo "" + echo "To tear down the network:" + echo -e " ${BLUE}cd $SAMPLE_DIR && ./scripts/teardown.sh${NC}" + echo "" +} + +# Main execution +main() { + log_info "Starting FPC with Fablo setup..." + echo "" + + check_prerequisites + echo "" + + install_fablo + echo "" + + start_fablo_network + echo "" + + deploy_ercc + echo "" + + deploy_chaincode + echo "" + + init_enclave + echo "" + + validate_deployment + echo "" + + print_next_steps +} + +# Run main function +main "$@" + +# Made with Bob diff --git a/samples/deployment/fablo/scripts/teardown.sh b/samples/deployment/fablo/scripts/teardown.sh new file mode 100644 index 000000000..ebe095f7a --- /dev/null +++ b/samples/deployment/fablo/scripts/teardown.sh @@ -0,0 +1,243 @@ +#!/bin/bash + +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Script to tear down the FPC with Fablo network + +set -euo pipefail + +# Color codes for output +RED='\033[0;31m' +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +# Script directory +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +SAMPLE_DIR="$(dirname "$SCRIPT_DIR")" + +# Logging functions +log_info() { + echo -e "${BLUE}[INFO]${NC} $1" +} + +log_success() { + echo -e "${GREEN}[SUCCESS]${NC} $1" +} + +log_warning() { + echo -e "${YELLOW}[WARNING]${NC} $1" +} + +log_error() { + echo -e "${RED}[ERROR]${NC} $1" +} + +# Stop FPC chaincode containers +stop_fpc_containers() { + log_info "Stopping FPC chaincode containers..." + + cd "$SAMPLE_DIR" + + # Stop echo-go containers + if [ -f compose/ecc-compose.yaml ]; then + docker-compose -f compose/ecc-compose.yaml down -v 2>/dev/null || true + log_success "Echo-go containers stopped" + fi + + # Stop ERCC containers + if [ -f compose/ercc-compose.yaml ]; then + docker-compose -f compose/ercc-compose.yaml down -v 2>/dev/null || true + log_success "ERCC containers stopped" + fi +} + +# Stop Fablo network +stop_fablo_network() { + log_info "Stopping Fablo network..." + + cd "$SAMPLE_DIR" + + # Stop network using Fablo + if command -v fablo &> /dev/null; then + fablo down 2>/dev/null || true + log_success "Fablo network stopped" + else + log_warning "Fablo command not found, attempting manual cleanup" + + # Manual cleanup if Fablo is not available + if [ -f target/fabric-docker/docker-compose.yaml ]; then + docker-compose -f target/fabric-docker/docker-compose.yaml down -v 2>/dev/null || true + fi + fi +} + +# Remove generated artifacts +clean_artifacts() { + log_info "Cleaning up generated artifacts..." + + cd "$SAMPLE_DIR" + + # Remove Fablo generated files + if [ -d target ]; then + rm -rf target + log_success "Removed target directory" + fi + + # Remove config files + if [ -d config/credentials ]; then + rm -rf config/credentials + log_success "Removed credentials directory" + fi + + if [ -f config/ercc-env.sh ]; then + rm -f config/ercc-env.sh + log_success "Removed ERCC environment file" + fi + + if [ -f config/chaincode-env.sh ]; then + rm -f config/chaincode-env.sh + log_success "Removed chaincode environment file" + fi + + # Remove chaincode packages + if [ -f "$FPC_PATH/ercc/ercc.tar.gz" ]; then + rm -f "$FPC_PATH/ercc/ercc.tar.gz" + rm -f "$FPC_PATH/ercc/code.tar.gz" + rm -f "$FPC_PATH/ercc/connection.json" + rm -f "$FPC_PATH/ercc/metadata.json" + log_success "Removed ERCC package files" + fi + + if [ -f "$FPC_PATH/samples/chaincode/echo-go/echo-go.tar.gz" ]; then + rm -f "$FPC_PATH/samples/chaincode/echo-go/echo-go.tar.gz" + rm -f "$FPC_PATH/samples/chaincode/echo-go/code.tar.gz" + rm -f "$FPC_PATH/samples/chaincode/echo-go/connection.json" + rm -f "$FPC_PATH/samples/chaincode/echo-go/metadata.json" + log_success "Removed echo-go package files" + fi +} + +# Remove Docker volumes +clean_volumes() { + log_info "Cleaning up Docker volumes..." + + # Remove Fablo network volumes + docker volume ls -q | grep -E "fablo|fabric" | xargs -r docker volume rm 2>/dev/null || true + + log_success "Docker volumes cleaned" +} + +# Remove Docker networks +clean_networks() { + log_info "Cleaning up Docker networks..." + + # Remove Fablo network + docker network rm fablo_default 2>/dev/null || true + + log_success "Docker networks cleaned" +} + +# Stop and remove all related containers +clean_containers() { + log_info "Stopping and removing all related containers..." + + # Stop and remove FPC containers + docker ps -a | grep -E "echo-go|ercc|peer|orderer|ca" | awk '{print $1}' | xargs -r docker rm -f 2>/dev/null || true + + log_success "Containers cleaned" +} + +# Prune Docker system (optional) +prune_docker() { + if [ "${PRUNE_DOCKER:-false}" = "true" ]; then + log_info "Pruning Docker system..." + docker system prune -f + log_success "Docker system pruned" + fi +} + +# Display cleanup summary +display_summary() { + echo "" + echo -e "${GREEN}========================================${NC}" + echo -e "${GREEN} Teardown Complete${NC}" + echo -e "${GREEN}========================================${NC}" + echo "" + echo "The following have been cleaned up:" + echo " ✓ FPC chaincode containers" + echo " ✓ Fablo network" + echo " ✓ Generated artifacts" + echo " ✓ Docker volumes" + echo " ✓ Docker networks" + echo "" + echo "To start the network again, run:" + echo -e " ${BLUE}./scripts/setup.sh${NC}" + echo "" +} + +# Main execution +main() { + log_info "Starting teardown of FPC with Fablo network..." + echo "" + + # Check if FPC_PATH is set + if [ -z "${FPC_PATH:-}" ]; then + log_warning "FPC_PATH not set, some cleanup operations may be skipped" + fi + + stop_fpc_containers + echo "" + + stop_fablo_network + echo "" + + clean_containers + echo "" + + clean_volumes + echo "" + + clean_networks + echo "" + + clean_artifacts + echo "" + + prune_docker + echo "" + + display_summary +} + +# Parse command line arguments +while [[ $# -gt 0 ]]; do + case $1 in + --prune) + export PRUNE_DOCKER=true + shift + ;; + -h|--help) + echo "Usage: $0 [OPTIONS]" + echo "" + echo "Options:" + echo " --prune Also prune Docker system (removes unused images, etc.)" + echo " -h, --help Show this help message" + exit 0 + ;; + *) + log_error "Unknown option: $1" + echo "Use -h or --help for usage information" + exit 1 + ;; + esac +done + +# Run main function +main "$@" + +# Made with Bob diff --git a/samples/deployment/fablo/scripts/validate.sh b/samples/deployment/fablo/scripts/validate.sh new file mode 100644 index 000000000..9fab965af --- /dev/null +++ b/samples/deployment/fablo/scripts/validate.sh @@ -0,0 +1,301 @@ +#!/bin/bash + +# Copyright IBM Corp. All Rights Reserved. +# Copyright 2020 Intel Corporation +# +# SPDX-License-Identifier: Apache-2.0 + +# Script to validate FPC with Fablo deployment + +set -euo pipefail + +# Color codes for output +RED='\033[0;31m' +GREEN='\033[0;32m' +YELLOW='\033[1;33m' +BLUE='\033[0;34m' +NC='\033[0m' # No Color + +# Script directory +SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +SAMPLE_DIR="$(dirname "$SCRIPT_DIR")" + +# Configuration +CHANNEL_NAME="${CHANNEL_NAME:-mychannel}" +CC_ID="${CC_ID:-echo-go}" +ERCC_ID="ercc" + +# Counters +PASSED=0 +FAILED=0 + +# Logging functions +log_info() { + echo -e "${BLUE}[INFO]${NC} $1" +} + +log_success() { + echo -e "${GREEN}[✓]${NC} $1" + ((PASSED++)) +} + +log_error() { + echo -e "${RED}[✗]${NC} $1" + ((FAILED++)) +} + +log_warning() { + echo -e "${YELLOW}[!]${NC} $1" +} + +# Set peer environment for Org1 +set_peer_org1() { + export CORE_PEER_LOCALMSPID="Org1MSP" + export CORE_PEER_TLS_ENABLED=true + export CORE_PEER_TLS_ROOTCERT_FILE="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" + export CORE_PEER_MSPCONFIGPATH="$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp" + export CORE_PEER_ADDRESS="localhost:7041" +} + +# Check Docker containers +check_containers() { + log_info "Checking Docker containers..." + + local REQUIRED_CONTAINERS=( + "peer0.org1.example.com" + "peer0.org2.example.com" + "orderer0.group1.orderer.example.com" + "ercc.peer0.org1.example.com" + "ercc.peer0.org2.example.com" + "echo-go.peer0.org1.example.com" + "echo-go.peer0.org2.example.com" + ) + + for container in "${REQUIRED_CONTAINERS[@]}"; do + if docker ps --format '{{.Names}}' | grep -q "^${container}$"; then + log_success "Container running: $container" + else + log_error "Container not running: $container" + fi + done + echo "" +} + +# Check network connectivity +check_network() { + log_info "Checking network connectivity..." + + set_peer_org1 + + # Check if peer is reachable + if peer channel list &> /dev/null; then + log_success "Peer connectivity OK" + else + log_error "Cannot connect to peer" + fi + + # Check if channel exists + if peer channel list 2>&1 | grep -q "$CHANNEL_NAME"; then + log_success "Channel exists: $CHANNEL_NAME" + else + log_error "Channel not found: $CHANNEL_NAME" + fi + echo "" +} + +# Check ERCC deployment +check_ercc() { + log_info "Checking ERCC deployment..." + + set_peer_org1 + + # Check if ERCC is committed + if peer lifecycle chaincode querycommitted --channelID "$CHANNEL_NAME" --name "$ERCC_ID" &> /dev/null; then + log_success "ERCC is committed on channel" + + # Get ERCC details + local ERCC_INFO=$(peer lifecycle chaincode querycommitted --channelID "$CHANNEL_NAME" --name "$ERCC_ID" 2>&1) + echo "$ERCC_INFO" | grep -E "Version|Sequence" | sed 's/^/ /' + else + log_error "ERCC is not committed on channel" + fi + + # Test ERCC query + if peer chaincode query -C "$CHANNEL_NAME" -n "$ERCC_ID" -c '{"Args":["queryChaincodes"]}' &> /dev/null; then + log_success "ERCC query successful" + else + log_error "ERCC query failed" + fi + echo "" +} + +# Check echo-go chaincode deployment +check_chaincode() { + log_info "Checking echo-go chaincode deployment..." + + set_peer_org1 + + # Check if chaincode is committed + if peer lifecycle chaincode querycommitted --channelID "$CHANNEL_NAME" --name "$CC_ID" &> /dev/null; then + log_success "Echo-go chaincode is committed on channel" + + # Get chaincode details + local CC_INFO=$(peer lifecycle chaincode querycommitted --channelID "$CHANNEL_NAME" --name "$CC_ID" 2>&1) + echo "$CC_INFO" | grep -E "Version|Sequence" | sed 's/^/ /' + else + log_error "Echo-go chaincode is not committed on channel" + fi + echo "" +} + +# Check enclave registration +check_enclave() { + log_info "Checking enclave registration..." + + set_peer_org1 + + # Query list of registered enclaves + local ENCLAVES=$(peer chaincode query -C "$CHANNEL_NAME" -n "$ERCC_ID" -c '{"Args":["queryListEnclaves"]}' 2>&1) + + if [ $? -eq 0 ]; then + if echo "$ENCLAVES" | grep -q "$CC_ID"; then + log_success "Enclave registered for $CC_ID" + echo "$ENCLAVES" | sed 's/^/ /' + else + log_error "Enclave not registered for $CC_ID" + log_info "Registered enclaves:" + echo "$ENCLAVES" | sed 's/^/ /' + fi + else + log_error "Failed to query enclave registry" + fi + echo "" +} + +# Test chaincode invocation +test_invocation() { + log_info "Testing chaincode invocation..." + + set_peer_org1 + + local TEST_MSG="Validation test at $(date +%s)" + local INVOKE_CMD='{"Args":["storeAsset","'$TEST_MSG'"]}' + + if peer chaincode invoke \ + -o localhost:7030 \ + --ordererTLSHostnameOverride orderer0.group1.orderer.example.com \ + --tls \ + --cafile "$SAMPLE_DIR/target/fabric-config/crypto-config/ordererOrganizations/orderer.example.com/orderers/orderer0.group1.orderer.example.com/tls/ca.crt" \ + -C "$CHANNEL_NAME" \ + -n "$CC_ID" \ + -c "$INVOKE_CMD" \ + --waitForEvent \ + --peerAddresses localhost:7041 \ + --tlsRootCertFiles "$SAMPLE_DIR/target/fabric-config/crypto-config/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt" \ + &> /dev/null; then + log_success "Chaincode invocation successful" + else + log_error "Chaincode invocation failed" + fi + echo "" +} + +# Test chaincode query +test_query() { + log_info "Testing chaincode query..." + + set_peer_org1 + + # Wait a bit for the previous invocation to be processed + sleep 2 + + local QUERY_CMD='{"Args":["retrieveAsset"]}' + local RESULT=$(peer chaincode query -C "$CHANNEL_NAME" -n "$CC_ID" -c "$QUERY_CMD" 2>&1) + + if [ $? -eq 0 ]; then + log_success "Chaincode query successful" + log_info "Query result: $RESULT" + else + log_error "Chaincode query failed" + fi + echo "" +} + +# Check SGX mode +check_sgx_mode() { + log_info "Checking SGX configuration..." + + if [ -n "${SGX_MODE:-}" ]; then + log_success "SGX_MODE is set: $SGX_MODE" + else + log_warning "SGX_MODE is not set (will default to HW)" + fi + + # Check if running in simulation mode + if [ "${SGX_MODE:-HW}" = "SIM" ]; then + log_info "Running in SIMULATION mode (no SGX hardware required)" + else + log_info "Running in HARDWARE mode (requires SGX-capable CPU)" + + # Check for SGX devices + if [ -e /dev/sgx_enclave ] && [ -e /dev/sgx_provision ]; then + log_success "SGX devices found" + else + log_warning "SGX devices not found (may cause issues in HW mode)" + fi + fi + echo "" +} + +# Display validation summary +display_summary() { + echo "" + echo -e "${BLUE}========================================${NC}" + echo -e "${BLUE} Validation Summary${NC}" + echo -e "${BLUE}========================================${NC}" + echo "" + echo -e "Tests passed: ${GREEN}$PASSED${NC}" + echo -e "Tests failed: ${RED}$FAILED${NC}" + echo "" + + if [ $FAILED -eq 0 ]; then + echo -e "${GREEN}✓ All validation checks passed!${NC}" + echo "" + echo "The FPC with Fablo deployment is working correctly." + echo "You can now use the simple-cli-go client to interact with the chaincode." + return 0 + else + echo -e "${RED}✗ Some validation checks failed${NC}" + echo "" + echo "Please review the errors above and check:" + echo " - All containers are running" + echo " - Network is properly configured" + echo " - Chaincodes are deployed correctly" + echo " - Enclave is initialized and registered" + return 1 + fi +} + +# Main execution +main() { + echo -e "${BLUE}========================================${NC}" + echo -e "${BLUE} FPC with Fablo - Validation${NC}" + echo -e "${BLUE}========================================${NC}" + echo "" + + check_sgx_mode + check_containers + check_network + check_ercc + check_chaincode + check_enclave + test_invocation + test_query + + display_summary +} + +# Run main function +main "$@" + +# Made with Bob