Losing a signing node
A two-of-three cluster keeps signing with one node down; the loss is reduced redundancy, not an outage. Restoring the node:- Re-provision the machine or pod.
- Restore the node’s identity from the approved secret store.
- Restore the encrypted share store from backup.
- Supply the store’s passphrase from the runtime secret store.
- Start the node; it registers as ready and rejoins signing sessions.
What is backed up
The chain code used for address derivation is never regenerated for existing wallets; derived addresses depend on it.

