Skip to main content
Reference for the .env variables, network ports, and data paths used by the Whitechain public-rpc-node stack.

Required variables

The full-snap-node profile also requires WHITECHAIN_RETH_TRUSTED_PEERS, a trusted reth enode to snap-sync from, in the form enode://<pubkey>@<ip>:30303.

Optional variables

Both example .env files set HTTP_API and WS_API explicitly to the read-only default, so the value you run is visible in your own configuration rather than inherited from the Compose file.

RPC namespaces

HTTP_API and WS_API drive every profile, archive-node included, so an archive node serves the same read-only set as the pruned profiles unless you widen it deliberately. The two ports are configured independently: widening HTTP_API does not change WebSocket, and the reverse. To enable tracing on an archive node, widen the HTTP set in .env and restart the profile:
Add the wide set to WS_API only if you also need those methods over WebSocket. The wider set is pointless on the pruned profiles, which do not hold the history these methods read.
The stack ships no authentication, CORS, or vhost restriction on 8545 and 8546, and RPC_MAX_TRACING_REQUESTS bounds how many tracing calls run at once, not what one call costs. A single trace_block or debug_traceTransaction on a heavy block costs seconds of CPU and gigabytes of RAM. Enable debug, trace, txpool, and reth only behind a reverse proxy that allowlists methods and rate-limits clients, never on a port open to untrusted clients.

Archive-only RPC limits

RPC_MAX_TRACING_REQUESTS only matters once debug or trace is enabled through HTTP_API or WS_API.

Network ports

Only one profile runs at a time, so all profiles share the same host ports. Each is remappable through the env var in parentheses. The Engine API (8551) stays on the profile’s own Compose network and is never published. op-node RPC (9545) is bound to loopback only on every profile, so it is reachable for local monitoring on the host but never from the network. The EL P2P port is mapped only for full-snap-node, on all interfaces (0.0.0.0), TCP and UDP. That profile bootstraps over EL P2P: op-reth snap-syncs the state from the trusted reth peer and uses reth discovery (UDP 30303) and devp2p (TCP 30303) for it, so the port accepts inbound EL peers as well. It carries devp2p traffic only, no RPC and no admin surface. If you do not want inbound EL peering, remap it with HOST_EL_P2P_PORT or block it at the firewall. For full-node and archive-node the mapping is commented out in docker-compose.yml and the port is not published; those profiles sync over L1 derivation and libp2p only and never use EL P2P. To run two profiles side by side on one host, override one profile’s ports in .env.

Data layout

Each profile keeps its data in its own subtree, so profiles never clash:
Each profile also owns its Engine API secret in keys/<profile>/jwt.txt and its own Compose network (public_rpc_full_snap, public_rpc_full, public_rpc_archive), so two profiles share neither a credential nor a network path. make up generates the secret for the selected profile if it is missing.