Skip to main content
deCDN ships two binaries. decdn is the CLI you type commands into: setup, bonding, status. decdn-node is the daemon that serves traffic. You need both on the host.

1. Install

Pick one of three ways. Release archive. Download the decdn and decdn-node archives for your platform from the latest release, then put both binaries on your PATH. A maintainer signs the SHA256SUMS manifest that covers the archives; SECURITY.md explains how to verify it. Cargo.
Docker. The image holds the decdn-node daemon only, so install the decdn CLI from the release archive or with Cargo as well. You use it for keys, setup and status.

2. Write the config

This writes ~/.decdn/node.toml with the testnet RPC endpoint and the deployed contract addresses filled in. Open it and set the cache size to match the disk you give the node:
~/.decdn/node.toml
See Requirements for how to size it. The default RPC endpoint is the public, rate-limited Arbitrum Sepolia endpoint. For a node that runs 24/7, use an RPC provider of your own.

3. Create keys and get funds

Send the operator address that whoami prints to the team to receive testnet TOKEN, and fund it with a little Arbitrum Sepolia ETH. See Get testnet funds.

4. Bond and register

Preview first. --dry-run checks the RPC, your clock, your TOKEN and ETH balances and the exact bond, and submits nothing:
When every check passes, run it for real:
setup shows the operator terms and asks you to accept them, confirms the bond, then bonds, declares your capacity and registers the node on-chain. It ends with a go/no-go summary.
  • --mbps is the bandwidth you commit to serve. It sets your bond. Declare what your uplink sustains.
  • --region is your ISO 3166-1 alpha-2 country code, such as BR or DE. It sets which regional takedown rules apply to you. See Compliance and risk.
  • --multiaddr is the public address peers dial. A dual-stack host passes a second one: /ip6/<addr>/udp/4433/quic-v1. Omit the flag to register the host’s detected public address. A host behind NAT with no forwarded port registers none and relies on hole-punching and relays.

5. Run the node

The daemon needs the keystore password to start. On a headless host, put it in a file readable only by the node’s user and pass --keystore-password-file (or set DECDN_KEYSTORE_PASSWORD_FILE, as the Docker example does), or set DECDN_KEYSTORE_PASSWORD.

Under systemd

/etc/systemd/system/decdn-node.service
SIGTERM drains in-flight deliveries and flushes settlement before the process exits. Keep TimeoutStopSec generous so a stop never cuts a paid delivery short.

Under Docker

Publish 4433 as UDP: QUIC does not use TCP. The volume holds the config, keys and cache, so mount it on the disk you sized the cache for. The container runs as uid 1000, so that user must own the mounted directory.

6. Check it

Your node earns from the first paid delivery onward. Next, turn on pull-through so it can fill cache misses, and read How you get traffic to know what volume to expect.