Oracles & Off-Chain Data — Key concepts
Use oracles safely.
Why it matters Oracles are a trust boundary. Freshness, bounds, and deviations keep your app from acting on garbage. VRF brings unpredictability; treating it like a normal callback prevents front-running.
Design lens Decide how your app behaves when data is missing: pause, clamp, or fall back. Make that behavior explicit for users and operators. Don’t assume feeds always exist—plan for outages.
Operational reality Oracle problems are often operational: sequencer downtime on L2, misconfigured decimals, or delayed fulfillments. Build observability (events/logs) so you can see when guards are tripped and communicate clearly.
Trust model Document which feeds you trust, how frequently they update, and who can change them. If you have a manual override, define when and how it is used.
- Oracle patterns:Pull (price feeds) vs push (webhooks/keepers); aggregated vs single-signer risk.
- Chainlink feeds:LatestRoundData fields, decimals, round completeness, revert conditions.
- Safety checks:UpdatedAt freshness, min/max bounds, deviation thresholds, sequencer uptime flags where relevant.
- VRF:Request/fulfill with commitments to avoid front-running; billing and subscription setup.
- Failure modes:Stale/invalid rounds, decimal confusion, L2 sequencer downtime, trusted node assumptions.
- Fallbacks:Pausing dependent actions, manual circuit breaker, secondary feed with quorum, or graceful reverts.