Sign inSign up

nexusocean/electrumx-firo

By nexusocean

•Updated 2 months ago

Image
0

538

nexusocean/electrumx-firo repository overview

⁠Firo ElectrumX Docker

A Docker Compose setup for running a Firo full node (firod) alongside an ElectrumX server.

Designed for Ubuntu 22.04+ / Debian-based systems.

  • 2 Core CPU
  • 8GB+ RAM
  • 40GB free disk space (Firo chain + ElectrumX db)

⁠Setup

⁠1. Generate RPC credentials
python3 rpcauth.py firoelectrumx
⁠2. Configure environment
cp .env.example .env

Fill in the values from the rpcauth.py output.

This image sets PEER_DISCOVERY=off and PEER_ANNOUNCE= (empty) so the server runs privately by default and won't announce itself to the network. Note that ElectrumX itself does not default to private — if undefined, PEER_ANNOUNCE defaults to enabled, since it isn't a true/false flag but an empty-vs-non-empty check (an empty value disables announcing; any other value, including no or false, enables it). Separately, announcing only ever happens as part of peer discovery, so PEER_DISCOVERY=off (or self) makes PEER_ANNOUNCE moot regardless of its value. If you want your server publicly discoverable, set REPORT_HOST to your public domain/IP, and set both PEER_DISCOVERY=on and PEER_ANNOUNCE=true.

REPORT_SERVICES=ssl://${REPORT_HOST}:50002 tells peers to connect to you over SSL on port 50002 (the Nginx-terminated port), even though ElectrumX itself only ever serves plaintext on 50001 internally. This only matters when announcing is enabled — if you're running privately it's unused.

⁠3. Start
docker compose up -d

⁠Notes

  • ALLOW_ROOT=true is set in the ElectrumX container to avoid permission issues.
  • Adjust cpus and memory limits in compose.yml to suit your hardware.

⁠Ports

PortServiceDescription
8168firodP2P network
8888firodRPC
50001electrumxElectrum TCP
50002electrumxElectrum SSL
  • 8168 is safe and encouraged to open publicly for peering
  • 8888 should remain firewalled — never expose RPC publicly
  • 50001 is plaintext — it is recommended to front it with Nginx on port 50002 with SSL

⁠Production: SSL with Nginx

For public-facing deployments it is recommended to use Nginx as a reverse proxy for SSL termination. ElectrumX runs plain TCP internally on port 50001 and Nginx handles SSL on port 50002.

⁠1. Install Nginx and Certbot
apt install nginx certbot python3-certbot-nginx libnginx-mod-stream -y
⁠2. Obtain a certificate
certbot --nginx -d your.domain
⁠3. Configure Nginx stream

Outside of the http block, add this to the bottom of /etc/nginx/nginx.conf:

stream {
    upstream electrumx {
        server 127.0.0.1:50001;
    }
    server {
        listen 50002 ssl;
        proxy_pass electrumx;
        ssl_certificate /etc/letsencrypt/live/your.domain/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/your.domain/privkey.pem;
        ssl_protocols TLSv1.2 TLSv1.3;
    }
}
⁠4. Reload Nginx
systemctl reload nginx
⁠5. Open firewall ports
ufw allow 8168/tcp
ufw allow 50002/tcp

Certbot will auto-renew your certificate via a systemd timer.

Tag summary

Content type

Image

Digest

sha256:c1b456019…

Size

51.1 MB

Last updated

2 months ago

docker pull nexusocean/electrumx-firo