HyperLedger Fabric用户与Composer参与者的区别及角色职责咨询
Hey there! Let's break this down clearly since mixing up these terms is super common when starting out with Hyperledger Fabric and Composer. I'll cover the crypto-config roles first, then clarify the User/Participant confusion across both frameworks.
First: Quick Term Clarification (The Big Confusion!)
Let’s get this straight first, because it’s easy to mix these up:
- Hyperledger Fabric User: This is a cryptographic identity (backed by certificates) that exists at the network infrastructure level. Think of it as a "network login" that lets an entity (person, service) interact with Fabric peers/orderers.
- Hyperledger Composer Participant: This is a business-level role defined in your business network. For example,
Supplier,Customer, orLogisticsManager. A Participant is always tied to a Fabric User (the underlying identity) but adds business context to who is performing actions.
Crypto-config.yaml: Admin & Regular User Roles (Fabric Layer)
The crypto-config.yaml file is your blueprint for generating all the cryptographic identities (certificates, keys) your Fabric network needs. Let’s break down the roles here:
Organization Admin Users
These are the "super users" for each organization in your Fabric network:
- Core Role: The highest-authority identity for their organization, with full control over the org’s network presence.
- Key Responsibilities:
- Register and enroll other identities (regular users, peer nodes, orderer nodes) with the organization’s Certificate Authority (CA).
- Create and sign the organization’s MSP (Membership Service Provider) configuration, which defines how the network validates the org’s identities.
- Perform network-level admin tasks: joining the org to a channel, updating channel configurations, or installing chaincodes on peers.
- Manage permissions for the org’s CA (if using Fabric’s built-in CA).
- Critical Note: Admin identities should never be used for regular business transactions—reserve them for setup and maintenance only.
Regular Users in Crypto-config
These are the day-to-day identities for people/services performing business operations:
- Core Role: Standard operational identities tied to an organization, used to interact with the Fabric ledger.
- Key Responsibilities:
- Submit transaction proposals to peer nodes (e.g., "transfer asset X" or "update order status").
- Query the ledger to retrieve data (e.g., "check current inventory levels").
- Sign transaction proposals to prove their identity, as required by Fabric’s consensus rules.
- Operate within the permissions set by the org’s admin (via Fabric’s ACLs, or later via Composer’s rules).
- Note: Regular user certificates are issued by the org’s CA (either root or intermediate, per your crypto-config setup) and have limited permissions compared to admins.
Hyperledger Composer Business Network Deep Dive
Composer sits on top of Fabric to simplify building business logic—here’s how the roles translate:
Participants in Composer
- Definition: These are the business actors in your network. You define them in your Composer model file (
.cto), e.g.:participant Supplier identified by supplierId { o String supplierId o String name } - Binding to Fabric Users: Every Participant must be linked to a Fabric User identity. This is how Composer maps a business role to a valid network identity.
- Purpose: Used to enforce business rules via Composer’s Access Control Language (ACL). For example, you could write a rule like: "Only Suppliers can create PurchaseOrder assets".
Composer Users vs Fabric Users
- In Composer, a "User" is just a direct mapping to a Fabric identity. It’s the underlying credential that lets a Participant interact with the Fabric network.
- Think of it this way: The Fabric User is the "key to the door", and the Composer Participant is the "job title" that defines what you can do once inside.
Typical Workflow Example
- Use
crypto-config.yamlto generate your org’s admin and regular user certificates (Fabric setup). - Define your Participant types in Composer’s model file (business logic setup).
- Bind a Fabric regular User identity to a Composer Participant instance (linking network identity to business role).
- Set up Composer ACLs to restrict actions to specific Participant roles (enforcing business rules).
内容的提问来源于stack exchange,提问作者Vankam Sree Hari

