您好,登錄后才能下訂單哦!
如何在現有Fabric網絡上添加一個Org,很多新手對此不是很清楚,為了幫助大家解決這個難題,下面小編將為大家詳細講解,有這方面需求的人可以來學習下,希望你能有所收獲。
如何在現有Fabric網絡上添加一個Org,下面基于IBM DeveloperWorks——使用簡單的工具將組織添加到現有的Hyperledger Fabric區塊鏈網絡中。
在byfn.sh所在的同一路徑上啟動此實驗。
Fabric網絡已經創建并運行(BYFN樣本)。
使用最新的Fabric build>= 1.1.0-preview
這個實驗需要jq
二進制文件。從jq存儲庫下載它們。
wget https://github.com/stedolan/jq/releases/download/jq-1.5/jq-osx-amd64 chmod +x jq-osx-amd64 sudo mv jq-osx-amd64 /usr/local/bin/jq
wget https://github.com/stedolan/jq/releases/download/jq-1.5/jq-linux64 chmod +x jq-linux64 sudo mv jq-linux64 /usr/local/bin/jq
創建配置文件:
cat > crypto-config-add.yaml <<EOF PeerOrgs: - Name: Org3 Domain: org3.example.com Template: Count: 1 Users: Count: 1 EOF
從配置文件生成證書:
../bin/cryptogen generate --config=./crypto-config-add.yaml
您在./crypto-config/peerOrganizations/org3.example.com/
上獲得了Org3的證書。
configtxlator工具旨在支持重新配置Fabric網絡。
../bin/configtxlator start &
查詢cli
容器的當前配置:
docker exec -it cli peer channel fetch config config_block.pb -o orderer.example.com:7050 -c mychannel --tls --cafile ./crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem docker cp cli:/opt/gopath/src/github.com/hyperledger/fabric/peer/config_block.pb .
使用configtxlator解碼獲取的配置文件:
curl -X POST --data-binary @config_block.pb http://127.0.0.1:7059/protolator/decode/common.Block > config_block.json
從解碼的配置文件config
中提取擴展配置部分:
jq .data.data[0].payload.data.config config_block.json > config.json
從配置部分提取Org1MSP
部分:
jq .channel_group.groups.Application.groups.Org1MSP config.json > Org1MSP.json
基于Org1MSP.json
創建Org3MSP.json
文件:
ADMIN_CERT=$(cat ./crypto-config/peerOrganizations/org3.example.com/users/Admin\@org3.example.com/msp/signcerts/Admin\@org3.example.com-cert.pem |base64 |tr -d '\n') ROOT_CERT=$(cat ./crypto-config/peerOrganizations/org3.example.com/ca/ca.org3.example.com-cert.pem |base64 |tr -d '\n') TLS_ROOT_CERT=$(cat ./crypto-config/peerOrganizations/org3.example.com/tlsca/tlsca.org3.example.com-cert.pem |base64 |tr -d '\n') jq --arg admin ${ADMIN_CERT} --arg root ${ROOT_CERT} --arg tls ${TLS_ROOT_CERT} '.values.MSP.value.config.admins[0] = $admin | .values.MSP.value.config.root_certs[0] = $root | .values.MSP.value.config.tls_root_certs[0] = $tls' Org1MSP.json > Org3MSP.json sed -i 's/Org1MSP/Org3MSP/g' Org3MSP.json
將Org2MSP.json
的內容放在config.json
文件中的Org2MSP
之后:
ORG3=$(cat Org3MSP.json) jq --argjson org3 "$ORG3" '.channel_group.groups.Application.groups.Org3MSP = $org3' config.json > updated_config.json
通過configtxlatr,編碼配置文件,config.json
和updated_config.json
:
curl -X POST --data-binary @config.json http://127.0.0.1:7059/protolator/encode/common.Config > config.pb curl -X POST --data-binary @updated_config.json http://127.0.0.1:7059/protolator/encode/common.Config > updated_config.pb
計算配置更新增量:
curl -X POST -F original=@config.pb -F updated=@updated_config.pb http://127.0.0.1:7059/configtxlator/compute/update-from-configs -F channel=mychannel > config_update.pb
將配置更新文件解碼為JSON:
curl -X POST --data-binary @config_update.pb http://127.0.0.1:7059/protolator/decode/common.ConfigUpdate > config_update.json
echo '{"payload":{"header":{"channel_header":{"channel_id":"mychannel", "type":2}},"data":{"config_update":'$(cat config_update.json)'}}}' > config_update_as_envelope.json
將封裝的消息編碼為protobuf格式:
curl -X POST --data-binary @ config_update_as_envelope.json http://127.0.0.1:7059/protolator/encode/common.Envelope> config_update_as_envelope.pb
在cli
容器上復制新交易:
docker cp config_update_as_envelope.pb cli:/opt/gopath/src/github.com/hyperledger/fabric/peer/
在所有MSP
上簽署配置更新交易:
將Org1MSP
的簽名添加到新交易中
docker exec -it \ -e CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt \ -e CORE_PEER_TLS_KEY_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.key \ -e CORE_PEER_LOCALMSPID=Org1MSP \ -e CORE_PEER_TLS_CERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.crt \ -e CORE_PEER_TLS_ENABLED=true \ -e CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp \ cli \ peer channel signconfigtx -f config_update_as_envelope.pb \ -o orderer.example.com:7050 --tls --cafile ./crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem
將Org2MSP
的簽名添加到新交易中
docker exec -it \ -e CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/ca.crt \ -e CORE_PEER_TLS_KEY_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.key \ -e CORE_PEER_LOCALMSPID=Org2MSP \ -e CORE_PEER_TLS_CERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.example.com/peers/peer0.org2.example.com/tls/server.crt \ -e CORE_PEER_TLS_ENABLED=true \ -e CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.example.com/users/Admin@org2.example.com/msp \ cli \ peer channel signconfigtx -f config_update_as_envelope.pb \ -o orderer0.example.com:7050 --tls --cafile ./crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem
提交更新的交易:
docker exec -it \ -e CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crt \ -e CORE_PEER_TLS_KEY_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.key \ -e CORE_PEER_LOCALMSPID=Org1MSP \ -e CORE_PEER_TLS_CERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/server.crt \ -e CORE_PEER_TLS_ENABLED=true \ -e CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp \ cli \ peer channel update -f config_update_as_envelope.pb \ -o orderer.example.com:7050 -c mychannel --tls --cafile ./crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem
現在添加Org3就完成了!
為peer0.org3
創建一個compose文件:
cat > docker-compose-peer0-org3.yaml <<EOF version: '2' networks: byfn: services: peer0.org3.example.com: container_name: peer0.org3.example.com extends: file: base/peer-base.yaml service: peer-base environment: - CORE_PEER_ID=peer0.org3.example.com - CORE_PEER_ADDRESS=peer0.org3.example.com:7051 - CORE_PEER_GOSSIP_EXTERNALENDPOINT=peer0.org3.example.com:7051 - CORE_PEER_GOSSIP_BOOTSTRAP=peer0.org3.example.com:7051 - CORE_PEER_LOCALMSPID=Or3MSP volumes: - /var/run/:/host/var/run/ - ./crypto-config/peerOrganizations/org3.example.com/peers/peer0.org3.example.com/msp:/etc/hyperledger/fabric/msp - ./crypto-config/peerOrganizations/org3.example.com/peers/peer0.org3.example.com/tls:/etc/hyperledger/fabric/tls ports: - 11051:7051 - 11053:7053 networks: - byfn EOF
啟動 peer0.org3:
docker-compose -f docker-compose-peer0-org3.yaml up -d
執行cli
容器的shell:
docker exec -it cli bash
在shell上,運行以下命令:
CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.example.com/peers/peer0.org3.example.com/tls/ca.crt CORE_PEER_TLS_KEY_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.example.com/peers/peer0.org3.example.com/tls/server.key CORE_PEER_LOCALMSPID=Org3MSP CORE_PEER_TLS_CERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.example.com/peers/peer0.org3.example.com/tls/server.crt CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.example.com/users/Admin\@org3.example.com/msp CORE_PEER_ADDRESS=peer0.org3.example.com:7051 CHANNEL_NAME=mychannel peer channel join -b ${CHANNEL_NAME}.block peer chaincode install -n mycc -v 1.0 -p github.com/hyperledger/fabric/examples/chaincode/go/chaincode_example02 peer chaincode query -C $CHANNEL_NAME -n mycc -c '{"Args":["query","a"]}'
看完上述內容是否對您有幫助呢?如果還想對相關知識有進一步的了解或閱讀更多相關文章,請關注億速云行業資訊頻道,感謝您對億速云的支持。
免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。