KERI Development & Deployment - Keanu Pahio

KERICONF26 Day 2 · 48:15

0:00 Keanu Pahio | KERI Developement & Deployment | KERI Conference 2026

0:04 I'm gonna start

0:07 and talk about KERI development

0:10 and deployment

0:12 [checks]

0:20 [inaudible, reconstruction - The Objectives are to:]

0:23 [Understand the architecture for deployment

0:31 understand the role of each part

0:37 Deploying local witnesses,

0:43 watchers and wallet

0:47 And to give an idea

0:53 where you]

0:59 can start for development on your own

1:02 and that includes maybe doing your

1:06 own plugin for Locksmith and developing

1:10 your own API for witnesses and

1:13 watchers.

1:15 So I want to talk first about the KERI

1:18 infrastructure that we have.

1:20 [inaudible - We have the Locksmith

1:22 wallet for signing, witnesses]

1:24 and the watchers which is pretty much

1:26 you've seen this the diagram a lot

1:30 in the past few days, but for the

1:33 requirements, the

1:36 only thing that we really need is Python.

1:39 We recommend the version 3.13, [because]

1:44 3.14 had some issues with some repos.

1:49 3.13 should be fine. And then [we need]

1:53 Libsodium because this is what

1:56 KERI uses for its cryptographic

1:58 library.

2:00 First, we'll go with the wallet.

2:03 It's a Locksmith. The role of

2:05 Locksmith on this wallet is to generate

2:07 the AIDs to sign it, to have the key

2:11 pairs secure and to store and verify

2:14 through your KELs and finally the

2:16 OOBIs.

2:18 Nothing more, I think, to expand on,

2:23 It's the basic function

2:25 of a wallet.

2:27 And then we're going to go through

2:28 deploying it. So we have just three

2:31 parts that we're going to go through

2:32 individually and first I'm

2:35 going to show you the repo and how you

2:37 can set up the environment with its

2:39 dependencies and how to run it.

2:43 Everything, every deployment that we're

2:44 going to go through are going to be

2:46 local.

2:47 I can explain that for a while

2:49 later. First you have the public

2:54 repo for the Locksmith which is on

2:57 the KERI Foundation [github repo]. Note that what

3:01 I'm going to use in this presentation

3:03 for the demo is from a branch of this

3:09 repo which is the KERI Foundation

3:11 branch. It's not the main branch that

3:13 I'm going to use because the KERI

3:15 Foundation branch has the KERI

3:17 Foundation plugin that we're going to

3:18 talk about later. I'm also going to

3:23 try to get your attention for the

3:26 docs that are provided by the repo and

3:29 I'm just going to show you a bit through

3:30 those docs. So the developer guide in

3:34 those docs explain what I

3:37 explained before. So if you need a

3:39 reminder, you can just go to the repo

3:41 and then read it. But first it's

3:44 going to be Python 3.13. And then to set

3:46 up your environment, you just have to

3:48 follow the commands that are on the

3:51 developer guide. Pretty easy.

3:55 And then finally to run it, you have the

3:58 Qt resource regeneration. And once you

4:01 copy paste and run those commands,

4:03 you can run this one. Then

4:07 hopefully a lot of initialization logs

4:11 will pop up and you will

4:13 have your Locksmith.

4:16 I'm going to run it myself,

4:21 and show you.

4:24 I'm going to

4:28 activate the virtual environment

4:32 [preparing his demo]

5:10 So here we have our Locksmith.

5:13 I just created a vault, but we can…

5:16 I make a new one…

5:20 call it presentation.

5:23 No passcode and then, here you go.

5:27 So here…

5:29 – A vault is just a logical grouping of

5:32 of AIDs or ..?

5:35 Yes, if you're familiar with the

5:37 KERIpy code, it's the same as a Habery

5:40 which is where you host your AIDs and

5:42 which is where you have your key pairs

5:44 and all that stuff.

5:45 – Okay.

5:47 Here you have the KERI Foundation

5:50 plugin which we're going to talk about

5:52 now. The reason

5:57 why we have a KERI Foundation plugin is

6:00 because of a boot server that

6:02 we have.

6:04 So the boot server, what is the boot

6:06 server? Well the boot server is kind of

6:09 the in between

6:12 between Locksmith and the

6:14 witnesses and watchers. And the role of

6:16 the boot server is to provision the

6:18 witnesses to your wallet. And now,

6:22 maybe a question that you might

6:24 have is why can I not just talk from

6:27 Locksmith directly to the witnesses and

6:29 watchers? The reason for that is

6:32 the witnesses and watchers API.

6:36 When you look here, for example

6:39 for the witnesses API, you have actually

6:43 two servers: you have the boot server

6:45 and then you have the witness server.

6:47 The boot server, if you pay attention to

6:50 the API,

6:53 this is the one that actually creates

6:56 the witnesses and deletes them. And the

6:59 problem is that the boot server is

7:02 private. So it's not publicly

7:03 accessible. So even if you try to send a

7:05 request to it, it will not respond.

7:09 But the witness server and the

7:11 watcher server, those two are public. So

7:14 once you have your witnesses and your

7:16 watcher you can publicly access those

7:19 however you want. And same for the

7:21 watcher API this is also private. So the

7:24 reason is that we have our boot

7:28 server which serve as the one who

7:33 will call the private APIs to get the

7:36 witnesses and watchers and the

7:39 KERI Foundation plug-in acts as a

7:41 bridge between the Locksmith wallet and

7:44 the boot server. Currently the

7:49 KERI Foundation plugin is in charge of

7:52 onboarding, witness registration, watcher

7:55 resolution and auth management. And when

7:57 we're talking about onboarding we're

7:59 talking about setting you up

8:02 so you can have your own witnesses

8:05 and watcher.

8:07 Now an important thing to note is that

8:10 for, at least locally, the

8:13 boot server has

8:16 to be on the same machine or server as

8:21 the witnesses and watchers so it can

8:23 talk locally. As I mentioned before

8:26 because the APIs are private.

8:36 Let's go through the

8:38 plugin before we go through the boot

8:40 server. So I want to go to the plugin

8:42 and how you could, if you wanted, make

8:45 your own plugin.

8:47 If you go to the Locksmith

8:50 repository and if you go to

8:53 “Locksmith/plugins/base.py” it has a bunch of

8:56 classes that allows you to create your

8:59 own plugin. If you look at the

9:03 “PluginBase,” it has a bunch of methods

9:06 that you can override to create your

9:09 own plugin.

9:11 For example, here is the KERI

9:13 Foundation plugin that is in the plugin

9:16 folder. You can also look it up on the

9:18 KERI Foundation branch. It is using

9:21 the plugin base, the witness provider

9:23 plugin and the account provider plugin.

9:26 Then it has

9:28 u for example here you can see that it's

9:30 overriding the plugin_id function

9:32 and the initialize function. I'm not

9:35 going to go into too much detail as to

9:37 How you can .. or What you should put into

9:40 into those methods, but at least know

9:42 that it's there. And if you need the

9:44 preferences you can just look at the

9:46 KERI Foundation plugin in the

9:48 repository to get some

9:51 inspiration.

9:54 Now I want to go

9:57 to the boot server. To

10:01 remind you, the boot server serves as a

10:03 public API to provision your

10:06 witnesses and watcher. The kf-boot is

10:09 also available publicly. So if you want

10:11 to look at it, you can. It's on the

10:13 KERI Foundation repository. You can

10:16 look at it and see how the code works.

10:20 To run it, very simple, create your

10:23 virtual environment. And then here are

10:26 the variables that your KERI

10:30 Foundation boot needs to talk to

10:33 the witnesses and watcher. I'm going

10:36 to just show you a demo.

10:43 Here I have my KERI Foundation

10:47 boot server. I'm going to

10:52 activate it. And then

10:55 just like in the

10:59 slide that I showed, I'm just going to

11:00 copy .., I'm not going to install the

11:03 dependencies since I have already done it.

11:06 I'm going to go here, paste these,

11:09 and then run it. So now you can see that

11:12 it's running here. And if I go

11:17 to my Locksmith [needs to refresh]

11:47 I also need to give Locksmith the

11:54 address for the

12:00 boot server. So here and then if I run

12:03 it back [then]

12:09 my Locksmith

12:12 can get in.

12:14 [Keanu checks and prepares]

12:53 So, I actually can't see it, but

12:59 usually if you look it up on the KERI

13:03 Foundation plugin, it should show that

13:05 you can service an AID and connect

13:10 witnesses and watchers to it.

13:12 – You could try deleting your local KERI

13:16 “home/.keri”

13:19 and then start fresh and then should

13:21 recreate on that.

13:22 Oh, I make a whole other repo?

13:25 I could…

13:26 – Yeah, go ahead.

13:27 I could do it at the end

13:28 probably. I just want to go through

13:31 the whole slide and maybe I'll do

13:33 another demo. But so let me finish the

13:36 slides first. Go to the witnesses, of

13:40 course you have the role of the witnesses

13:42 and what they do to anchor the events

13:44 and trying to keep the authenticity

13:49 and make sure that everything is correct

13:50 of course, because they're the witnesses.

13:54 So same thing, we're going to go through

13:55 the repo, the environment and

13:58 how to run it locally.

14:01 So first you can get the code on the

14:03 witness repository in the KERI

14:06 Foundation.

14:08 It also has docs. So I have the

14:12 developer guide. Same thing just make

14:15 sure that you have Libsodium.

14:18 How to set up your environment.

14:21 And then one thing about the

14:24 configuration:

14:26 If you were here last time Ryan (Hansen),

14:29 you talked about it and how it works. So

14:32 I'm not going to repeat it but

14:34 surely the curls here

14:38 will be the address that the witness

14:42 server is going to use.

14:46 To run the witnesses, you can

14:49 use the first one or I usually use the

14:52 other one. Let me

14:56 show it here.

15:02 So I have it here. Let me activate the ..,

15:27 You have my

15:28 witnesses running

15:31 and if you look at here you can

15:33 see the [private, red.] server address, I mean the

15:35 port which is 5631 ..,

15:38 Sorry, the private one which is

15:40 internal and then external which is the

15:42 public one at the 5632 port which is

15:46 the default one unless you change it in

15:49 the configuration and then you can see

15:52 your witnesses and their own AID.

15:57 Now to develop with witnesses

16:00 you have the API which is given and

16:03 shown in the readme file of the

16:05 repository for the witnesses, you have

16:08 different, of course, action POST

16:11 [action] DELETE but I'm going to go into the POST

16:15 and here basically we have the

16:19 the whole POST function it's a Falcon

16:22 app so it's in under the witness

16:25 collection class. And if you look at it

16:28 closely,

16:29 you can see that when it receive a post

16:33 method, it will first check for the AID,

16:36 check that it's a valid AID, and then it

16:38 just creates a witness,

16:41 gets the OOBIs and sends the data

16:43 back. That's all it does. So, if you

16:46 wanted, you could check for, I don't

16:49 know, check for more things. But if you

16:52 want to start developing witnesses and

16:54 changing maybe how they behave, this is

16:56 where you would go. This is just an

16:58 example of the 'on_post', but there's also

17:01 the 'on_delete'. There's also all the

17:04 the public

17:08 actions and API that you can change

17:11 which would also be under

17:14 under this. So it's in

17:17 ”src/witopnet/witnessing.py”. So if you want to

17:19 change anything go here.

17:25 Now the watchers,

17:28 same thing that we're going to go

17:30 through: public repo of the watchers in

17:33 the KERI Foundation [github repo].

17:35 This one doesn't have docs yet. I

17:38 suppose we might either add it later.

17:42 But that's from the readme.

17:46 I don't think we can install from Pypy

17:48 yet. Correct me if I'm wrong. Yeah, we

17:50 can't install it from PyPy yet. So, just

17:53 clone the repo and then install the

17:56 environment or hopefully from a

17:59 virtual environment.

18:01 Same thing for the

18:03 configuration. The curls is also the

18:06 address from which the watcher server is

18:09 going to respond.

18:10 [Keanu prepares]

18:54 But here you can see the same thing as

18:55 the witnesses. It shows your address,

18:58 public address for the watcher

19:01 server, private and also the watchers

19:04 running. I can probably show it

19:06 better on here.

19:11 You can see they have the watchers here

19:14 as well as their AIDs. You can

19:17 see that it's going up because the

19:19 witnesses are running. So, they're all

19:21 checking the witnesses.

19:28 A quick note that is important

19:31 is that the witnesses and watcher are

19:34 supposed to run together. They're not

19:36 supposed to be individually

19:39 running. They have to be together.

19:41 So, first would be the witnesses and

19:43 then the watchers have to be

19:45 deployed together.

19:48 Same thing for the watchers. You

19:50 have the same API and you can find the

19:54 functions for them in this file here.

19:58 I took the POST for the watchers that

20:01 provision the watcher.

20:03 So to finish: what we have is this

20:08 architecture technically that we have

20:10 the wallet that can make public API

20:12 requests but mostly if you want to just

20:15 have witnesses and watchers provisioning

20:18 it would be through a boot server that

20:20 then talks privately to witnesses and

20:24 watcher server in their own environment.

20:28 I think that's all I have. Unless

20:33 do you guys have any questions?

20:36 Yes.

20:37 – Thank you.

20:39 Given that KERI is a protocol and again

20:42 protocols not companies. So why

20:43 would you want to make changes to

20:45 witnesses or watchers? I thought that

20:47 was like common infrastructure or am I

20:50 wrong?

20:52 – Like for example in this?

20:56 – Yeah. – For example, you can add

20:58 some more checks or you can have… we

21:01 were talking about weight limiting

21:04 for example on how much a person

21:08 could provision witnesses. You could

21:10 limit it or you could expand it.

21:13 Also another thing that you

21:16 could note

21:18 for example for the plugin if I can

21:21 find it. I think it was here. Oh yeah.

21:24 So, for example, for the KERI

21:25 Foundation plugin, all it does right now

21:27 is just onboarding. So, it's pretty

21:29 simple. But if you really wanted to, you

21:31 can make your own plugin where you

21:33 include payment. So, people go through

21:35 the payment first and then it would

21:37 provision your witnesses and watchers.

21:39 – And your watchers can make sure the

21:41 money was transferred.

21:43 – Yeah. So, it could it could go through

21:44 the auth authorization for some account

21:47 account management and

21:50 approvement.

21:51 – Approval.

21:52 Approval. That's the word.

21:54 If you want, I think what

21:57 would be more interesting is probably

21:59 doing your own plug-in first because

22:01 that's when you could decouple that

22:04 from the witnesses and just handle

22:05 everything in your own plugin.

22:08 – One thing to note also that this

22:10 witness service that we're talking about

22:12 here doesn't necessarily, if you're

22:15 manipulating in that 'on_post' handler,

22:18 you're not necessarily manipulating how

22:20 the witness code itself works [inaudible]

22:24 you're just manipulating the

22:27 layer, basically the API layer of

22:29 [inaudible]

22:30 so you can expand…

22:31 – So you're really not modifying any other…

22:34 – Just adding extra functionality,

22:35 auxiliary functionality.

22:39 – Of course being open source if you

22:41 wanted to go in and manipulate the

22:43 witness protocol some way for your own

22:45 version, that's on your own.

22:51 If you look here for example…

22:55 This is all it does, just calls create

22:58 witness but then everything after, you

23:00 can probably

23:03 add more functionalities for yourself

23:05 for example for tracking or for like

23:08 stats if you wanted to but that's up to

23:11 you. So I'm just trying to give you an

23:13 example of where you would start and how

23:16 you could start.

23:17 – That “createWitness” method weaves down

23:20 into the KERIpy.

23:22 – Yeah.

23:27 – Great. Thank you.

23:29 – Yeah, no problem. If you don't have

23:31 any questions, then I think I'll give

23:33 you back 20 minutes.