A Docker Compose setup for running a Firo full node (firod) alongside an ElectrumX server.
Designed for Ubuntu 22.04+ / Debian-based systems.
- 2 Core CPU
- 8GB+ RAM
- 40GB free disk space (Firo chain + ElectrumX db)
python3 rpcauth.py firoelectrumxcp .env.example .envFill in the values from the rpcauth.py output.
This image sets PEER_DISCOVERY=off and PEER_ANNOUNCE= (empty) so the server runs privately by default and won't announce itself to the network. Note that ElectrumX itself does not default to private — if undefined, PEER_ANNOUNCE defaults to enabled, since it isn't a true/false flag but an empty-vs-non-empty check (an empty value disables announcing; any other value, including no or false, enables it). Separately, announcing only ever happens as part of peer discovery, so PEER_DISCOVERY=off (or self) makes PEER_ANNOUNCE moot regardless of its value. If you want your server publicly discoverable, set REPORT_HOST to your public domain/IP, and set both PEER_DISCOVERY=on and PEER_ANNOUNCE=true.
REPORT_SERVICES=ssl://${REPORT_HOST}:50002 tells peers to connect to you over SSL on port 50002 (the Nginx-terminated port), even though ElectrumX itself only ever serves plaintext on 50001 internally. This only matters when announcing is enabled — if you're running privately it's unused.
docker compose up -dALLOW_ROOT=trueis set in the ElectrumX container to avoid permission issues.- Adjust
cpusandmemorylimits incompose.ymlto suit your hardware.
| Port | Service | Description |
|---|---|---|
| 8168 | firod | P2P network |
| 8888 | firod | RPC |
| 50001 | electrumx | Electrum TCP |
| 50002 | electrumx | Electrum SSL |
- 8168 is safe and encouraged to open publicly for peering
- 8888 should remain firewalled — never expose RPC publicly
- 50001 is plaintext — it is recommended to front it with Nginx on port 50002 with SSL
For public-facing deployments it is recommended to use Nginx as a reverse proxy for SSL termination. ElectrumX runs plain TCP internally on port 50001 and Nginx handles SSL on port 50002.
apt install nginx certbot python3-certbot-nginx libnginx-mod-stream -ycertbot --nginx -d your.domainOutside of the http block, add this to the bottom of /etc/nginx/nginx.conf:
stream {
upstream electrumx {
server 127.0.0.1:50001;
}
server {
listen 50002 ssl;
proxy_pass electrumx;
ssl_certificate /etc/letsencrypt/live/your.domain/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/your.domain/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
}
}systemctl reload nginxufw allow 8168/tcp
ufw allow 50002/tcpCertbot will auto-renew your certificate via a systemd timer.
