Witnesses & Watchers - Ryan Hansen

KERICONF26 Day 1 · 40:30

0:00 Ryan Hansen | Witnesses & Watchers | KERI Conference 2026

0:02 All right.

0:04 How's everybody doing? My name's Ryan.

0:07 I'm one of the team, the KERI

0:10 Foundation development team. We're

0:12 all pretty new to this gig, so it's kind

0:15 of a fun little trial by fire to be up

0:17 in front of you talking about some of

0:18 these things that we're only

0:20 getting into ourselves.

0:24 I wanted to kind of take the temperature

0:26 of the room. Generally speaking, I know

0:28 we've got at least one person in the

0:30 back that wants to see specifically kind

0:32 of about deployment. How do we get

0:33 really started? We'll cover some of

0:35 that. What else do you guys want from

0:37 this particular session? Anything in

0:40 particular? Do you want or should we

0:42 just get into it and see where the

0:43 questions go?

0:45 Sounds good. All right. So, the

0:47 objectives here for this session,

0:51 we're going to do some overview of three

0:53 of the five W's. the witnesses,

0:55 watchers, and boot service isn't really

0:58 the one of the W's, but secondarily,

1:02 it's the web in general, deploying to

1:04 the web. Three of those five W's.

1:07 So, we'll talk about all of those things

1:09 a little bit. We'll do a

1:11 walkthrough, high-level walkthrough of a

1:14 deployment guide that I created that's

1:16 on the repo. When we get to that point,

1:18 There will be a link and a QR code

1:20 if you want to follow along. And

1:22 probably would be best to or easiest for

1:24 you if you want to see how it actually

1:26 works to pull that up in your own laptop

1:28 and just follow along. I'll just be kind

1:30 of taking high-level snapshot

1:32 overview of that. We're not going to

1:34 actually do the deployment here because

1:35 I've already done it. But when we're

1:37 done with all that, kind of walking

1:39 through what that those steps are, I'll

1:41 give you a quick view of the wallet

1:43 launching and then actually connecting

1:45 to some witnesses and provisioning

1:47 witnesses and stuff. We'll go

1:49 through that. So, here are the repos

1:53 we'll be dealing with. They're all under

1:54 the KERI Foundation GitHub account. So,

1:58 if you go to KERI Foundation, these are

1:59 the three that you're looking for that

2:01 we'll be talking about today. And just

2:03 for a I don't know that you're going to

2:05 follow along on your phones or whatever,

2:06 but that's the QR code to the

2:08 setup guide specifically, you can just

2:10 go to the KF boot repo itself, and

2:13 it's just right there on the at the top

2:15 level. You can click on it and pull it

2:17 up

2:19 to kind of follow along with that.

2:25 – A QR, but

2:26 – What's that?

2:26 – Doesn't show a QR, but

2:28 – Oh, sorry. I hadn't got that far yet.

2:31 Next step in .., my bad!

2:35 I've got my double view here and I

2:38 wasn't looking at the right one.

2:42 So, but we've got some new people coming

2:43 in. So, these are the repos we're going

2:45 to be dealing with in this particular

2:48 session today. For those who want to

2:50 just pull this stuff up, I would

2:52 recommend pulling up the setup guide and

2:55 just at least following along. I'm not

2:56 going to go through it like actually run

2:58 the code in this the setup guide because

3:00 I've already done it. So, but we are

3:02 going to go through it at high

3:04 level. So, it'll be easier for

3:06 you guys to see what's really going on

3:08 by taking a look at that and just

3:09 following along as we go through

3:11 it. And it's all broken out into steps.

3:13 So should be pretty easy to follow.

3:18 So everybody got that?

3:21 Okay, we'll go on to… I want to just… I

3:24 mean, I probably don't need to do this

3:26 with this group, but just to remind

3:29 everybody the core concepts of what

3:31 KERI's all about. First, it's about

3:33 keys. Above all, it's about keys.

3:37 And there's two different kinds of keys.

3:39 Who wants to answer? What kind of keys

3:40 are we talking about?

3:43 [inaudible] keys.

3:43 Public and private. Yes, but there's

3:45 two different kinds.

3:47 Signing and private.

3:48 Signing and…

3:50 – Rotation.

3:50 – Rotation. That's it. Signing and

3:53 rotation keys. So, those are the keys we

3:55 talk about when we're talking about

3:56 KERI. You got to remember that there's

3:58 those are different things. And

4:00 always just kind of remember that's

4:02 how it works. The next thing that's one

4:05 of these core concepts is Key Events

4:08 themselves. anything Events related to

4:10 those keys, those various different

4:12 kinds of keys. And within that sort of

4:15 context, there's a lot of ways we could

4:17 break it down, but I just for the sake

4:19 of this particular presentation, I

4:22 separated it into single and multi-

4:24 signature types of events.

4:28 And finally, the Key Event Log, the log

4:32 that keeps track of all the events.

4:35 Those things taken together are in

4:38 effect I mean it's probably

4:39 oversimplifying but in effect are the

4:42 canonical core of what KERI is all

4:44 about. Everything else is sort of in

4:46 support of this set of things.

4:50 So keep that in mind as we talk about

4:53 KERI ecosystem which this is a slide

4:55 from Sam's white paper as you guys saw

4:57 earlier today in Sam's presentation.

5:00 This describes what the different roles

5:02 of each of these different components

5:04 are.

5:05 So, the best place to go and get a real

5:07 deep understanding of that stuff is

5:10 Sam's white papers. And if you go to

5:13 (https://) keri.one, he's got links to the white

5:15 paper, and he's also got a link to his

5:16 slide deck, which is related to his

5:19 white paper. So, I definitely recommend

5:22 going and looking through that stuff,

5:24 too.

5:26 There's the three core

5:28 components we're going to talk about,

5:29 Keanu. Now, I'm getting back to where

5:31 your question you asked earlier.

5:33 Those three core components are and

5:35 we're sticking with the movie theme. For

5:37 those who missed it, my first slide was

5:38 a screenshot from a movie called

5:40 Witness.

5:42 So the first core concept or component

5:45 is a boot service.

5:50 Dumb movie jokes, right?

5:52 Second one, witness. We just talked

5:54 about that. And the third one, there it

5:56 is.

5:58 Watchers. Watcher in the Woods.

6:00 Keeping that movie theme alive.

6:03 So those are the kind of the core

6:06 components we're talking about here to

6:07 deploy this infrastructure that

6:11 HealthKERI has so generously donated

6:13 into the open-source world. Just in time.

6:17 Come on in.

6:21 You're going to want to .., probably if

6:23 you can kick that bag out of the

6:25 way and just toss on the ground or

6:26 whatever.

6:27 – Thank you.

6:29 – Yeah. So for a lot of what we're going

6:32 to do today, I'm going to do a high

6:33 level walkthrough of some deployment

6:35 stuff. So you'll want to go back. Let me

6:37 just back up and I'll show you.

6:41 So you can get to

6:44 So for those that are just coming in,

6:47 you'll want to go to this setup guide on

6:49 the KF boot

6:52 repo because I'm going

6:54 to do a high-level walkthrough of that.

6:56 That's very detailed, with commands and

6:58 everything, that you can use after this,

7:00 but we're going to kind of step through

7:01 it and I'll talk about it a little bit

7:04 Just so you guys can follow along.

7:07 And whether you want to do it live here,

7:11 probably won't have enough time for

7:12 that, but you can certainly walk through

7:14 the setup guide and actually do it

7:16 on any infrastructure you've got and it

7:18 should work for you great. So anyway,

7:20 let me get back to where I was. The

7:22 movie theme. Okay, a couple of quick

7:24 disclaimers. First of all, this is a

7:26 this guide is a very opinionated guide,

7:28 meaning that it's one way to

7:31 deploy this infrastructure.

7:34 As you get more familiar with

7:36 how this works, you can start to

7:38 recognize that there's a lot

7:41 of ways you could actually do this. So,

7:42 this one's going to pick one track and

7:45 be very opinionated about how to do it.

7:47 Doesn't mean that's the only way to do

7:49 it. So, keep that in mind. Second of

7:51 all, all these repos and all the

7:53 services that they run are Falcon apps,

7:55 which is just Python – HTTP; in the end. So

7:59 they're all Python processes. It's all

8:01 Python under the hood. So there nothing

8:04 really magic about that. It's all Python

8:06 stuff. It's all early work in progress

8:09 still as well. Well, I mean the

8:12 witness and watcher code is pretty

8:16 robust in terms of that's the stuff that

8:18 healthKERI open sourced, they're

8:21 using it in production.

8:23 So, it's pretty proven in that sense.

8:24 The boot service itself is a little

8:26 newer and we'll certainly go through

8:30 iteration and all of this stuff will

8:31 continue to grow and we'll iterate

8:33 on it as a team and as a community and

8:37 it will certainly get better and better.

8:39 So don't be too harsh in judgment of how

8:41 it is right now. It'll keep growing. And

8:45 finally, this is a demo-only version of

8:48 how to do this stuff, meaning it's

8:50 all going to be on one host.

8:53 We're going to do a multiple-witness

8:55 configuration on one host. Which is

8:58 not a production sort of deployment.

9:02 We would not say do that in production.

9:04 It doesn't really give you much help.

9:07 As an example of what a production

9:09 and deployment might look like, again

9:11 with an asterisk,

9:13 “ish”, productionish,

9:16 this is a high-level sort of idea of what it

9:19 might look like in production where

9:21 you've got your wallet, you've got these

9:23 providers that provide witness watcher

9:27 service, deployed on cloud

9:30 environments across the vertical lines

9:32 here or separations or maybe zones and

9:36 and, or sorry: regions, and then

9:39 availability zones or the

9:41 horizontals. So in theory anybody who's

9:45 providing these services including a

9:47 private data center of your own where

9:49 you deploy this kind of a situation

9:50 where it's distributed across multiple

9:52 zones and multiple regions and all

9:55 that kind of stuff is really the ideal

9:56 way to do that. And then from the wallet

9:58 side, the AIDs when it gets to that

10:01 point in the wallet, the plug-in could

10:04 provide multiple providers. You could

10:05 choose from either one provider that has

10:07 a good distribution into their cloud

10:09 environment or multiple cloud

10:10 environments or you could choose from

10:12 multiple different providers to

10:14 spread your witness surface out

10:17 as far as you can and have as much

10:20 availability and redundancy and all

10:22 that as possible. So that's the

10:24 kind of idea of how you would want to

10:26 deploy this in production at scale.

10:28 There's a lot of nuance and a lot of

10:30 different ways to do that, but that's

10:31 that's what it might look like. So with

10:34 all that preamble,

10:36 let's get into the actual setup guide

10:38 itself. So base requirements step, which

10:41 is step one of this setup guide. Our

10:45 opinion of this, in this guide, is we're

10:48 using Ubuntu 24.04.

10:50 So the latest LTS.

10:53 It does depend on Libsodium

10:57 one of the libraries that's underlying

11:00 KERIPy and KERI you know the KERI

11:03 code in general. Nginx for, in this

11:07 case, for TLS termination and reverse

11:11 proxying

11:12 and certbot, just to set up

11:17 certificates and stuff like that. So,

11:18 that's just the base guide setups.

11:29 (I forgot to mention that .. Oh, no, I did mention it. Never mind. Sorry.)

11:33 So, no real magic there. If

11:37 you're looking at the guide, it's

11:38 pretty straightforward to get

11:40 these things set up. If you have any

11:41 experience with infrastructure at all,

11:44 Any particular cloud provider,

11:46 whatever. Our we set ours up on Digital

11:48 Ocean. I did want… Yeah.

11:50 – Stupid question.

11:52 Do you throw that in a Docker container or?

11:54 No, I mean, you could. Don't

11:57 tell Sam though because he does

12:00 not like Docker for this kind of a

12:02 deployment for security reasons, which is…

12:05 – For development?

12:06 … valid. I mean, for development, sure,

12:07 you could. I run Docker locally.

12:10 And you could certainly put this all in

12:13 Docker and deploy it in that way and

12:15 into Kubernetes or any kind of

12:17 orchestration system, but Sam's

12:19 pretty adamant that there's

12:21 some major security concerns about that

12:23 approach. So, just be aware of that. So,

12:26 this is pretty much bare metal.

12:27 So, no production.

12:29 Yeah. According to Sam, he

12:31 would not do that. And so this guide

12:34 is bare metal. It's not really bare

12:36 metal because we're still in a cloud

12:38 environment and so it's not really bare

12:39 metal, but it's as close as it gets

12:41 these days unless you got your own data

12:42 center with your own hardware.

12:47 Any questions so far? Everybody good?

12:51 All right, step two.

12:53 Set up a service user that has we're

12:57 just going to call that user KERI.

13:00 And there's no login. We're, so the

13:02 service user, no login on this one. And

13:05 we're going to set up some

13:06 directory structure. The setup guide

13:09 goes in a little more detail about this,

13:11 but generally everything's under /opt/keri,

13:16 witness pool watcher and KF boot.

13:20 So there's some… the guide as you'll

13:23 see has a broader structure and it'll

13:25 give you the command to create all that

13:27 stuff. Just copy and paste and it'll

13:29 just work.

13:32 Oh. What time are we

13:33 ending this session again, Henk? 4:00.

13:38 Okay, I'll keep that. Keep in mind of

13:41 that.

13:41 – Five minutes to 4

13:43 – In five minutes [Ryan misheard, red.]. All

13:45 right. Quick. Next. We set up uv and

13:49 Python. This particular version of

13:52 Python 3.14.0

13:54 for this purpose. There's some

13:55 dependency there for that

13:58 particular version. So we just kind

14:01 of pinned to that and uv is the

14:03 easiest way to manage that dependency

14:05 these days. Anybody that's dealt with

14:07 Python much… uv is kind of the way to go.

14:12 Now we get into a little more of the

14:13 gut. That's just basic setup. Just to

14:15 get the environment in place. Now we get

14:18 into a little bit more of the guts of

14:19 this install. So the witness

14:25 The repo is called witness HK. That's

14:28 the healthKERI open- sourced version of

14:30 the witness infrastructure. The

14:33 witopnet is the name of the package that

14:36 will go into PyPy. It's not there yet. So

14:39 the install in the guide is just an

14:41 install straight from GitHub over

14:44 HTTP. So it's just a uv install from

14:48 straight from GitHub with the latest

14:50 version of the witness HK.

14:55 But shortly after, I'm sure sometime

14:57 shortly after this conference, we'll get

14:59 it all into PyPy and then you can install

15:01 it from… just with pip straight up. And

15:04 then of course the next one is the

15:07 watcher

15:08 Operational network or I don't know

15:10 what the op means exactly, but we'll say

15:13 that.

15:14 And then the boot service which acts

15:18 as kind of a control surface for the

15:21 witness and watcher provisioning and

15:24 deployment all… or not deployment but the

15:26 provisioning and communication

15:28 and stuff.

15:31 So.

15:33 anybody following along actually doing

15:35 it?

15:37 Nobody's actually installing it. I

15:39 wouldn't figure you would. But any

15:41 questions yet? We'll I'm kind of

15:43 going a little bit quick through this to

15:45 get to more of a demo and then we can

15:46 get to questions about anything related.

15:51 Okay, next part of the setup is just the

15:53 config. And there are various

15:56 different config files that we'll have

15:58 to set up to make this work. The witness

16:00 config is called witopnet.json. The

16:03 paths are all there on the setup guide

16:05 itself. In this particular instance, the

16:09 wallet will allow for a one-witness

16:11 configuration where, with your

16:13 AID, you're going to set up one witness

16:15 or if you've got your configuration set

16:17 up right on the server, it'll allow a

16:20 three of four, meaning that it'll the

16:22 threshold, it'll have four

16:24 witnesses available and it'll require

16:26 three of the four for it to be

16:28 considered fully witnessed. So by

16:32 doing this four times, four different

16:34 instances of the witness service, we're

16:37 kind of faking on one host being able to

16:40 have that three or four

16:41 configurations and test

16:44 it out without actually having to spread

16:47 that across multiple different servers

16:48 or data centers or whatever.

16:51 And that's what the configuration file

16:53 looks like. That curl is that

16:56 URL will be the base URL of what

17:01 the witness communicates back to the

17:04 wallet for OOBIs and things like that,

17:07 as we get into that point.

17:10 As the guide

17:14 describes, you'd have a different copy

17:16 of that with a different port for each

17:18 one of those. Whatever ports you want

17:20 really, but in our case, we did 5632,

17:24 5642, 52, and 62. Those are the ports

17:27 that we're running on our

17:29 infrastructure.

17:33 watopnet.json is the watcher config.

17:36 It's very similar pretty much the same

17:39 structure just slight differences in

17:41 naming and the different port. And in

17:44 theory you can .., I have not done this yet,

17:46 but in theory the design is such

17:48 that you can run a network of watchers

17:51 as well we won't talk about that in this

17:53 particular session because we I haven't

17:55 actually done it so we're not quite to

17:57 that point but you can do that.

18:01 And then next

18:03 we'll set up some launch

18:05 scripts for each of these services,

18:08 these are just shell scripts that invoke

18:11 the various different packages. Well, in

18:13 this case, it's just the witnesses with

18:14 the setups. Again, pay a special

18:16 attention to the HTTP and boot port.

18:20 Those will have to

18:23 coincide with what we put into the

18:25 previous config. Make sure that those

18:27 ports align.

18:29 And that will be used for the public and

18:32 the internal private communication ports

18:35 that it'll use.

18:38 The 5631 in this case is the

18:40 internal local loop-back communication

18:43 port that it uses.

18:48 And then the watopnet similar, watcher

18:50 network same thing. Same kind of

18:53 stuff. Set this up to your liking,

18:56 but for the most part that's

19:00 the pattern. So,

19:03 and then the boot script, the KF boot

19:06 boot service has a bunch of environment

19:07 variables that we have to set up to

19:10 make this system work, make it all

19:13 communicate well and keep track of

19:15 itself and all that stuff. The one that

19:16 we want to pay special attention to

19:18 in this particular thing, this

19:21 particular demo is the boot witness

19:25 backends. This is a string of multiple

19:28 witness IPs with the following

19:31 pattern: witness ID, internal IP and

19:35 port and external IP and port. As you

19:37 can see at the end of this string here,

19:39 it starts after the comment starts into

19:41 the next one. So, by doing that with the

19:45 the all four of those

19:48 configurations, that's basically what's

19:50 going to tell the wallet to allow a

19:53 three of four configuration because

19:55 we're telling it there's four different

19:56 witnesses to choose from. So, we've met

19:59 that requirement for the wallet to be

20:00 able to enable it.

20:02 – Those IDs are AIDs or?

20:04 – They're just arbitrary

20:06 witness IDs. You can call them whatever

20:07 you want. They're just an identifier

20:11 internally.

20:15 So they're actually like literal wit

20:18 wit one wit two, that's the literal

20:21 name or ID for this purpose.

20:28 And then next step is

20:32 Circus install. Now technically in the

20:35 guide I think the Circus install is at

20:37 like set step four or five and then the

20:40 Circus configuration is at step eight or

20:42 nine. For this presentation, I kind of

20:45 combined those. Circus install you can

20:47 do whenever you want and you know before

20:49 you configure it. And Circus, anybody

20:52 know what Circus is? Anybody? Okay. So

20:54 Circus is a process manager. So, it's

20:57 the thing that's going to actually

20:59 manage the launch and the state of the

21:02 Python processes themselves, the

21:05 witness and watcher and boot service

21:08 processes themselves. So, we're going to

21:11 put together a config file as it shows

21:13 in the guide there. And any

21:15 file that has all the run scripts for

21:17 all those different things and Circus is

21:19 going to manage all that. So all you

21:21 have to do is run one Circus command to

21:23 start them all up and you can get status

21:25 from it and all that stuff as opposed to

21:27 running them all independently.

21:30 And then along with Circus we're going

21:31 to set up 'systemd' unit

21:34 so that systemd can manage Circus so

21:36 that it boots on startup and you know

21:38 keeps the state and the logging of

21:40 the Circus process itself. So it's a

21:42 little bit two layers deep when it comes

21:44 to that.

21:46 So you can restart these services

21:48 either with Circus

21:50 Or at the global level

21:55 with systemd

21:57 and then finally

22:00 Nginx setup

22:03 to be able to… if you want to have TLS

22:06 termination… in our case we wanted

22:08 TLS for the initial communication so

22:12 that was all encrypted and then

22:17 subsequent communications all signed and

22:19 all that stuff anyway. So you don't

22:22 have to set up the TLS stuff, but we did

22:25 in our case.

22:28 And I've done this on two different

22:30 machines. I've done it on… KERI

22:31 Foundation is providing

22:33 the one I'll show. I also

22:36 have my own that I set it up on as

22:39 well that is fully TLS, all the

22:42 endpoints are encrypted,

22:44 running over TLS.

22:48 And that's pretty much the long and

22:51 short of the actual setup. So if you do

22:54 want to try this out, by all means, go

22:58 ahead and follow through that

23:00 setup guide. If you've got servers of

23:02 your own you want to try it

23:04 on. I mean, you're going to have to have

23:05 them, obviously, or a Docker container,

23:06 whatever. You can just follow along

23:08 through that. And it should get you

23:14 up to where you're ready to try it

23:16 out and see how it all goes. So, that's

23:19 pretty much it for the setup guide

23:23 itself. And there's a couple more steps

23:25 in the guide, but they're mostly, you

23:26 know, setting up the firewall.

23:28 That's because my slideshow's over.

23:52 You guys aren't going to see this yet, but…

24:03 Any questions so far?

24:07 Anybody have any…

24:14 – So, what is the boot doing exactly? It's

24:17 it's going to… it will create the [inaudible]

24:20 – It's basically the control

24:22 plan for the witness and watcher

24:26 network themselves. So when we

24:28 first launch the… I'll kind of walk you

24:31 through it. Let me… oops wrong thing.

24:36 Let me get my display in the right place…

24:43 There we go.

24:46 Let me open up the right project here.

25:06 In theory, I think I cleaned

25:09 myself off enough, my environment

25:12 off, that we're starting entirely fresh

25:14 with a new deployment. So we're

25:19 going to initialize a new vault. We'll

25:21 just call it 'test'.

25:24 I'll give it a

25:27 passcode.

25:35 … a new AID. So now I have the new AID.

25:37 Nothing special yet. Now all that does

25:40 is the local key, the local AID and in

25:46 the inception event in the KEL

25:49 locally. So I'm not talking to anybody

25:51 yet. It's just a local KEL, has an

25:53 inception event in it. You're not going

25:54 to see that here but that's where we are

25:56 at this point. And then from here I can

25:59 go into this KERI-Foundation

26:01 plugin. This is an adaptation of

26:04 what healthKERI provided for us. So Evan

26:07 did a bunch of good work to turn

26:10 this into something more useful for us.

26:13 Good job!

26:16 And for all you to use. So you can see

26:18 it's connected

26:20 to this particular host which is the

26:24 KERI Foundation host. I'm going to

26:27 choose

26:28 my AID and the profile that I want,

26:32 which in this case is “three of four”. And

26:35 then when I click this "begin onboarding"

26:37 to answer your question, Joseph, it's

26:39 going to hit that boot service to

26:41 basically make the introduction and

26:44 initialize the process of provisioning

26:47 witnesses, sending back the URLs for the

26:50 OOBIs and taking it through that whole

26:53 process of introducing the

26:57 witnesses, sending a rotation. Since

27:00 we've already done an inception, it's

27:01 going to do a rotation to rotate the

27:03 witnesses in based on what the boot

27:05 service is returning back from the

27:08 witness service. Does that make sense?

27:09 Ish.

27:11 Well enough. Get into the code, you'll

27:13 you'll get it.

27:17 So now fingers crossed. If I did

27:20 everything right, this is the big moment

27:22 of truth when I'm going to click a

27:24 button and hope it does something.

27:30 It's going to give me the beach ball…

27:37 for some reason. I've literally never

27:39 seen that.

27:50 Looks like it's trying to do something.

27:53 Oh, it failed.

28:42 Am I connected to the internet?

28:44 Make sure that all works.

28:48 The Wi-Fi here isn't super fast, so…

28:56 Yeah, we could try that.

29:06 So, you can see it's doing some stuff,

29:10 but it's bailing. I don't know what

29:12 that's about.

29:21 Oh, I might know what it is. Sorry.

29:25 I'm gonna kill my session there.

29:31 I was running in debug mode. I wonder if

29:33 that's just slowing it down too much.

29:50 There we go. Getting a little bit

29:52 better. Can see all the stuff that's

29:54 happening here.

29:58 Does take a minute for this to finish.

30:13 This is gripping…

30:15 watching this work, right? Everyone's on

30:18 pins and needles like, is it

30:20 gonna work?

30:24 Shazam.

30:26 – What made the difference?

30:28 – I was running in debug mode on my IDE,

30:32 which was just puts too much overhead

30:35 into the process. It was just too slow.

30:37 So, what I can do now with this

30:42 QR code

30:44 is I'm going to scan it into

30:47 I'll use Authy for this one. Any

30:49 authenticator app should work fine.

31:01 Okay, so now it's… I've got it in my

31:02 authenticator app and then I can go

31:06 back into the plugin

31:09 and this is just a demonstration but

31:11 I'll go to the credentials. I have

31:13 a schema that's a test schema that we

31:15 use for issuing credentials and I

31:18 will

31:21 … local ident… oh I got to upload

31:24 the schema first. Sorry.

31:36 Downloads I think.

31:40 So I'm adding this particular credential

31:42 schema. Going to use that for issuance.

31:44 – So is that's an ACDC?

31:48 – It's just a credential just a schema

31:50 for a credential. It's not necessarily

31:52 an A… or is it an ACDC?

31:54 That's a good question.

31:55 I think it's just a credential, but that

31:58 is a good question. I have to look at

32:00 it. It's just a test one that we've got.

32:04 And now I have to authenticate with my

32:07 authenticator.

32:16 And now I've issued a credential, which

32:18 is nothing more than a little test just

32:20 to show that it worked.

32:25 And there you go. That's a basic rundown

32:29 of setting up the wit… using the code

32:32 that healthKERI

32:34 has open sourced providing it to you

32:38 guys to all of us to start to build

32:42 on, deploy on, test with, all that kind of

32:44 stuff. We're we're fairly new to it,

32:46 ourselves on the KERI Foundation team.

32:48 So it's it's been a cool

32:51 exploration and a cool process. So,

32:54 Any questions…

32:56 any…

32:58 Anything else you want to know about

32:59 witnesses, watchers deployment, any

33:02 of that stuff?

33:05 Yeah.

33:05 – How is this whole infrastructure

33:07 different from what the packaging was three

33:11 months ago when we done doing the

33:13 hackathon?

33:14 packaging.

33:16 – Oh, I honestly don't know because I

33:18 don't know what was going on with the

33:19 hackathon.

33:20 This all this code came from

33:23 healthKERI. So, it could be the same

33:25 stuff to be honest,

33:26 but I don't know what the hackathon was

33:28 doing. So,

33:29 – I mean the witness

33:30 is from KERIPy.

33:33 There's a witness inside KERIPy

33:36 but that was added by Phil in the

33:38 early days. It's wasn't like, as you

33:42 said, production grade. So a separate

33:44 service because you know KERIPy is

33:46 just [inaudible] core.

33:47 Right. Yeah. So this is

33:50 a separate deployment a

33:53 whole separate project that is for

33:55 deploying a witness network

33:58 being able to put up a whole… so as I

34:00 went back to… in my earlier slides

34:03 in a production demo or a production

34:06 environment that variable that I was

34:08 showing you, that had all the different

34:10 configuration in it, that wouldn't be all

34:12 on the same host those would be pointing

34:14 to ..., the boot service itself

34:16 would probably run independently

34:18 pointing to various different endpoints

34:21 across cloud and whatever other

34:24 infrastructure you want. So…

34:27 – And you can run with a single

34:29 witness, but the wallet can't connect to

34:30 a single witness?

34:31 – It can. Yeah, actually that's one

34:33 of the options in here. I'd have to

34:36 create a new one to go back to it. So,

34:37 you can choose one witness and deploy it

34:40 that way if you want. The ultimate

34:43 KERI idea is that you want to have a

34:45 lot of witnesses, but if you want to

34:46 just run one, you can certainly do that.

34:48 And it works just the same way

34:50 it does here.

34:54 It did in the demo anyway. So, any other

34:57 questions?

35:00 Is this useful? Yeah.

35:01 – What does Circus add instead of just

35:03 using systemd? – Nothing really other

35:06 than it's just a nice little wrapper for

35:08 all the Python stuff, but you could do

35:10 it all with systemd for sure.

35:13 Handle it that way just as easily.

35:17 – Circus is just the Python native way of

35:19 doing systemd type stuff, right? Service

35:21 management…

35:22 – Kind of. Yeah, it's not service

35:23 management, process management really. I

35:25 guess it's service management. Yeah.

35:28 It's kind of scoped at the project

35:31 level. I mean, Circus gets installed

35:34 with the project as opposed to at the

35:37 system level. Generally, I guess you

35:39 could maybe do it that way if you wanted

35:40 to, but generally at least what I've

35:44 seen, Circus is usually kind of part of

35:47 it's a Python thing that gets installed

35:48 with your dependencies as opposed to

35:50 being part of the server infra or server

35:52 toolkit.

36:01 And now I would like to do some tap

36:03 dancing for you.

36:08 Is that good? Anybody questions? Is this

36:11 useful to you?

36:13 We want to see everybody get out

36:15 there and start trying to use it. Get

36:18 it deployed, give us feedback, make

36:21 suggestions, whatever. Like I

36:23 mentioned, this particular

36:27 infrastructure that I connected to is

36:28 the healthKERI… sorry is the KERI

36:31 Foundation

36:33 deployment of these services which

36:36 right now is for just demo purposes.

36:38 You're welcome to actually use it. I

36:40 guess I'll show you one .., I don't

36:42 remember if Jay covered this or I

36:45 might have missed it in his demo,

36:47 but as it is right now, when you launch…

36:55 the Locksmith code, there's a few

37:01 environment variables that you have to

37:03 set up so that it knows how to go and

37:06 discover the witnesses that are avail…

37:10 or the witness services that's available.

37:12 And those are right here that I

37:14 set up in my configuration for running

37:16 Locksmith locally.

37:19 So that's the host if you were going

37:22 to try to use this. That's the host you

37:25 would want to use, to use our

37:27 infrastructure. We'll put that out there

37:29 somewhere at some point publicly.

37:32 – That means that's part of where

37:34 the OOBI…

37:36 – Yeah. So the first phase of it

37:39 when you first create an AID and click

37:41 the button it's going to hit this URL

37:43 here for onboarding to make its kind of

37:46 initial introduction. It'll use a an

37:48 ephemeral AID to make the first

37:51 connection and say that it wants to

37:53 connect and then from then on it'll use

37:56 the account after it's set up what's

37:58 called basically an account

38:00 relationship.

38:01 It will use the account URL for

38:05 subsequent ...,

38:06 some of the subsequent calls, some of

38:08 them go straight to the witnesses, some

38:10 of them go through the boot service.

38:12 Yeah.

38:14 – A little tangential, but [inaudible] between the web

38:17 GitHub or the KERI Foundation GitHub

38:21 work?

38:22 – it's a thin… it's sort of a blurry

38:24 line at this point, but the KERI

38:26 Foundation one came along later because

38:28 the KERI Foundation itself came along

38:29 later. And probably

38:33 if I were to guess eventually KERIPy

38:35 will move into the KERI Foundation org

38:38 if it's worth the trouble of moving it.

38:40 Maybe not. They're both Sam's… that

38:44 created both of them. So the

38:47 distinction is more logical than

38:51 physical. You know, it's not much in

38:55 other words. We created these ones in

38:57 KERI Foundation just because now that

38:59 the foundation exists, we want to start

39:01 kind of centralizing some of this open

39:03 source stuff related to

39:05 KERI into that particular org.

39:11 Cool. I mean I have nothing further

39:12 unless you have any other questions?

39:21 All right. Thanks everyone.

39:22 [applause]