AWS独立服务器部署Corda节点技术咨询及问题排查
Solution for Deploying Corda Nodes on AWS EC2 Cluster (PartyA, PartyB, Notary)
Let me walk you through fixing each of your issues with practical, hands-on steps based on my experience deploying Corda 4.5 on Linux servers:
1. Correct Path for Corda Jar Files
The official docs mention a 4.5 directory because it’s a best practice to use versioned directories for easy maintenance and upgrade tracking. Here’s what you should do:
- First, create the recommended directory structure (you can adjust this, but versioning simplifies future updates):
sudo mkdir -p /opt/corda/4.5 - Copy your built Corda jar file into this directory. If transferring from your local machine to AWS, use
scpor AWS S3 for secure file transfer:sudo cp ./corda-4.5.jar /opt/corda/4.5/ - Critical Security Note: Never run Corda as root. Create a dedicated
cordauser to own all files and run the service—this avoids permission conflicts and aligns with security best practices:sudo useradd -r -m -U -d /opt/corda -s /bin/bash corda sudo chown -R corda:corda /opt/corda
2. Network Certificates: Purpose, Necessity, and Usage
What are they?
Network certificates are the foundation of Corda’s trust model. They:
- Authenticate node identities across the network
- Enable encrypted peer-to-peer communication
- Ensure only authorized nodes can join and participate in transactions
Are they mandatory?
- Yes for all multi-node networks: Even for your private 3-node cluster, you can’t run a functional Corda network without them. They’re non-negotiable for establishing trust between nodes.
- For public/managed networks (like Corda Testnet), you need to request certificates from the network’s compatibility zone.
- For private clusters (your use case), you’ll generate your own private certificate authority (CA) and node certificates.
How to use them for your private cluster:
- Use the Corda Network Builder tool (included in the Corda distribution) to generate a root CA and node-specific certificates for PartyA, PartyB, and Notary.
- For each node, place the generated certificate files in the
certificatessubdirectory under the node’s root folder (e.g.,/opt/corda/nodes/Notary/certificates). - Update each node’s
node.confto disable public compatibility zone access (since this is a private network):compatibilityZone { url = null }
3. Fixing the Node Startup Error: "Couldn't find network parameters file..."
This error happens because your node can’t locate network parameters (rules defining network behavior like maximum transaction size, supported Corda versions) and can’t reach a compatibility zone to fetch them. Here’s how to resolve it:
Step 1: Generate Network Parameters (for private cluster)
- Use the
network-parameters-generatortool (included with Corda) to create anetwork-parametersfile:java -jar /opt/corda/4.5/corda-tools-network-parameters-generator-4.5.jar --output-file network-parameters - Customize parameters if needed (e.g., set
minimumPlatformVersionto 4) by editing the generated JSON file.
Step 2: Configure Nodes to Use Local Network Parameters
- Copy the
network-parametersfile to each node’s root directory (e.g.,/opt/corda/nodes/PartyA/). - Update each node’s
node.confto specify the file path:networkParametersFilePath = "/opt/corda/nodes/PartyA/network-parameters"
Step 3: Fix Permissions
- Ensure the
network-parametersfile is owned by thecordauser and has read permissions:sudo chown corda:corda /opt/corda/nodes/PartyA/network-parameters sudo chmod 644 /opt/corda/nodes/PartyA/network-parameters
Step 4: Start Nodes in the Correct Order
- Always start the Notary node first in a private cluster. It acts as the network parameter distributor, so other nodes rely on it to sync configuration (even with local files, starting Notary first avoids edge cases).
- Then start PartyA and PartyB nodes.
Quick AWS Deployment Checklist
- Ensure all EC2 instances have inbound/outbound rules open for Corda’s default ports: 10002 (P2P), 10003 (RPC), 8080 (webserver).
- Use systemd service files (as per official docs) to manage Corda as a service, running under the
cordauser. - Verify each node’s
node.confhas correct peer addresses (AWS public/private IPs of other nodes) in thep2pAddressandrpcSettingssections.
内容的提问来源于stack exchange,提问作者siqbal
相关产品推荐
相关产品推荐

