Skip to main content

Sei Kubernetes Deployment

Sei uses the public charts/cosmos-validator chart pattern. This chart is based on CometBFT/Cosmos validator operations and FP Validated's internal remote-signer/Kubernetes operating model, but it removes private topology and secret details.

Chart source

charts/cosmos-validator/
values.yaml
templates/all.yaml

Concrete chart model

ComponentChart fieldWhy it exists
StatefulSetone validator workloadStable identity and persistent chain data.
P2Pports.p2p: 26656CometBFT peer networking.
RPCports.rpc: 26657CometBFT RPC, private or gatewayed.
REST/APIports.api: 1317Cosmos SDK API where enabled.
gRPCports.grpc: 9090Cosmos SDK gRPC where enabled.
Metricsports.metrics: 26660CometBFT instrumentation.
ConfigMapcometbft.*Public-safe config overrides for P2P, consensus, state sync, and instrumentation.
Signersigner.modeRemote signer recommended for production validator safety.

CometBFT validator policy

The chart surfaces production-relevant CometBFT fields:

cometbft:
p2p:
pex: false
persistentPeers: ""
privatePeerIds: ""
consensus:
doubleSignCheckHeight: 10
instrumentation:
prometheus: true
prometheusListenAddr: ":26660"

Use a sentry/peer topology for public peering and keep validator signing endpoints private.

Render

helm template sei charts/cosmos-validator --set chain.name=sei --set image.repository=ghcr.io/example/sei-node

Exposure policy

  • P2P can be public through a reviewed service/firewall policy.
  • RPC, REST, gRPC, and metrics are private or gatewayed.
  • Signer endpoints are never public.
  • Consensus keys should be treated as production secret material; remote signer/KMS/HSM patterns are preferred over plain local key files.