# Full disclosure: Let's publish validator operations & infrastructure info 📖

**URL:** https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242
**Category:** Validation
**Created:** [June 4, 2019, 11:49pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242 "2019-06-04T23:49:05Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![Gavin](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/gavin/32/5602_2.png) [@Gavin](https://forum.cosmos.network/u/Gavin)
#### Post date: [June 4, 2019, 11:49pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/1 "2019-06-04T23:49:05Z")

</div>

Full disclosure on Figment Networks’ Cosmos validator infrastructure and operations: [https://twitter.com/FigmentNetworks/status/1136000871463104512](https://twitter.com/FigmentNetworks/status/1136000871463104512)

Let’s get 🗣 about how to make staking on Cosmos as secure as possible, and let’s be open 📖 for delegators to make informed decisions.

Spread the word: more transparency and a stronger, more secure Cosmos network 💪

[Medium article here](https://medium.com/figment-networks/full-disclosure-figments-cosmos-validator-infrastructure-3bc707283967?_branch_match_id=660322389149300777)

---

<div class="post-metadata">

### Author: ![guyht](https://avatars.discourse-cdn.com/v4/letter/g/439d5e/32.png) [@guyht](https://forum.cosmos.network/u/guyht)
#### Post date: [June 5, 2019, 3:41pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/2 "2019-06-05T15:41:28Z")

</div>

Thanks Gavin, we will be publishing something soon for Neptune Stake and I think this is a great initiative.

Something I would also like to see added to the block explorers, is some way to indicate which validators are using an HSM versus software keys, as I think its an important consideration for delegators.

Im not aware of any way to do this automatically, but even a community verification for HSM and correctly setup infrastructure would be very beneficial for the community.

This would both inform delegators which validators have properly setup infrastucture, and also encourage validators that dont to improve their setup.

---

<div class="post-metadata">

### Author: ![Gavin](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/gavin/32/5602_2.png) [@Gavin](https://forum.cosmos.network/u/Gavin)
#### Post date: [June 5, 2019, 6:09pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/3 "2019-06-05T18:09:30Z")

</div>

Thanks Guy, it would be nice to have a badge or something to indicate HSM-based validators. But verifying that would open a whole can of worms that we’re not prepared to handle at the moment. We’d be open to chatting with anyone else who is interested in implementing this sort of thing 👍

---

<div class="post-metadata">

### Author: ![unicorn](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/unicorn/32/612_2.png) [@unicorn](https://forum.cosmos.network/u/unicorn)
#### Post date: [June 6, 2019, 6:34am UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/4 "2019-06-06T06:34:08Z")

</div>

HSM based validation is not the only secure solution. We use a custom remote signing sever, which is similarly secure. If you want to prove that your setup is really secure, get audited from a 3rd party and publish the results. Feel free to get in touch with us [https://www.ethermat.com](https://www.ethermat.com/)

If you want to go a step further get certified… ISO27001 etc.

We strongly believe that the ecosystem might profit from non-HSM validators. If all deployments were the same, potential attacks would have a critical impact. Mixed validators with different deployment styles and (custom) software strongly add value to the ecosystem.

---

<div class="post-metadata">

### Author: ![chris-chainflow](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/chris-chainflow/32/1530_2.png) [@chris-chainflow](https://forum.cosmos.network/u/chris-chainflow)
#### Post date: [June 11, 2019, 5:55pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/5 "2019-06-11T17:55:38Z")

</div>

Here’s Chainflow’s -

> **[Chainflow Cosmos Validator Network Architecture](https://chainflow.io/cosmos-validator-architecture/)**
>
> This architecture draws on my 20+ years of experience designing large, global and mission critical network and data center architectures.

In describing the architecture, I again am trying to strike a beneficial balance. This balance is between providing transparency, while not compromising operational security.

---

<div class="post-metadata">

### Author: ![clawmvp](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/clawmvp/32/396_2.png) [@clawmvp](https://forum.cosmos.network/u/clawmvp)
#### Post date: [July 24, 2019, 7:52pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/6 "2019-07-24T19:52:55Z")

</div>

we did publish some along the way

> **[On Validator Setup » How to Choose the Best Validator? | 01NODE](https://01node.com/on-validator-setup/)**
>
> How to choose the best validator? Or a particular one for that matter. Most of the time we let the metrics tell the stories, and we are more about the facts and action than words, although good stories do sell! But this time we decided to give a...

  

> **[on validator setup — part2](https://medium.com/01node/on-validator-setup-part2-c78c05937927)**
>
> i think it s time to publish an update regarding our validator setup.

---

<div class="post-metadata">

### Author: ![michaelng](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/michaelng/32/405_2.png) [@michaelng](https://forum.cosmos.network/u/michaelng)
#### Post date: [July 25, 2019, 7:06am UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/7 "2019-07-25T07:06:46Z")

</div>

We will be disclosing ours soon in a medium post and also our learnings along the way. Will update here!

---

<div class="post-metadata">

### Author: ![mdyring](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@mdyring](https://forum.cosmos.network/u/mdyring)
#### Post date: [July 25, 2019, 12:54pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/8 "2019-07-25T12:54:11Z")

</div>

Great idea!

We’re already providing documentation about our infrastructure through our website: [https://validator.network](https://validator.network).

Datacenter:

- Using YubiHSM inside redundant isolated hosts
- Redundant validators hosts

Redundant, dedicated bandwidth to AWS Frankfurt where we operate multiple public sentry nodes in different availability zones.

We’re doing 24x7 monitoring via Pagerduty on logs and Prometheus data and have developed in-house tooling for improving observability.

20+ years of experience operating secure and highly available IT infrastructure.

---

<div class="post-metadata">

### Author: ![iqlusion](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/iqlusion/32/294_2.png) [@iqlusion](https://forum.cosmos.network/u/iqlusion)
#### Post date: [July 25, 2019, 7:40pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/9 "2019-07-25T19:40:40Z")

</div>

You can find a description of our validator architecture and some operations info here:

> **[A look inside iqlusion's Cosmos Hub Validator architecture • the iqlusion blog](https://iqlusion.blog/a-look-inside-our-validator-architecture)**
>
> By Tony Arcieri and Shella Stephens Here at iqlusion, we have taken our past professional experiences from infrastructure and security teams at notable Silicon Valley companies and applied them in building what we believe is one of the most... | the...

We also tweet when we’re performing maintenance, noting if there was downtime/missed blocks, and also have published a postmortem for our first outage:

> **[Postmortem: 2019-03-29 DNS-related Cosmos Hub Validator Incident • the...](https://iqlusion.blog/postmortem-2019-03-29-dns-related-cosmos-hub-validator-incident)**
>
> It began with a series of PagerDuty alerts on our phones. We occasionally have false positives, but this was different: several alarms in a row. We looked up at the display in our NOC (above photo, although from a different day) to see that this... |...

> [@Gavin](#):
>
> Thanks Guy, it would be nice to have a badge or something to indicate HSM-based validators.

This would be interesting, especially if HSM-backed validators could publish cryptographically signed attestations of how they are storing keys as a sort of (trusted hardware-based) “proof” of how their consensus keys are generated/stored.

Unfortunately I just checked if the YubiHSM2’s attestation features were capable of attesting Ed25519 keys and it appears that’s not supported (it only appears to support attestation for RSA and ECDSA keys).

---

<div class="post-metadata">

### Author: ![michaelng](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/michaelng/32/405_2.png) [@michaelng](https://forum.cosmos.network/u/michaelng)
#### Post date: [July 26, 2019, 3:29pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/10 "2019-07-26T15:29:50Z")

</div>

We have just published our setup and some learnings here: [http://bit.ly/SetupAndLearnings](http://bit.ly/SetupAndLearnings)

We will continue to publish articles on some tools we use and more learnings along the way. Happy to discuss infrastructure related issues!

---

<div class="post-metadata">

### Author: ![gaia](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/gaia/32/1015_2.png) [@gaia](https://forum.cosmos.network/u/gaia)
#### Post date: [January 3, 2020, 8:54pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/11 "2020-01-03T20:54:58Z")

</div>

We just published our infrastructure to our website: [https://freshatoms.com/](https://freshatoms.com/)

We do not have automatic failover yet, for fear of slashing, but we can get the spare node and signer running nearly seamlessly in case of maintenance (missing 0 to 3 blocks max), or on alert (in case of failure) within minutes of receiving the alert (which is monitored 24/7).

---

<div class="post-metadata">

### Author: ![asmodat](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/asmodat/32/813_2.png) [@asmodat](https://forum.cosmos.network/u/asmodat)
#### Post date: [February 19, 2020, 11:49am UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/12 "2020-02-19T11:49:13Z")

</div>

KIRA Staking, architecture overview and disclosure -\> [https://medium.com/kira-core/kira-cosmos-hub-validator-db1828264506](https://medium.com/kira-core/kira-cosmos-hub-validator-db1828264506)

---

<div class="post-metadata">

### Author: ![FHZ](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/fhz/32/7351_2.png) [@FHZ](https://forum.cosmos.network/u/FHZ)
#### Post date: [November 11, 2024, 2:52pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/13 "2024-11-11T14:52:03Z")

</div>

## **Question(s):**

Does the broader Cosmos Hub community have the right to explicitly know, and distinguish, whether or not certain **Validators are the same entity, direct partners, etc**?

(_Instead of opening a new conversation, saw this thread captured the general sentiment of the question above_)

How is a user to know if certain COI’s exist within the Validator set when choosing to delegate?

At this point, who is to say if **Validator X** is, or is not, **Validator Y** , or **Validator Z**? In the spirit of securing true decentralization, is publishing validator operations & infrastructure info “enough?”

Curious to hear others thoughts.

---

<div class="post-metadata">

### Author: ![FHZ](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.cosmos.network/fhz/32/7351_2.png) [@FHZ](https://forum.cosmos.network/u/FHZ)
#### Post date: [November 15, 2024, 4:30pm UTC](https://forum.cosmos.network/t/full-disclosure-lets-publish-validator-operations-infrastructure-info/2242/14 "2024-11-15T16:30:36Z")

</div>

Fascinating to see validators blatantly ignore these questions, which would serve as a net benefit for all small/new validators, delegators, and users, to be made fully aware.
