0:00 Ryan Hansen | Witnesses & Watchers | KERI Conference 2026
0:02 All right.
0:04 How's everybody doing? My name's Ryan.
0:07 I'm one of the team, the KERI
0:10 Foundation development team. We're
0:12 all pretty new to this gig, so it's kind
0:15 of a fun little trial by fire to be up
0:17 in front of you talking about some of
0:18 these things that we're only
0:20 getting into ourselves.
0:24 I wanted to kind of take the temperature
0:26 of the room. Generally speaking, I know
0:28 we've got at least one person in the
0:30 back that wants to see specifically kind
0:32 of about deployment. How do we get
0:33 really started? We'll cover some of
0:35 that. What else do you guys want from
0:37 this particular session? Anything in
0:40 particular? Do you want or should we
0:42 just get into it and see where the
0:43 questions go?
0:45 Sounds good. All right. So, the
0:47 objectives here for this session,
0:51 we're going to do some overview of three
0:53 of the five W's. the witnesses,
0:55 watchers, and boot service isn't really
0:58 the one of the W's, but secondarily,
1:02 it's the web in general, deploying to
1:04 the web. Three of those five W's.
1:07 So, we'll talk about all of those things
1:09 a little bit. We'll do a
1:11 walkthrough, high-level walkthrough of a
1:14 deployment guide that I created that's
1:16 on the repo. When we get to that point,
1:18 There will be a link and a QR code
1:20 if you want to follow along. And
1:22 probably would be best to or easiest for
1:24 you if you want to see how it actually
1:26 works to pull that up in your own laptop
1:28 and just follow along. I'll just be kind
1:30 of taking high-level snapshot
1:32 overview of that. We're not going to
1:34 actually do the deployment here because
1:35 I've already done it. But when we're
1:37 done with all that, kind of walking
1:39 through what that those steps are, I'll
1:41 give you a quick view of the wallet
1:43 launching and then actually connecting
1:45 to some witnesses and provisioning
1:47 witnesses and stuff. We'll go
1:49 through that. So, here are the repos
1:53 we'll be dealing with. They're all under
1:54 the KERI Foundation GitHub account. So,
1:58 if you go to KERI Foundation, these are
1:59 the three that you're looking for that
2:01 we'll be talking about today. And just
2:03 for a I don't know that you're going to
2:05 follow along on your phones or whatever,
2:06 but that's the QR code to the
2:08 setup guide specifically, you can just
2:10 go to the KF boot repo itself, and
2:13 it's just right there on the at the top
2:15 level. You can click on it and pull it
2:17 up
2:19 to kind of follow along with that.
2:25 – A QR, but
2:26 – What's that?
2:26 – Doesn't show a QR, but
2:28 – Oh, sorry. I hadn't got that far yet.
2:31 Next step in .., my bad!
2:35 I've got my double view here and I
2:38 wasn't looking at the right one.
2:42 So, but we've got some new people coming
2:43 in. So, these are the repos we're going
2:45 to be dealing with in this particular
2:48 session today. For those who want to
2:50 just pull this stuff up, I would
2:52 recommend pulling up the setup guide and
2:55 just at least following along. I'm not
2:56 going to go through it like actually run
2:58 the code in this the setup guide because
3:00 I've already done it. So, but we are
3:02 going to go through it at high
3:04 level. So, it'll be easier for
3:06 you guys to see what's really going on
3:08 by taking a look at that and just
3:09 following along as we go through
3:11 it. And it's all broken out into steps.
3:13 So should be pretty easy to follow.
3:18 So everybody got that?
3:21 Okay, we'll go on to… I want to just… I
3:24 mean, I probably don't need to do this
3:26 with this group, but just to remind
3:29 everybody the core concepts of what
3:31 KERI's all about. First, it's about
3:33 keys. Above all, it's about keys.
3:37 And there's two different kinds of keys.
3:39 Who wants to answer? What kind of keys
3:40 are we talking about?
3:43 [inaudible] keys.
3:43 Public and private. Yes, but there's
3:45 two different kinds.
3:47 Signing and private.
3:48 Signing and…
3:50 – Rotation.
3:50 – Rotation. That's it. Signing and
3:53 rotation keys. So, those are the keys we
3:55 talk about when we're talking about
3:56 KERI. You got to remember that there's
3:58 those are different things. And
4:00 always just kind of remember that's
4:02 how it works. The next thing that's one
4:05 of these core concepts is Key Events
4:08 themselves. anything Events related to
4:10 those keys, those various different
4:12 kinds of keys. And within that sort of
4:15 context, there's a lot of ways we could
4:17 break it down, but I just for the sake
4:19 of this particular presentation, I
4:22 separated it into single and multi-
4:24 signature types of events.
4:28 And finally, the Key Event Log, the log
4:32 that keeps track of all the events.
4:35 Those things taken together are in
4:38 effect I mean it's probably
4:39 oversimplifying but in effect are the
4:42 canonical core of what KERI is all
4:44 about. Everything else is sort of in
4:46 support of this set of things.
4:50 So keep that in mind as we talk about
4:53 KERI ecosystem which this is a slide
4:55 from Sam's white paper as you guys saw
4:57 earlier today in Sam's presentation.
5:00 This describes what the different roles
5:02 of each of these different components
5:04 are.
5:05 So, the best place to go and get a real
5:07 deep understanding of that stuff is
5:10 Sam's white papers. And if you go to
5:13 (https://) keri.one, he's got links to the white
5:15 paper, and he's also got a link to his
5:16 slide deck, which is related to his
5:19 white paper. So, I definitely recommend
5:22 going and looking through that stuff,
5:24 too.
5:26 There's the three core
5:28 components we're going to talk about,
5:29 Keanu. Now, I'm getting back to where
5:31 your question you asked earlier.
5:33 Those three core components are and
5:35 we're sticking with the movie theme. For
5:37 those who missed it, my first slide was
5:38 a screenshot from a movie called
5:40 Witness.
5:42 So the first core concept or component
5:45 is a boot service.
5:50 Dumb movie jokes, right?
5:52 Second one, witness. We just talked
5:54 about that. And the third one, there it
5:56 is.
5:58 Watchers. Watcher in the Woods.
6:00 Keeping that movie theme alive.
6:03 So those are the kind of the core
6:06 components we're talking about here to
6:07 deploy this infrastructure that
6:11 HealthKERI has so generously donated
6:13 into the open-source world. Just in time.
6:17 Come on in.
6:21 You're going to want to .., probably if
6:23 you can kick that bag out of the
6:25 way and just toss on the ground or
6:26 whatever.
6:27 – Thank you.
6:29 – Yeah. So for a lot of what we're going
6:32 to do today, I'm going to do a high
6:33 level walkthrough of some deployment
6:35 stuff. So you'll want to go back. Let me
6:37 just back up and I'll show you.
6:41 So you can get to
6:44 So for those that are just coming in,
6:47 you'll want to go to this setup guide on
6:49 the KF boot
6:52 repo because I'm going
6:54 to do a high-level walkthrough of that.
6:56 That's very detailed, with commands and
6:58 everything, that you can use after this,
7:00 but we're going to kind of step through
7:01 it and I'll talk about it a little bit
7:04 Just so you guys can follow along.
7:07 And whether you want to do it live here,
7:11 probably won't have enough time for
7:12 that, but you can certainly walk through
7:14 the setup guide and actually do it
7:16 on any infrastructure you've got and it
7:18 should work for you great. So anyway,
7:20 let me get back to where I was. The
7:22 movie theme. Okay, a couple of quick
7:24 disclaimers. First of all, this is a
7:26 this guide is a very opinionated guide,
7:28 meaning that it's one way to
7:31 deploy this infrastructure.
7:34 As you get more familiar with
7:36 how this works, you can start to
7:38 recognize that there's a lot
7:41 of ways you could actually do this. So,
7:42 this one's going to pick one track and
7:45 be very opinionated about how to do it.
7:47 Doesn't mean that's the only way to do
7:49 it. So, keep that in mind. Second of
7:51 all, all these repos and all the
7:53 services that they run are Falcon apps,
7:55 which is just Python – HTTP; in the end. So
7:59 they're all Python processes. It's all
8:01 Python under the hood. So there nothing
8:04 really magic about that. It's all Python
8:06 stuff. It's all early work in progress
8:09 still as well. Well, I mean the
8:12 witness and watcher code is pretty
8:16 robust in terms of that's the stuff that
8:18 healthKERI open sourced, they're
8:21 using it in production.
8:23 So, it's pretty proven in that sense.
8:24 The boot service itself is a little
8:26 newer and we'll certainly go through
8:30 iteration and all of this stuff will
8:31 continue to grow and we'll iterate
8:33 on it as a team and as a community and
8:37 it will certainly get better and better.
8:39 So don't be too harsh in judgment of how
8:41 it is right now. It'll keep growing. And
8:45 finally, this is a demo-only version of
8:48 how to do this stuff, meaning it's
8:50 all going to be on one host.
8:53 We're going to do a multiple-witness
8:55 configuration on one host. Which is
8:58 not a production sort of deployment.
9:02 We would not say do that in production.
9:04 It doesn't really give you much help.
9:07 As an example of what a production
9:09 and deployment might look like, again
9:11 with an asterisk,
9:13 “ish”, productionish,
9:16 this is a high-level sort of idea of what it
9:19 might look like in production where
9:21 you've got your wallet, you've got these
9:23 providers that provide witness watcher
9:27 service, deployed on cloud
9:30 environments across the vertical lines
9:32 here or separations or maybe zones and
9:36 and, or sorry: regions, and then
9:39 availability zones or the
9:41 horizontals. So in theory anybody who's
9:45 providing these services including a
9:47 private data center of your own where
9:49 you deploy this kind of a situation
9:50 where it's distributed across multiple
9:52 zones and multiple regions and all
9:55 that kind of stuff is really the ideal
9:56 way to do that. And then from the wallet
9:58 side, the AIDs when it gets to that
10:01 point in the wallet, the plug-in could
10:04 provide multiple providers. You could
10:05 choose from either one provider that has
10:07 a good distribution into their cloud
10:09 environment or multiple cloud
10:10 environments or you could choose from
10:12 multiple different providers to
10:14 spread your witness surface out
10:17 as far as you can and have as much
10:20 availability and redundancy and all
10:22 that as possible. So that's the
10:24 kind of idea of how you would want to
10:26 deploy this in production at scale.
10:28 There's a lot of nuance and a lot of
10:30 different ways to do that, but that's
10:31 that's what it might look like. So with
10:34 all that preamble,
10:36 let's get into the actual setup guide
10:38 itself. So base requirements step, which
10:41 is step one of this setup guide. Our
10:45 opinion of this, in this guide, is we're
10:48 using Ubuntu 24.04.
10:50 So the latest LTS.
10:53 It does depend on Libsodium
10:57 one of the libraries that's underlying
11:00 KERIPy and KERI you know the KERI
11:03 code in general. Nginx for, in this
11:07 case, for TLS termination and reverse
11:11 proxying
11:12 and certbot, just to set up
11:17 certificates and stuff like that. So,
11:18 that's just the base guide setups.
11:29 (I forgot to mention that .. Oh, no, I did mention it. Never mind. Sorry.)
11:33 So, no real magic there. If
11:37 you're looking at the guide, it's
11:38 pretty straightforward to get
11:40 these things set up. If you have any
11:41 experience with infrastructure at all,
11:44 Any particular cloud provider,
11:46 whatever. Our we set ours up on Digital
11:48 Ocean. I did want… Yeah.
11:50 – Stupid question.
11:52 Do you throw that in a Docker container or?
11:54 No, I mean, you could. Don't
11:57 tell Sam though because he does
12:00 not like Docker for this kind of a
12:02 deployment for security reasons, which is…
12:05 – For development?
12:06 … valid. I mean, for development, sure,
12:07 you could. I run Docker locally.
12:10 And you could certainly put this all in
12:13 Docker and deploy it in that way and
12:15 into Kubernetes or any kind of
12:17 orchestration system, but Sam's
12:19 pretty adamant that there's
12:21 some major security concerns about that
12:23 approach. So, just be aware of that. So,
12:26 this is pretty much bare metal.
12:27 So, no production.
12:29 Yeah. According to Sam, he
12:31 would not do that. And so this guide
12:34 is bare metal. It's not really bare
12:36 metal because we're still in a cloud
12:38 environment and so it's not really bare
12:39 metal, but it's as close as it gets
12:41 these days unless you got your own data
12:42 center with your own hardware.
12:47 Any questions so far? Everybody good?
12:51 All right, step two.
12:53 Set up a service user that has we're
12:57 just going to call that user KERI.
13:00 And there's no login. We're, so the
13:02 service user, no login on this one. And
13:05 we're going to set up some
13:06 directory structure. The setup guide
13:09 goes in a little more detail about this,
13:11 but generally everything's under /opt/keri,
13:16 witness pool watcher and KF boot.
13:20 So there's some… the guide as you'll
13:23 see has a broader structure and it'll
13:25 give you the command to create all that
13:27 stuff. Just copy and paste and it'll
13:29 just work.
13:32 Oh. What time are we
13:33 ending this session again, Henk? 4:00.
13:38 Okay, I'll keep that. Keep in mind of
13:41 that.
13:41 – Five minutes to 4
13:43 – In five minutes [Ryan misheard, red.]. All
13:45 right. Quick. Next. We set up uv and
13:49 Python. This particular version of
13:52 Python 3.14.0
13:54 for this purpose. There's some
13:55 dependency there for that
13:58 particular version. So we just kind
14:01 of pinned to that and uv is the
14:03 easiest way to manage that dependency
14:05 these days. Anybody that's dealt with
14:07 Python much… uv is kind of the way to go.
14:12 Now we get into a little more of the
14:13 gut. That's just basic setup. Just to
14:15 get the environment in place. Now we get
14:18 into a little bit more of the guts of
14:19 this install. So the witness
14:25 The repo is called witness HK. That's
14:28 the healthKERI open- sourced version of
14:30 the witness infrastructure. The
14:33 witopnet is the name of the package that
14:36 will go into PyPy. It's not there yet. So
14:39 the install in the guide is just an
14:41 install straight from GitHub over
14:44 HTTP. So it's just a uv install from
14:48 straight from GitHub with the latest
14:50 version of the witness HK.
14:55 But shortly after, I'm sure sometime
14:57 shortly after this conference, we'll get
14:59 it all into PyPy and then you can install
15:01 it from… just with pip straight up. And
15:04 then of course the next one is the
15:07 watcher
15:08 Operational network or I don't know
15:10 what the op means exactly, but we'll say
15:13 that.
15:14 And then the boot service which acts
15:18 as kind of a control surface for the
15:21 witness and watcher provisioning and
15:24 deployment all… or not deployment but the
15:26 provisioning and communication
15:28 and stuff.
15:31 So.
15:33 anybody following along actually doing
15:35 it?
15:37 Nobody's actually installing it. I
15:39 wouldn't figure you would. But any
15:41 questions yet? We'll I'm kind of
15:43 going a little bit quick through this to
15:45 get to more of a demo and then we can
15:46 get to questions about anything related.
15:51 Okay, next part of the setup is just the
15:53 config. And there are various
15:56 different config files that we'll have
15:58 to set up to make this work. The witness
16:00 config is called witopnet.json. The
16:03 paths are all there on the setup guide
16:05 itself. In this particular instance, the
16:09 wallet will allow for a one-witness
16:11 configuration where, with your
16:13 AID, you're going to set up one witness
16:15 or if you've got your configuration set
16:17 up right on the server, it'll allow a
16:20 three of four, meaning that it'll the
16:22 threshold, it'll have four
16:24 witnesses available and it'll require
16:26 three of the four for it to be
16:28 considered fully witnessed. So by
16:32 doing this four times, four different
16:34 instances of the witness service, we're
16:37 kind of faking on one host being able to
16:40 have that three or four
16:41 configurations and test
16:44 it out without actually having to spread
16:47 that across multiple different servers
16:48 or data centers or whatever.
16:51 And that's what the configuration file
16:53 looks like. That curl is that
16:56 URL will be the base URL of what
17:01 the witness communicates back to the
17:04 wallet for OOBIs and things like that,
17:07 as we get into that point.
17:10 As the guide
17:14 describes, you'd have a different copy
17:16 of that with a different port for each
17:18 one of those. Whatever ports you want
17:20 really, but in our case, we did 5632,
17:24 5642, 52, and 62. Those are the ports
17:27 that we're running on our
17:29 infrastructure.
17:33 watopnet.json is the watcher config.
17:36 It's very similar pretty much the same
17:39 structure just slight differences in
17:41 naming and the different port. And in
17:44 theory you can .., I have not done this yet,
17:46 but in theory the design is such
17:48 that you can run a network of watchers
17:51 as well we won't talk about that in this
17:53 particular session because we I haven't
17:55 actually done it so we're not quite to
17:57 that point but you can do that.
18:01 And then next
18:03 we'll set up some launch
18:05 scripts for each of these services,
18:08 these are just shell scripts that invoke
18:11 the various different packages. Well, in
18:13 this case, it's just the witnesses with
18:14 the setups. Again, pay a special
18:16 attention to the HTTP and boot port.
18:20 Those will have to
18:23 coincide with what we put into the
18:25 previous config. Make sure that those
18:27 ports align.
18:29 And that will be used for the public and
18:32 the internal private communication ports
18:35 that it'll use.
18:38 The 5631 in this case is the
18:40 internal local loop-back communication
18:43 port that it uses.
18:48 And then the watopnet similar, watcher
18:50 network same thing. Same kind of
18:53 stuff. Set this up to your liking,
18:56 but for the most part that's
19:00 the pattern. So,
19:03 and then the boot script, the KF boot
19:06 boot service has a bunch of environment
19:07 variables that we have to set up to
19:10 make this system work, make it all
19:13 communicate well and keep track of
19:15 itself and all that stuff. The one that
19:16 we want to pay special attention to
19:18 in this particular thing, this
19:21 particular demo is the boot witness
19:25 backends. This is a string of multiple
19:28 witness IPs with the following
19:31 pattern: witness ID, internal IP and
19:35 port and external IP and port. As you
19:37 can see at the end of this string here,
19:39 it starts after the comment starts into
19:41 the next one. So, by doing that with the
19:45 the all four of those
19:48 configurations, that's basically what's
19:50 going to tell the wallet to allow a
19:53 three of four configuration because
19:55 we're telling it there's four different
19:56 witnesses to choose from. So, we've met
19:59 that requirement for the wallet to be
20:00 able to enable it.
20:02 – Those IDs are AIDs or?
20:04 – They're just arbitrary
20:06 witness IDs. You can call them whatever
20:07 you want. They're just an identifier
20:11 internally.
20:15 So they're actually like literal wit
20:18 wit one wit two, that's the literal
20:21 name or ID for this purpose.
20:28 And then next step is
20:32 Circus install. Now technically in the
20:35 guide I think the Circus install is at
20:37 like set step four or five and then the
20:40 Circus configuration is at step eight or
20:42 nine. For this presentation, I kind of
20:45 combined those. Circus install you can
20:47 do whenever you want and you know before
20:49 you configure it. And Circus, anybody
20:52 know what Circus is? Anybody? Okay. So
20:54 Circus is a process manager. So, it's
20:57 the thing that's going to actually
20:59 manage the launch and the state of the
21:02 Python processes themselves, the
21:05 witness and watcher and boot service
21:08 processes themselves. So, we're going to
21:11 put together a config file as it shows
21:13 in the guide there. And any
21:15 file that has all the run scripts for
21:17 all those different things and Circus is
21:19 going to manage all that. So all you
21:21 have to do is run one Circus command to
21:23 start them all up and you can get status
21:25 from it and all that stuff as opposed to
21:27 running them all independently.
21:30 And then along with Circus we're going
21:31 to set up 'systemd' unit
21:34 so that systemd can manage Circus so
21:36 that it boots on startup and you know
21:38 keeps the state and the logging of
21:40 the Circus process itself. So it's a
21:42 little bit two layers deep when it comes
21:44 to that.
21:46 So you can restart these services
21:48 either with Circus
21:50 Or at the global level
21:55 with systemd
21:57 and then finally
22:00 Nginx setup
22:03 to be able to… if you want to have TLS
22:06 termination… in our case we wanted
22:08 TLS for the initial communication so
22:12 that was all encrypted and then
22:17 subsequent communications all signed and
22:19 all that stuff anyway. So you don't
22:22 have to set up the TLS stuff, but we did
22:25 in our case.
22:28 And I've done this on two different
22:30 machines. I've done it on… KERI
22:31 Foundation is providing
22:33 the one I'll show. I also
22:36 have my own that I set it up on as
22:39 well that is fully TLS, all the
22:42 endpoints are encrypted,
22:44 running over TLS.
22:48 And that's pretty much the long and
22:51 short of the actual setup. So if you do
22:54 want to try this out, by all means, go
22:58 ahead and follow through that
23:00 setup guide. If you've got servers of
23:02 your own you want to try it
23:04 on. I mean, you're going to have to have
23:05 them, obviously, or a Docker container,
23:06 whatever. You can just follow along
23:08 through that. And it should get you
23:14 up to where you're ready to try it
23:16 out and see how it all goes. So, that's
23:19 pretty much it for the setup guide
23:23 itself. And there's a couple more steps
23:25 in the guide, but they're mostly, you
23:26 know, setting up the firewall.
23:28 That's because my slideshow's over.
23:52 You guys aren't going to see this yet, but…
24:03 Any questions so far?
24:07 Anybody have any…
24:14 – So, what is the boot doing exactly? It's
24:17 it's going to… it will create the [inaudible]
24:20 – It's basically the control
24:22 plan for the witness and watcher
24:26 network themselves. So when we
24:28 first launch the… I'll kind of walk you
24:31 through it. Let me… oops wrong thing.
24:36 Let me get my display in the right place…
24:43 There we go.
24:46 Let me open up the right project here.
25:06 In theory, I think I cleaned
25:09 myself off enough, my environment
25:12 off, that we're starting entirely fresh
25:14 with a new deployment. So we're
25:19 going to initialize a new vault. We'll
25:21 just call it 'test'.
25:24 I'll give it a
25:27 passcode.
25:35 … a new AID. So now I have the new AID.
25:37 Nothing special yet. Now all that does
25:40 is the local key, the local AID and in
25:46 the inception event in the KEL
25:49 locally. So I'm not talking to anybody
25:51 yet. It's just a local KEL, has an
25:53 inception event in it. You're not going
25:54 to see that here but that's where we are
25:56 at this point. And then from here I can
25:59 go into this KERI-Foundation
26:01 plugin. This is an adaptation of
26:04 what healthKERI provided for us. So Evan
26:07 did a bunch of good work to turn
26:10 this into something more useful for us.
26:13 Good job!
26:16 And for all you to use. So you can see
26:18 it's connected
26:20 to this particular host which is the
26:24 KERI Foundation host. I'm going to
26:27 choose
26:28 my AID and the profile that I want,
26:32 which in this case is “three of four”. And
26:35 then when I click this "begin onboarding"
26:37 to answer your question, Joseph, it's
26:39 going to hit that boot service to
26:41 basically make the introduction and
26:44 initialize the process of provisioning
26:47 witnesses, sending back the URLs for the
26:50 OOBIs and taking it through that whole
26:53 process of introducing the
26:57 witnesses, sending a rotation. Since
27:00 we've already done an inception, it's
27:01 going to do a rotation to rotate the
27:03 witnesses in based on what the boot
27:05 service is returning back from the
27:08 witness service. Does that make sense?
27:09 Ish.
27:11 Well enough. Get into the code, you'll
27:13 you'll get it.
27:17 So now fingers crossed. If I did
27:20 everything right, this is the big moment
27:22 of truth when I'm going to click a
27:24 button and hope it does something.
27:30 It's going to give me the beach ball…
27:37 for some reason. I've literally never
27:39 seen that.
27:50 Looks like it's trying to do something.
27:53 Oh, it failed.
28:42 Am I connected to the internet?
28:44 Make sure that all works.
28:48 The Wi-Fi here isn't super fast, so…
28:56 Yeah, we could try that.
29:06 So, you can see it's doing some stuff,
29:10 but it's bailing. I don't know what
29:12 that's about.
29:21 Oh, I might know what it is. Sorry.
29:25 I'm gonna kill my session there.
29:31 I was running in debug mode. I wonder if
29:33 that's just slowing it down too much.
29:50 There we go. Getting a little bit
29:52 better. Can see all the stuff that's
29:54 happening here.
29:58 Does take a minute for this to finish.
30:13 This is gripping…
30:15 watching this work, right? Everyone's on
30:18 pins and needles like, is it
30:20 gonna work?
30:24 Shazam.
30:26 – What made the difference?
30:28 – I was running in debug mode on my IDE,
30:32 which was just puts too much overhead
30:35 into the process. It was just too slow.
30:37 So, what I can do now with this
30:42 QR code
30:44 is I'm going to scan it into
30:47 I'll use Authy for this one. Any
30:49 authenticator app should work fine.
31:01 Okay, so now it's… I've got it in my
31:02 authenticator app and then I can go
31:06 back into the plugin
31:09 and this is just a demonstration but
31:11 I'll go to the credentials. I have
31:13 a schema that's a test schema that we
31:15 use for issuing credentials and I
31:18 will
31:21 … local ident… oh I got to upload
31:24 the schema first. Sorry.
31:36 Downloads I think.
31:40 So I'm adding this particular credential
31:42 schema. Going to use that for issuance.
31:44 – So is that's an ACDC?
31:48 – It's just a credential just a schema
31:50 for a credential. It's not necessarily
31:52 an A… or is it an ACDC?
31:54 That's a good question.
31:55 I think it's just a credential, but that
31:58 is a good question. I have to look at
32:00 it. It's just a test one that we've got.
32:04 And now I have to authenticate with my
32:07 authenticator.
32:16 And now I've issued a credential, which
32:18 is nothing more than a little test just
32:20 to show that it worked.
32:25 And there you go. That's a basic rundown
32:29 of setting up the wit… using the code
32:32 that healthKERI
32:34 has open sourced providing it to you
32:38 guys to all of us to start to build
32:42 on, deploy on, test with, all that kind of
32:44 stuff. We're we're fairly new to it,
32:46 ourselves on the KERI Foundation team.
32:48 So it's it's been a cool
32:51 exploration and a cool process. So,
32:54 Any questions…
32:56 any…
32:58 Anything else you want to know about
32:59 witnesses, watchers deployment, any
33:02 of that stuff?
33:05 Yeah.
33:05 – How is this whole infrastructure
33:07 different from what the packaging was three
33:11 months ago when we done doing the
33:13 hackathon?
33:14 packaging.
33:16 – Oh, I honestly don't know because I
33:18 don't know what was going on with the
33:19 hackathon.
33:20 This all this code came from
33:23 healthKERI. So, it could be the same
33:25 stuff to be honest,
33:26 but I don't know what the hackathon was
33:28 doing. So,
33:29 – I mean the witness
33:30 is from KERIPy.
33:33 There's a witness inside KERIPy
33:36 but that was added by Phil in the
33:38 early days. It's wasn't like, as you
33:42 said, production grade. So a separate
33:44 service because you know KERIPy is
33:46 just [inaudible] core.
33:47 Right. Yeah. So this is
33:50 a separate deployment a
33:53 whole separate project that is for
33:55 deploying a witness network
33:58 being able to put up a whole… so as I
34:00 went back to… in my earlier slides
34:03 in a production demo or a production
34:06 environment that variable that I was
34:08 showing you, that had all the different
34:10 configuration in it, that wouldn't be all
34:12 on the same host those would be pointing
34:14 to ..., the boot service itself
34:16 would probably run independently
34:18 pointing to various different endpoints
34:21 across cloud and whatever other
34:24 infrastructure you want. So…
34:27 – And you can run with a single
34:29 witness, but the wallet can't connect to
34:30 a single witness?
34:31 – It can. Yeah, actually that's one
34:33 of the options in here. I'd have to
34:36 create a new one to go back to it. So,
34:37 you can choose one witness and deploy it
34:40 that way if you want. The ultimate
34:43 KERI idea is that you want to have a
34:45 lot of witnesses, but if you want to
34:46 just run one, you can certainly do that.
34:48 And it works just the same way
34:50 it does here.
34:54 It did in the demo anyway. So, any other
34:57 questions?
35:00 Is this useful? Yeah.
35:01 – What does Circus add instead of just
35:03 using systemd? – Nothing really other
35:06 than it's just a nice little wrapper for
35:08 all the Python stuff, but you could do
35:10 it all with systemd for sure.
35:13 Handle it that way just as easily.
35:17 – Circus is just the Python native way of
35:19 doing systemd type stuff, right? Service
35:21 management…
35:22 – Kind of. Yeah, it's not service
35:23 management, process management really. I
35:25 guess it's service management. Yeah.
35:28 It's kind of scoped at the project
35:31 level. I mean, Circus gets installed
35:34 with the project as opposed to at the
35:37 system level. Generally, I guess you
35:39 could maybe do it that way if you wanted
35:40 to, but generally at least what I've
35:44 seen, Circus is usually kind of part of
35:47 it's a Python thing that gets installed
35:48 with your dependencies as opposed to
35:50 being part of the server infra or server
35:52 toolkit.
36:01 And now I would like to do some tap
36:03 dancing for you.
36:08 Is that good? Anybody questions? Is this
36:11 useful to you?
36:13 We want to see everybody get out
36:15 there and start trying to use it. Get
36:18 it deployed, give us feedback, make
36:21 suggestions, whatever. Like I
36:23 mentioned, this particular
36:27 infrastructure that I connected to is
36:28 the healthKERI… sorry is the KERI
36:31 Foundation
36:33 deployment of these services which
36:36 right now is for just demo purposes.
36:38 You're welcome to actually use it. I
36:40 guess I'll show you one .., I don't
36:42 remember if Jay covered this or I
36:45 might have missed it in his demo,
36:47 but as it is right now, when you launch…
36:55 the Locksmith code, there's a few
37:01 environment variables that you have to
37:03 set up so that it knows how to go and
37:06 discover the witnesses that are avail…
37:10 or the witness services that's available.
37:12 And those are right here that I
37:14 set up in my configuration for running
37:16 Locksmith locally.
37:19 So that's the host if you were going
37:22 to try to use this. That's the host you
37:25 would want to use, to use our
37:27 infrastructure. We'll put that out there
37:29 somewhere at some point publicly.
37:32 – That means that's part of where
37:34 the OOBI…
37:36 – Yeah. So the first phase of it
37:39 when you first create an AID and click
37:41 the button it's going to hit this URL
37:43 here for onboarding to make its kind of
37:46 initial introduction. It'll use a an
37:48 ephemeral AID to make the first
37:51 connection and say that it wants to
37:53 connect and then from then on it'll use
37:56 the account after it's set up what's
37:58 called basically an account
38:00 relationship.
38:01 It will use the account URL for
38:05 subsequent ...,
38:06 some of the subsequent calls, some of
38:08 them go straight to the witnesses, some
38:10 of them go through the boot service.
38:12 Yeah.
38:14 – A little tangential, but [inaudible] between the web
38:17 GitHub or the KERI Foundation GitHub
38:21 work?
38:22 – it's a thin… it's sort of a blurry
38:24 line at this point, but the KERI
38:26 Foundation one came along later because
38:28 the KERI Foundation itself came along
38:29 later. And probably
38:33 if I were to guess eventually KERIPy
38:35 will move into the KERI Foundation org
38:38 if it's worth the trouble of moving it.
38:40 Maybe not. They're both Sam's… that
38:44 created both of them. So the
38:47 distinction is more logical than
38:51 physical. You know, it's not much in
38:55 other words. We created these ones in
38:57 KERI Foundation just because now that
38:59 the foundation exists, we want to start
39:01 kind of centralizing some of this open
39:03 source stuff related to
39:05 KERI into that particular org.
39:11 Cool. I mean I have nothing further
39:12 unless you have any other questions?
39:21 All right. Thanks everyone.
39:22 [applause]