Skip to content

Repository files navigation

keeper

Permissionless keeper that keeps Google's JWT signing keys trusted on chain: it obtains MPC-TLS notarized readings of Google's JWKS from a libid notary and submits rotate() to GoogleJwtRoots on every configured network, paying the Notary Fee. Configuration is one keeper.toml; the container image and how to run it are described in Dockerfile.

End-to-end test

The real rotation path: the published notary image, the contract stack libid-deploy lays down on anvil, and Google's live key set. compose.yaml is the stack; the test runs on the host and reads e2e/local-dev.toml, chain-configurations' published network file unmodified, through the keeper's own network_file. That file names the chain by its compose service name, so the host maps it once.

Needs Docker with Compose v2.7 or later (up --wait over a one-shot service), a Rust toolchain, sudo for the hosts line, and network to Google.

echo "127.0.0.1 anvil" | sudo tee -a /etc/hosts   # once per machine
docker compose up -d --wait --build
cargo test --test e2e_real -- --ignored --nocapture
docker compose down                                # a fresh chain per run

CI runs the same commands (.github/workflows/ci.yml, job e2e). When something fails, docker compose logs has every service's output.

About

Keeper is a maintenance daemon that watches authoritative off-chain sources and pushes updates on-chain when they drift. Its first duty is rotating OIDC public keys (JWKS) for each supported platform on every configured chain; new duties plug in as subcommands.

Resources

Contributing

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages