准备环境
- 安装 docker
- 安装 docker-compose
- 安装 go
- 下载 Hyperledger Fabric 的二进制文件和docker镜像
curl -sSL https://goo.gl/6wtTN5 | bash -s 1.1.0
创建项目目录
mkdir -p fabric_test/test01
生成认证文件
新建文件 crypto-config.yaml
OrdererOrgs:
- Name: Orderer
Domain: acme.com
Specs:
- Hostname: orderer
PeerOrgs:
- Name: Org1
Domain: org1.acme.com
Template:
Count: 1
Users:
Count: 1
- Name: Org2
Domain: org2.acme.com
Template:
Count: 1
Users:
Count: 1
- Name: Org3
Domain: org3.acme.com
Template:
Count: 1
Users:
Count: 1
生成认证文件命令
cryptogen generate --config=./crypto-config.yaml
生成创始块
新建文件 configtx.yaml
---
Profiles:
ThreeOrgsOrdererGenesis:
Orderer:
<<: *OrdererDefaults
Organizations:
- *OrdererOrg
Consortiums:
SampleConsortium:
Organizations:
- *Org1
- *Org2
- *Org3
ThreeOrgsChannel:
Consortium: SampleConsortium
Application:
<<: *ApplicationDefaults
Organizations:
- *Org1
- *Org2
- *Org3
Organizations:
- &OrdererOrg
Name: OrdererOrg
ID: OrdererMSP
MSPDir: crypto-config/ordererOrganizations/acme.com/msp
- &Org1
Name: Org1MSP
ID: Org1MSP
MSPDir: crypto-config/peerOrganizations/org1.acme.com/msp
AnchorPeers:
- Host: peer0.org1.acme.com
Port: 7051
- &Org2
Name: Org2MSP
ID: Org2MSP
MSPDir: crypto-config/peerOrganizations/org2.acme.com/msp
AnchorPeers:
- Host: peer0.org2.acme.com
Port: 7051
- &Org3
Name: Org3MSP
ID: Org3MSP
MSPDir: crypto-config/peerOrganizations/org3.acme.com/msp
AnchorPeers:
- Host: peer0.org3.acme.com
Port: 7051
Orderer: &OrdererDefaults
OrdererType: solo
Addresses:
- orderer.acme.com:7050
BatchTimeout: 2s
BatchSize:
MaxMessageCount: 10
AbsoluteMaxBytes: 99 MB
PreferredMaxBytes: 512 KB
Kafka:
Brokers:
- 127.0.0.1:9092
Organizations:
Application: &ApplicationDefaults
Organizations:
执行命令
export FABRIC_CFG_PATH=$PWD
mkdir channel-artifacts
configtxgen -profile ThreeOrgsOrdererGenesis -outputBlock ./channel-artifacts/genesis.block
export CHANNEL_NAME=mychannel
configtxgen -profile ThreeOrgsChannel -outputCreateChannelTx ./channel-artifacts/channel.tx -channelID $CHANNEL_NAME
configtxgen -profile ThreeOrgsChannel -outputAnchorPeersUpdate ./channel-artifacts/Org1MSPanchors.tx -channelID $CHANNEL_NAME -asOrg Org1MSP
configtxgen -profile ThreeOrgsChannel -outputAnchorPeersUpdate ./channel-artifacts/Org2MSPanchors.tx -channelID $CHANNEL_NAME -asOrg Org2MSP
configtxgen -profile ThreeOrgsChannel -outputAnchorPeersUpdate ./channel-artifacts/Org3MSPanchors.tx -channelID $CHANNEL_NAME -asOrg Org3MSP
配置 docker-compose
新建文件 .env
COMPOSE_PROJECT_NAME=mytest01
创建 base 目录
mkdir base
base 目录下新建 2 个文件:peer-base.yaml 和 docker-compose-base.yaml
peer-base.yaml
version: '2'
services:
peer-base:
image: hyperledger/fabric-peer
environment:
- CORE_VM_ENDPOINT=unix:///host/var/run/docker.sock
# the following setting starts chaincode containers on the same
# bridge network as the peers
# https://docs.docker.com/compose/networking/
# ---CHANGED---
- CORE_VM_DOCKER_HOSTCONFIG_NETWORKMODE=${COMPOSE_PROJECT_NAME}_basic
#- CORE_LOGGING_LEVEL=ERROR
- CORE_LOGGING_LEVEL=DEBUG
- CORE_PEER_TLS_ENABLED=true
- CORE_PEER_GOSSIP_USELEADERELECTION=true
- CORE_PEER_GOSSIP_ORGLEADER=false
- CORE_PEER_PROFILE_ENABLED=true
- CORE_PEER_TLS_CERT_FILE=/etc/hyperledger/fabric/tls/server.crt
- CORE_PEER_TLS_KEY_FILE=/etc/hyperledger/fabric/tls/server.key
- CORE_PEER_TLS_ROOTCERT_FILE=/etc/hyperledger/fabric/tls/ca.crt
working_dir: /opt/gopath/src/github.com/hyperledger/fabric/peer
command: peer node start
docker-compose-base.yaml
version: '2'
services:
# ---CHANGED--- The orderer name is taken from the name generated by the "cryptogen" certs – it indicates the orderer orgs one and only orderer
orderer.acme.com:
# ---CHANGED--- The container name is a copy of the orderer name
container_name: orderer.acme.com
image: hyperledger/fabric-orderer
environment:
- ORDERER_GENERAL_LOGLEVEL=debug
- ORDERER_GENERAL_LISTENADDRESS=0.0.0.0
- ORDERER_GENERAL_GENESISMETHOD=file
- ORDERER_GENERAL_GENESISFILE=/var/hyperledger/orderer/orderer.genesis.block
- ORDERER_GENERAL_LOCALMSPID=OrdererMSP
- ORDERER_GENERAL_LOCALMSPDIR=/var/hyperledger/orderer/msp
# enabled TLS
- ORDERER_GENERAL_TLS_ENABLED=true
- ORDERER_GENERAL_TLS_PRIVATEKEY=/var/hyperledger/orderer/tls/server.key
- ORDERER_GENERAL_TLS_CERTIFICATE=/var/hyperledger/orderer/tls/server.crt
- ORDERER_GENERAL_TLS_ROOTCAS=[/var/hyperledger/orderer/tls/ca.crt]
working_dir: /opt/gopath/src/github.com/hyperledger/fabric
command: orderer
volumes:
- ../channel-artifacts/genesis.block:/var/hyperledger/orderer/orderer.genesis.block
# ---CHANGED--- the path is different to reflect our company's domain
- ../crypto-config/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp:/var/hyperledger/orderer/msp
# ---CHANGED--- the path is different to reflect our company's domain
- ../crypto-config/ordererOrganizations/acme.com/orderers/orderer.acme.com/tls/:/var/hyperledger/orderer/tls
ports:
- 7050:7050
# ---CHANGED--- The peer name is taken from the name generated by the "cryptogen" certs – it indicates the peer org 1 and one peer "peer0"
peer0.org1.acme.com:
# ---CHANGED--- Container name – same as the peer name
container_name: peer0.org1.acme.com
extends:
file: peer-base.yaml
service: peer-base
environment:
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_ID=peer0.org1.acme.com
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_ADDRESS=peer0.org1.acme.com:7051
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_GOSSIP_EXTERNALENDPOINT=peer0.org1.acme.com:7051
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_GOSSIP_BOOTSTRAP=peer0.org1.acme.com:7051
- CORE_PEER_LOCALMSPID=Org1MSP
volumes:
- /var/run/:/host/var/run/
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- ../crypto-config/peerOrganizations/org1.acme.com/peers/peer0.org1.acme.com/msp:/etc/hyperledger/fabric/msp
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- ../crypto-config/peerOrganizations/org1.acme.com/peers/peer0.org1.acme.com/tls:/etc/hyperledger/fabric/tls
ports:
- 7051:7051
- 7053:7053
# ---CHANGED--- The peer name is taken from the name generated by the "cryptogen" certs – it indicates the peer org 2 and one peer "peer0"
peer0.org2.acme.com:
# ---CHANGED--- Container name – same as the peer name
container_name: peer0.org2.acme.com
extends:
file: peer-base.yaml
service: peer-base
environment:
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_ID=peer0.org2.acme.com
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_ADDRESS=peer0.org2.acme.com:7051
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_GOSSIP_EXTERNALENDPOINT=peer0.org2.acme.com:7051
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_GOSSIP_BOOTSTRAP=peer0.org2.acme.com:7051
# ---CHANGED--- ensure that the MSP ID is correctly set of Org2
- CORE_PEER_LOCALMSPID=Org2MSP
volumes:
- /var/run/:/host/var/run/
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- ../crypto-config/peerOrganizations/org2.acme.com/peers/peer0.org2.acme.com/msp:/etc/hyperledger/fabric/msp
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- ../crypto-config/peerOrganizations/org2.acme.com/peers/peer0.org2.acme.com/tls:/etc/hyperledger/fabric/tls
ports:
- 8051:7051
- 8053:7053
# ---CHANGED--- The peer name is taken from the name generated by the "cryptogen" certs – it indicates the peer org 3 and one peer "peer0"
peer0.org3.acme.com:
# ---CHANGED--- Container name – same as the peer name
container_name: peer0.org3.acme.com
extends:
file: peer-base.yaml
service: peer-base
environment:
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_ID=peer0.org3.acme.com
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_ADDRESS=peer0.org3.acme.com:7051
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_GOSSIP_EXTERNALENDPOINT=peer0.org3.acme.com:7051
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- CORE_PEER_GOSSIP_BOOTSTRAP=peer0.org3.acme.com:7051
# ---CHANGED--- ensure that the MSP ID is correctly set of Org3
- CORE_PEER_LOCALMSPID=Org3MSP
volumes:
- /var/run/:/host/var/run/
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- ../crypto-config/peerOrganizations/org3.acme.com/peers/peer0.org3.acme.com/msp:/etc/hyperledger/fabric/msp
# ---CHANGED--- changed to reflect peer name, org name and our company's domain
- ../crypto-config/peerOrganizations/org3.acme.com/peers/peer0.org3.acme.com/tls:/etc/hyperledger/fabric/tls
ports:
- 9051:7051
- 9053:7053
项目根目录下新建文件 docker-compose-cli.yaml
version: '2'
# ---CHANGED--- our network is called "basic"
networks:
basic:
services:
# ---CHANGED--- The orderer name is taken from the name generated by the "cryptogen" certs – it indicates the orderer orgs one and only orderer
orderer.acme.com:
extends:
file: base/docker-compose-base.yaml
# ---CHANGED--- refers to orderer name
service: orderer.acme.com
# ---CHANGED--- The container name is a copy of the orderer name
container_name: orderer.acme.com
networks:
- basic
# ---CHANGED--- The peer name is taken from the name generated by the "cryptogen" certs – it indicates the peer org 1 and one peer "peer0"
peer0.org1.acme.com:
# ---CHANGED--- Container name – same as the peer name
container_name: peer0.org1.acme.com
extends:
file: base/docker-compose-base.yaml
# ---CHANGED--- Refers to peer name
service: peer0.org1.acme.com
networks:
# ---CHANGED--- our network is called "basic"
- basic
# ---CHANGED--- The peer name is taken from the name generated by the "cryptogen" certs – it indicates the peer org 2 and one peer "peer0"
peer0.org2.acme.com:
# ---CHANGED--- Container name – same as the peer name
container_name: peer0.org2.acme.com
extends:
file: base/docker-compose-base.yaml
# ---CHANGED--- Refers to peer name
service: peer0.org2.acme.com
networks:
# ---CHANGED--- our network is called "basic"
- basic
# ---CHANGED--- The peer name is taken from the name generated by the "cryptogen" certs – it indicates the peer org 3 and one peer "peer0"
peer0.org3.acme.com:
# ---CHANGED--- Container name – same as the peer name
container_name: peer0.org3.acme.com
extends:
file: base/docker-compose-base.yaml
# ---CHANGED--- Refers to peer name
service: peer0.org3.acme.com
networks:
# ---CHANGED--- our network is called "basic"
- basic
cli:
container_name: cli
image: hyperledger/fabric-tools
tty: true
environment:
- GOPATH=/opt/gopath
- CORE_VM_ENDPOINT=unix:///host/var/run/docker.sock
- CORE_LOGGING_LEVEL=DEBUG
- CORE_PEER_ID=cli
# ---CHANGED--- peer0 from Org1 is the default for this CLI container
- CORE_PEER_ADDRESS=peer0.org1.acme.com:7051
- CORE_PEER_LOCALMSPID=Org1MSP
- CORE_PEER_TLS_ENABLED=true
# ---CHANGED--- changed to reflect peer0 name, org1 name and our company's domain
- CORE_PEER_TLS_CERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.acme.com/peers/peer0.org1.acme.com/tls/server.crt
# ---CHANGED--- changed to reflect peer0 name, org1 name and our company's domain
- CORE_PEER_TLS_KEY_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.acme.com/peers/peer0.org1.acme.com/tls/server.key
# ---CHANGED--- changed to reflect peer0 name, org1 name and our company's domain
- CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.acme.com/peers/peer0.org1.acme.com/tls/ca.crt
# ---CHANGED--- changed to reflect peer0 name, org1 name and our company's domain
- CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.acme.com/users/[email protected]/msp
working_dir: /opt/gopath/src/github.com/hyperledger/fabric/peer
# ---CHANGED--- command needs to be connected out as we will be issuing commands explicitly, not using by any script
# command: /bin/bash -c './scripts/script.sh ${CHANNEL_NAME}; sleep $TIMEOUT'
volumes:
- /var/run/:/host/var/run/
# ---CHANGED--- chaincode path adjusted
- ./chaincode/:/opt/gopath/src/github.com/chaincode
- ./crypto-config:/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/
- ./channel-artifacts:/opt/gopath/src/github.com/hyperledger/fabric/peer/channel-artifacts
depends_on:
# ---CHANGED--- reference to our orderer
- orderer.acme.com
# ---CHANGED--- reference to peer0 of Org1
- peer0.org1.acme.com
# ---CHANGED--- reference to peer0 of Org2
- peer0.org2.acme.com
# ---CHANGED--- reference to peer0 of Org3
- peer0.org3.acme.com
networks:
# ---CHANGED--- our network is called "basic"
- basic
启动容器
先清理现有容器
docker stop $(docker ps -a -q)
docker rm $(docker ps -a -q)
启动命令
CHANNEL_NAME=$CHANNEL_NAME docker-compose -f docker-compose-cli.yaml up -d
进入 cli 容器
docker exec -it cli bash
创建 channel
export CHANNEL_NAME=mychannel
peer channel create -o orderer.acme.com:7050 -c $CHANNEL_NAME -f ./channel-artifacts/channel.tx --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem
加入 channel
peer0 org1
peer channel join -b mychannel.block
peer0 org2
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org2.acme.com:7051 CORE_PEER_LOCALMSPID="Org2MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/peers/peer0.org2.acme.com/tls/ca.crt peer channel join -b mychannel.block
peer0 org3
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org3.acme.com:7051 CORE_PEER_LOCALMSPID="Org3MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/peers/peer0.org3.acme.com/tls/ca.crt peer channel join -b mychannel.block
更新锚节点
peer0 org1
peer channel update -o orderer.acme.com:7050 -c $CHANNEL_NAME -f ./channel-artifacts/Org1MSPanchors.tx --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem
peer0 org2
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org2.acme.com:7051 CORE_PEER_LOCALMSPID="Org2MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/peers/peer0.org2.acme.com/tls/ca.crt peer channel update -o orderer.acme.com:7050 -c $CHANNEL_NAME -f ./channel-artifacts/Org2MSPanchors.tx --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem
peer0 org3
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org3.acme.com:7051 CORE_PEER_LOCALMSPID="Org3MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/peers/peer0.org3.acme.com/tls/ca.crt peer channel update -o orderer.acme.com:7050 -c $CHANNEL_NAME -f ./channel-artifacts/Org3MSPanchors.tx --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem
安装 chaincode
peer chaincode install -n mycc -v 1.0 -p github.com/chaincode/chaincode_example02/go/
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org2.acme.com:7051 CORE_PEER_LOCALMSPID="Org2MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/peers/peer0.org2.acme.com/tls/ca.crt peer chaincode install -n mycc -v 1.0 -p github.com/chaincode/chaincode_example02/go/
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org3.acme.com:7051 CORE_PEER_LOCALMSPID="Org3MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/peers/peer0.org3.acme.com/tls/ca.crt peer chaincode install -n mycc -v 1.0 -p github.com/chaincode/chaincode_example02/go/
实例化 chaincode
peer chaincode instantiate -o orderer.acme.com:7050 --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem -C $CHANNEL_NAME -n mycc -v 1.0 -c '{"Args":["init","a", "100", "b","200"]}' -P "OR ('Org1MSP.member','Org2MSP.member','Org3MSP.member')"
调用 chaincode
peer chaincode invoke -o orderer.acme.com:7050 --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem -C $CHANNEL_NAME -n mycc -c '{"Args":["invoke","a","b","10"]}'
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org2.acme.com:7051 CORE_PEER_LOCALMSPID="Org2MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org2.acme.com/peers/peer0.org2.acme.com/tls/ca.crt peer chaincode invoke -o orderer.acme.com:7050 --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem -C $CHANNEL_NAME -n mycc -c '{"Args":["invoke","a","b","10"]}'
CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/users/[email protected]/msp CORE_PEER_ADDRESS=peer0.org3.acme.com:7051 CORE_PEER_LOCALMSPID="Org3MSP" CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org3.acme.com/peers/peer0.org3.acme.com/tls/ca.crt peer chaincode invoke -o orderer.acme.com:7050 --tls --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/acme.com/orderers/orderer.acme.com/msp/tlscacerts/tlsca.acme.com-cert.pem -C $CHANNEL_NAME -n mycc -c '{"Args":["invoke","a","b","10"]}'
查询结果
查询 a:
peer chaincode query -C $CHANNEL_NAME -n mycc -c '{"Args":["query","a"]}'
查询 b:
peer chaincode query -C $CHANNEL_NAME -n mycc -c '{"Args":["query","b"]}'