如何让其他用户连接我的Hyperledger网络(含Playground及样本链)并发起交易
Nice question! I’ve helped a few folks set up shared access to their Hyperledger networks in Playground, so let’s walk through the steps clearly for both your personal network and the sample one.
1. Prep Your Network for External Access
First, other users need the right configuration and credentials to connect.
- Export the Connection Profile: In Playground, navigate to your network’s settings (usually a gear icon or "Network Config" tab) and export the connection profile. This JSON file has all the critical details: peer/orderer addresses, MSP IDs, and CA endpoints.
- Share Limited Credentials: Don’t send admin keys! Instead, create dedicated user identities via your network’s Certificate Authority (CA) and share those user-specific certificates/keys. For Playground, you can use the built-in CA manager to register and enroll new users, or run this CLI command if you’re working with Fabric directly:
fabric-ca-client register --id.name collaborator --id.type client --id.affiliation org1.team --id.attrs 'hf.Registrar.Roles=client'
2. Grant Permissions to New Users
Connection info alone won’t let them do anything—you need to give them access to channels and chaincodes.
- Add Users to Channels: If your network uses channels (most do), make sure the new user’s MSP is added to the channel’s policy. In Playground, you can edit channel permissions under the "Channels" tab, or update the channel config via CLI if needed.
- Set Chaincode Transaction Permissions: Control what users can do at the chaincode level. For example, in a Fabric chaincode, you can check the caller’s identity before allowing a transaction:
func (s *MyContract) CreateAsset(ctx contractapi.TransactionContextInterface, assetID string, value string) error { callerID, err := ctx.GetClientIdentity().GetID() if err != nil { return fmt.Errorf("failed to get caller ID: %v", err) } // Only allow users from org1 to create assets if !strings.Contains(callerID, "org1.example.com") { return fmt.Errorf("user %s is not authorized to create assets", callerID) } // Proceed with asset creation logic return ctx.GetStub().PutState(assetID, []byte(value)) } - Update ACLs (Optional): For more granular control, adjust the network’s Access Control Lists (ACLs) to restrict actions like joining channels or querying peers to specific roles.
3. Walk Users Through Connecting & Executing Transactions
Once they have the config and credentials, here’s how they get started:
- Import Connection Profile: Have them open Playground, select "Import Network" or "Connect to External Network", then upload the connection profile you sent.
- Import User Identity: In Playground’s "Identities" tab, select "Import Identity" and upload the user certificate/key pair you shared. Name the identity something recognizable (e.g., "Collaborator - Org1").
- Connect & Transact: Select the imported identity and connection profile, then connect to your network. They’ll now see the chaincodes deployed on the network—navigate to the "Test" tab, pick a chaincode function, input parameters, and hit "Submit Transaction" to run it.
4. Fix Common Hiccups
- Connection Failures: If you’re running Playground locally, you’ll need to expose your node ports to the internet (use a port forwarding tool) so external users can reach your peers/orderers. For cloud-hosted Playground, double-check that users have access to your tenant/project.
- Permission Denied Errors: Verify the user’s identity is enrolled under the correct MSP, added to the channel, and that your chaincode/ACLs allow the action they’re trying to take.
- Certificate Mismatches: Make sure the user’s imported credentials match the MSP ID specified in the connection profile.
内容的提问来源于stack exchange,提问作者Alexandre Marechal Ferrant
相关产品推荐
相关产品推荐

