Deployments & Artifact Pins
Deploy the contracts and record the hashes needed to authenticate them.
Record deployment identity#
Record the chain, Pool, verifier and hash contracts, receiving directory, routers, assets and routes. Keep runtime hashes and deployment blocks alongside the proof files served by the app.
For external proxies, record the implementation slot and implementation hash too. Their behavior can change while the proxy bytecode stays the same.
Run the deployment script#
Select a network profile and inspect it before running the core script. It writes addresses and code hashes to your output directory. Give every attempt a fresh directory.
The script cannot resume a failed deployment. Start again with fresh output rather than treating partial results as complete. Keep deployer signing material in local secret storage, outside committed configuration.
# Run from the protocol checkout on the provisioned Linux host.
# Supply reviewed RPC, deployer and governance configuration externally.
export FUYU_NETWORK=sepolia
export FUYU_OUT=/absolute/path/to/fresh-deployment-output
node contracts/script/deploy-core.cjsConfigure governance#
The publisher admits tokens and routes and manages source policy. The governor adds delayed admission and council, guardian and reviewer roles. Use deployer-as-publisher only for development or testnet deployments.
Review token transfer behavior and external dependencies, then test original exit behavior. Setting governance roles does not perform those checks for you.
Check the release#
Record the source revision, reproduced contract files and proof-key hashes. Run funded app flows and recovery tests, then verify the public runtime serves that same deployment. Contract deployment success is only one part of this process.
The repository uses development proof keys. Production key setup is still required, and a checked-in network profile or fork report cannot tell you which public mainnet deployment is currently served.
- Check the chain and contract code before funding or proving.
- Check served proof-file digests and the Pool verifier hash.
- Test ordinary exit as well as admitted actions.
- Save the recovery bundle's hash and its deployment trust data.