A Docker Compose setup for running a Firo full node (firod) alongside an ElectrumX server.
Designed for Ubuntu 22.04+ / Debian-based systems.
python3 rpcauth.py firoelectrumx
cp .env.example .env
Fill in the values from the rpcauth.py output.
This image sets PEER_DISCOVERY=off and PEER_ANNOUNCE= (empty) so the server runs privately by default and won't announce itself to the network. Note that ElectrumX itself does not default to private — if undefined, PEER_ANNOUNCE defaults to enabled, since it isn't a true/false flag but an empty-vs-non-empty check (an empty value disables announcing; any other value, including no or false, enables it). Separately, announcing only ever happens as part of peer discovery, so PEER_DISCOVERY=off (or self) makes PEER_ANNOUNCE moot regardless of its value. If you want your server publicly discoverable, set REPORT_HOST to your public domain/IP, and set both PEER_DISCOVERY=on and PEER_ANNOUNCE=true.
REPORT_SERVICES=ssl://${REPORT_HOST}:50002 tells peers to connect to you over SSL on port 50002 (the Nginx-terminated port), even though ElectrumX itself only ever serves plaintext on 50001 internally. This only matters when announcing is enabled — if you're running privately it's unused.
docker compose up -d
ALLOW_ROOT=true is set in the ElectrumX container to avoid permission issues.cpus and memory limits in compose.yml to suit your hardware.| Port | Service | Description |
|---|---|---|
| 8168 | firod | P2P network |
| 8888 | firod | RPC |
| 50001 | electrumx | Electrum TCP |
| 50002 | electrumx | Electrum SSL |
For public-facing deployments it is recommended to use Nginx as a reverse proxy for SSL termination. ElectrumX runs plain TCP internally on port 50001 and Nginx handles SSL on port 50002.
apt install nginx certbot python3-certbot-nginx libnginx-mod-stream -y
certbot --nginx -d your.domain
Outside of the http block, add this to the bottom of /etc/nginx/nginx.conf:
stream {
upstream electrumx {
server 127.0.0.1:50001;
}
server {
listen 50002 ssl;
proxy_pass electrumx;
ssl_certificate /etc/letsencrypt/live/your.domain/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/your.domain/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
}
}
systemctl reload nginx
ufw allow 8168/tcp
ufw allow 50002/tcp
Certbot will auto-renew your certificate via a systemd timer.
Content type
Image
Digest
sha256:c1b456019…
Size
51.1 MB
Last updated
2 months ago
docker pull nexusocean/electrumx-firo