How to set up Full Node on Raspberry Pi 5 via Tor for Noobs?
How to set up Full Node on Raspberry Pi 5 via Tor for Noobs?
Loading saved threads...
just-a-guest-name · External communityPost link
External question — Bitcoin Stack Exchange
Author: just-a-guest-name
Original post: https://bitcoin.stackexchange.com/questions/125305
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
TLDR: Can someone lead me through the process of running a Bitcoin Full Node on a Raspberry Pi 5 with Raspberry Pi OS (64-bit), which does not display my IP adress openly (so probably via TOR) and explain me the whole thing about portforwarding and how to minimize risk with it?
I would like to run a Bitcoin Full Node on my Raspberry Pi 5 running Raspberry Pi OS (64-bit). The Pi is booted from an external 2TB SSD which, before imaging the OS, I formated to ext4 and on which I would run the whole node. The Pi is only intended for running a full node. Even though the Pi is only connected to my guest wifi, I would like to not display the IP adress openly, so I would like to run it via Tor.
I'm trying to follow several different tutorials througout the last days, but somehow I do not get it set up properly, especially because all tutorials I found so far connecting the concept of full node & tor are for older version of bitcoin core or older Pi's and somehow sth is always not working the way it seems in the tutorial or it seems as if some step is missing or the tutorial is just the closest I get to my setup but always different enough that at some point the path they take and the path I have to take seperate.
So is there maybe someone that can kind of lead me through the process maybe?
It's kind of weird that I can't find anything about this so far, because I can't imagine it being that complicated - in essence, I guess, it should be sth along the way of
install tor
install bitcoin core
change torrc
change bitcoin.conf
run bitcoin core, download blockchain and then just let it run
but I kind of just can't get it set up. So can someone maybe help me with this?
additional: I can't grasp the whole thing about the portforwarding. Is this necessary for supporting the network and if so, isn't this a security risk for my network/device? How can I minimize/eradicate this risk or is using tor already a good security measure for this?
Maybe necessary info: my wifi is secured with at least WPA2 (maybe WPA3, I'm not quite sure right now) and a pretty complex passphrase.
Quote
Report
Davor Marić · External communityPost link
External answer — Bitcoin Stack Exchange
Author: Davor Marić
Original post: https://bitcoin.stackexchange.com/a/125438
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
Answered by ChatGPT o1:
Below is a high-level guide for setting up a Bitcoin Core full node on a Raspberry Pi 5 (running Raspberry Pi OS 64-bit) over Tor, with some notes on port forwarding and security. While the exact steps can vary slightly based on OS version and network configurations, the broad process remains consistent.
Prerequisites and Basic Setup
Hardware:
Raspberry Pi 5 (4GB or 8GB recommended if you plan to use it only for the node).
A sufficiently large SSD (2TB is more than enough for the ~500GB Bitcoin blockchain, plus future growth).
Power supply, case, and the usual Pi accessories.
Operating System:
You’ve mentioned using Raspberry Pi OS (64-bit). Ensure it’s up-to-date (sudo apt update && sudo apt full-upgrade).
Initial Storage Setup:
Since you already formatted the SSD to ext4 and imaged the OS onto it, you’re good to go. Otherwise, ensure you have a properly formatted external SSD that can store the entire Bitcoin data directory. Mount it automatically on boot so that your Pi can access it without manual intervention.
Basic Security:
Keep your Pi behind a firewall or NAT (typical in home routers).
Use strong passwords and WPA2/WPA3 on your Wi-Fi.
(Optional) Change the default user and password on Raspberry Pi OS if you haven’t already.
2. Installing Tor
Install Tor:
bash
Copy
sudo apt update
sudo apt install tor
Enable and Start Tor:
bash
Copy
sudo systemctl enable tor
sudo systemctl start tor
By default, Tor is configured to run as a client. We’ll configure a hidden service for Bitcoin Core.
3. Installing Bitcoin Core
There are two main ways:
Install from apt (Debian Repository):
bash
Copy
sudo apt update
sudo apt install bitcoin-daemon bitcoin-qt
This might not always be the latest version.
Download from bitcoin.org (Official Binaries):
Go to
https://bitcoin.org/en/download
and download the ARM64 tarball (bitcoin--arm64.tar.gz).
Verify signatures if you want to be absolutely sure. (Optional but recommended.)
Extract the binary:
bash
Copy
tar -xvf bitcoin--arm64.tar.gz
Copy or symlink bitcoind, bitcoin-cli, bitcoin-qt to a location in your PATH (e.g. /usr/local/bin).
Either route works. For a dedicated node on Pi, the second approach gives you more control over the version and is often more up to date.
Configuring Tor and Bitcoin Core
A) Tor Configuration
The Tor configuration file is typically located at /etc/tor/torrc. We want Tor to create a hidden service for inbound Bitcoin peer connections.
Open Tor config:
bash
Copy
sudo nano /etc/tor/torrc
Add (or un-comment) lines for a Hidden Service:
bash
Copy
Hidden service for Bitcoin node
HiddenServiceDir /var/lib/tor/bitcoin-service/
HiddenServiceVersion 3
HiddenServicePort 8333 127.0.0.1:8333
HiddenServiceDir: Directory storing the hidden service keys/hostname. You can call it anything, but typically store it in /var/lib/tor/....
HiddenServiceVersion 3: Use the newer v3 onion services.
HiddenServicePort 8333: Tells Tor to forward traffic from your onion address on port 8333 to 127.0.0.1:8333 on the Pi. (Bitcoin’s default P2P port is 8333.)
Save and exit. Then restart Tor:
bash
Copy
sudo systemctl restart tor
Locate your Onion address:
After Tor restarts, you can find your onion address in the file /var/lib/tor/bitcoin-service/hostname.
bash
Copy
sudo cat /var/lib/tor/bitcoin-service/hostname
This onion address looks like .onion and is what other peers over Tor will see instead of your public IP.
B) Bitcoin Core Configuration
Create bitcoin.conf (if it doesn’t exist) in your data directory. If you want the data directory on the SSD (recommended), let’s assume it’s mounted at /mnt/ssd or similar. For example:
bash
Copy
mkdir -p /mnt/ssd/bitcoin
nano /mnt/ssd/bitcoin/bitcoin.conf
A minimal Tor-only config might look like this:
ini
Copy
bitcoin.conf
Tell Bitcoin Core where the data directory is located
datadir=/mnt/ssd/bitcoin
Run as a daemon on Linux (no GUI)
daemon=1
Disable listening on your LAN IP; we’ll only listen on Tor
listen=1
bind=127.0.0.1
Connect only through Tor; no clearnet
proxy=127.0.0.1:9050
onlynet=onion
If you still want to have normal (clearnet) connections in parallel:
Comment out onlynet=onion and add:
listenonion=1
or onion=127.0.0.1:9050
Tor hidden service
This instructs Bitcoin Core to announce the onion service created in torrc
externalip=<YOUR_ONION_ADDRESS>.onion
(Optional) The number of connections you allow:
maxconnections=40
(Optional but recommended) for faster initial block download (if you want clearnet):
addnode=
or use .onion bootstrap nodes
RPC settings (if you plan to connect a wallet or monitor the node)
rpcuser=bitcoinrpc
rpcpassword=<STRONG_PASSWORD>
You can add more advanced config as needed
(Optional) Systemd unit override: If installing via apt, bitcoind may be managed by systemd. Verify or change the data directory in the systemd service if needed. Otherwise, you can run bitcoind manually or from a simple systemd unit file.
Start Bitcoin Core:
bash
Copy
bitcoind -conf=/mnt/ssd/bitcoin/bitcoin.conf
Or if installed via apt, it might auto-start with your config once placed in the default directory. The default data directory is usually ~/.bitcoin, but we forced it to datadir=/mnt/ssd/bitcoin in the config to store on the SSD.
Verification:
Check logs:
bash
Copy
tail -f /mnt/ssd/bitcoin/debug.log
or if you used default location
bash
Copy
tail -f ~/.bitcoin/debug.log
Look for lines referencing “tor” or “Onion”. If everything is correct, you should eventually see that it is listening on the onion address.
5. Port Forwarding and Network Considerations
Do You Need Port Forwarding?
Over Tor:
If you’re exclusively running your Bitcoin node as a Tor hidden service (onlynet=onion), you do not need to open any ports on your router or do any port forwarding. Tor handles the inbound connections to your node via your onion address.
Dual-Stack: Tor + Clearnet:
If you also want to receive connections from normal (non-Tor) peers (i.e., letting them connect to your public IP on port 8333), you do need to forward port 8333 from your router to your Pi.
This helps the network—because you become a full public node—but it may reveal your IP.
Security Risks?
Generally, Bitcoin Core is secure enough to run with an open port if you keep your system updated and hardened. But opening any port always carries some risk, especially if the software (Bitcoin Core or your OS) has a security flaw.
Running over Tor only (with no clearnet port forwarding) is often considered more private and can be safer from a network perspective, as your real IP is never exposed.
Minimizing Risk if You Want Clearnet Connections
Use a Guest Network (as you mentioned). Even if compromised, it’s segmented from your main network.
Regular Updates: Keep your Pi OS and Bitcoin Core updated.
Firewall: By default, Raspberry Pi OS does not open inbound ports except for your forwarded ports. You can also use ufw (Uncomplicated Firewall) to be explicit about which ports are open.
Router Config: Use a good router that doesn’t misconfigure port forwarding or expose other services.
6. Letting it Sync
Once the node starts, it will begin the initial blockchain download (IBD). Depending on your bandwidth and CPU performance (the Pi 5 is more powerful than previous models, but still not as fast as a typical desktop), this can take a few days or even more:
Monitor progress:
Using bitcoin-cli getblockcount
Or checking tail -f debug.log.
Ensure enough space: The blockchain is around 500GB (late 2023/early 2024) and growing. Your 2TB SSD is more than sufficient.
Performance tips:
If you’re CPU-bound, you could lower dbcache in bitcoin.conf, though a Pi 5 can handle at least dbcache=2048 (2GB) if it has enough RAM.
Limit inbound connections (maxconnections) if your bandwidth is limited.
7. Final Check and Ongoing Operation
Confirm your node is reachable over Tor:
Another Tor-enabled Bitcoin node or an onion peer can connect to <YOUR_ONION_ADDRESS>.onion:8333.
Auto-start on Boot:
If installed via apt, it can be set to start automatically (systemd).
If manual, create a systemd service or use cron @reboot to start bitcoind.
Privacy:
When running only over Tor (and not enabling clearnet connections in bitcoin.conf), you will not publicly display your IP—only your .onion address.
For more anonymity, do not mix your real IP inbound connections and Tor inbound connections.
8. Summary of Key Points
Tor Installation + Hidden Service in /etc/tor/torrc.
Bitcoin Core configured to listen=1, externalip=<YOUR_ONION_ADDRESS>.onion, proxy=127.0.0.1:9050, and optionally onlynet=onion.
No Port Forwarding is strictly necessary if you only want to be an onion-only node. Tor will handle inbound requests automatically.
Optional Port Forwarding on 8333 if you want to also serve clearnet peers—which reveals your IP and requires extra care.
Security:
Use a guest network + strong Wi-Fi password.
Keep Raspberry Pi OS and Bitcoin Core updated.
Using Tor significantly hides your real IP and can protect you from some direct attacks.
By following these steps, you should have a (1) working Bitcoin full node running on the Pi 5, (2) storing the blockchain on your SSD, (3) using Tor so that your IP address is not directly exposed, and (4) optionally port-forwarding if you want to offer clearnet connections.
Further Resources
Official Bitcoin Core documentation – outlines general full node requirements.
Bitcoin Core and Tor Setup Docs – though slightly older, the principles are the same.
Raspberry Pi Documentation – always check for OS-specific details.
With that, you should have a solid template for running a secure, Tor-only Bitcoin node on a Raspberry Pi 5. Good luck, and happy node-running!
Quote
Report
Post Reply
Quoted from Forex.com.bd-Editorial External answer — Bitcoin Stack Exchange Author: Davor Marić Source score (net votes, not local likes): -2 Original post: https://bitcoin.stackexchange.com/a/125438 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. Answered by ChatGPT o1: Below is a high-level guide for setting up a Bitcoin Core full node on a Raspberry Pi 5 (running Raspberry Pi OS 64-bit) over Tor, with some notes on port forwarding and security. While the exact steps can vary slightly based on OS version and network configurations, the broad process remains consistent. Prerequisites and Basic Setup Hardware: Raspberry Pi 5 (4GB or 8GB recommended if you plan to use it only for the node). A sufficiently large SSD (2TB is more than enough for the ~500GB Bitcoin blockchain, plus future growth). Power supply, case, and the usual Pi accessories. Operating System: You’ve mentioned using Raspberry Pi OS (64-bit). Ensure it’s up-to-date (sudo apt update && sudo apt full-upgrade). Initial Storage Setup: Since you already formatted the SSD to ext4 and imaged the OS onto it, you’re good to go. Otherwise, ensure you have a properly formatted external SSD that can store the entire Bitcoin data directory. Mount it automatically on boot so that your Pi can access it without manual intervention. Basic Security: Keep your Pi behind a firewall or NAT (typical in home routers). Use strong passwords and WPA2/WPA3 on your Wi-Fi. (Optional) Change the default user and password on Raspberry Pi OS if you haven’t already. 2. Installing Tor Install Tor: bash Copy sudo apt update sudo apt install tor Enable and Start Tor: bash Copy sudo systemctl enable tor sudo systemctl start tor By default, Tor is configured to run as a client. We’ll configure a hidden service for Bitcoin Core. 3. Installing Bitcoin Core There are two main ways: Install from apt (Debian Repository): bash Copy sudo apt update sudo apt install bitcoin-daemon bitcoin-qt This might not always be the latest version. Download from bitcoin.org (Official Binaries): Go to https://bitcoin.org/en/download and download the ARM64 tarball (bitcoin--arm64.tar.gz). Verify signatures if you want to be absolutely sure. (Optional but recommended.) Extract the binary: bash Copy tar -xvf bitcoin--arm64.tar.gz Copy or symlink bitcoind, bitcoin-cli, bitcoin-qt to a location in your PATH (e.g. /usr/local/bin). Either route works. For a dedicated node on Pi, the second approach gives you more control over the version and is often more up to date. Configuring Tor and Bitcoin Core A) Tor Configuration The Tor configuration file is typically located at /etc/tor/torrc. We want Tor to create a hidden service for inbound Bitcoin peer connections. Open Tor config: bash Copy sudo nano /etc/tor/torrc Add (or un-comment) lines for a Hidden Service: bash Copy Hidden service for Bitcoin node HiddenServiceDir /var/lib/tor/bitcoin-service/ HiddenServiceVersion 3 HiddenServicePort 8333 127.0.0.1:8333 HiddenServiceDir: Directory storing the hidden service keys/hostname. You can call it anything, but typically store it in /var/lib/tor/.... HiddenServiceVersion 3: Use the newer v3 onion services. HiddenServicePort 8333: Tells Tor to forward traffic from your onion address on port 8333 to 127.0.0.1:8333 on the Pi. (Bitcoin’s default P2P port is 8333.) Save and exit. Then restart Tor: bash Copy sudo systemctl restart tor Locate your Onion address: After Tor restarts, you can find your onion address in the file /var/lib/tor/bitcoin-service/hostname. bash Copy sudo cat /var/lib/tor/bitcoin-service/hostname This onion address looks like .onion and is what other peers over Tor will see instead of your public IP. B) Bitcoin Core Configuration Create bitcoin.conf (if it doesn’t exist) in your data directory. If you want the data directory on the SSD (recommended), let’s assume it’s mounted at /mnt/ssd or similar. For example: bash Copy mkdir -p /mnt/ssd/bitcoin nano /mnt/ssd/bitcoin/bitcoin.conf A minimal Tor-only config might look like this: ini Copy bitcoin.conf Tell Bitcoin Core where the data directory is located datadir=/mnt/ssd/bitcoin Run as a daemon on Linux (no GUI) daemon=1 Disable listening on your LAN IP; we’ll only listen on Tor listen=1 bind=127.0.0.1 Connect only through Tor; no clearnet proxy=127.0.0.1:9050 onlynet=onion If you still want to have normal (clearnet) connections in parallel: Comment out onlynet=onion and add: listenonion=1 or onion=127.0.0.1:9050 Tor hidden service This instructs Bitcoin Core to announce the onion service created in torrc externalip=<YOUR_ONION_ADDRESS>.onion (Optional) The number of connections you allow: maxconnections=40 (Optional but recommended) for faster initial block download (if you want clearnet): addnode= or use .onion bootstrap nodes RPC settings (if you plan to connect a wallet or monitor the node) rpcuser=bitcoinrpc rpcpassword=<STRONG_PASSWORD> You can add more advanced config as needed (Optional) Systemd unit override: If installing via apt, bitcoind may be managed by systemd. Verify or change the data directory in the systemd service if needed. Otherwise, you can run bitcoind manually or from a simple systemd unit file. Start Bitcoin Core: bash Copy bitcoind -conf=/mnt/ssd/bitcoin/bitcoin.conf Or if installed via apt, it might auto-start with your config once placed in the default directory. The default data directory is usually ~/.bitcoin, but we forced it to datadir=/mnt/ssd/bitcoin in the config to store on the SSD. Verification: Check logs: bash Copy tail -f /mnt/ssd/bitcoin/debug.log or if you used default location bash Copy tail -f ~/.bitcoin/debug.log Look for lines referencing “tor” or “Onion”. If everything is correct, you should eventually see that it is listening on the onion address. 5. Port Forwarding and Network Considerations Do You Need Port Forwarding? Over Tor: If you’re exclusively running your Bitcoin node as a Tor hidden service (onlynet=onion), you do not need to open any ports on your router or do any port forwarding. Tor handles the inbound connections to your node via your onion address. Dual-Stack: Tor + Clearnet: If you also want to receive connections from normal (non-Tor) peers (i.e., letting them connect to your public IP on port 8333), you do need to forward port 8333 from your router to your Pi. This helps the network—because you become a full public node—but it may reveal your IP. Security Risks? Generally, Bitcoin Core is secure enough to run with an open port if you keep your system updated and hardened. But opening any port always carries some risk, especially if the software (Bitcoin Core or your OS) has a security flaw. Running over Tor only (with no clearnet port forwarding) is often considered more private and can be safer from a network perspective, as your real IP is never exposed. Minimizing Risk if You Want Clearnet Connections Use a Guest Network (as you mentioned). Even if compromised, it’s segmented from your main network. Regular Updates: Keep your Pi OS and Bitcoin Core updated. Firewall: By default, Raspberry Pi OS does not open inbound ports except for your forwarded ports. You can also use ufw (Uncomplicated Firewall) to be explicit about which ports are open. Router Config: Use a good router that doesn’t misconfigure port forwarding or expose other services. 6. Letting it Sync Once the node starts, it will begin the initial blockchain download (IBD). Depending on your bandwidth and CPU performance (the Pi 5 is more powerful than previous models, but still not as fast as a typical desktop), this can take a few days or even more: Monitor progress: Using bitcoin-cli getblockcount Or checking tail -f debug.log. Ensure enough space: The blockchain is around 500GB (late 2023/early 2024) and growing. Your 2TB SSD is more than sufficient. Performance tips: If you’re CPU-bound, you could lower dbcache in bitcoin.conf, though a Pi 5 can handle at least dbcache=2048 (2GB) if it has enough RAM. Limit inbound connections (maxconnections) if your bandwidth is limited. 7. Final Check and Ongoing Operation Confirm your node is reachable over Tor: Another Tor-enabled Bitcoin node or an onion peer can connect to <YOUR_ONION_ADDRESS>.onion:8333. Auto-start on Boot: If installed via apt, it can be set to start automatically (systemd). If manual, create a systemd service or use cron @reboot to start bitcoind. Privacy: When running only over Tor (and not enabling clearnet connections in bitcoin.conf), you will not publicly display your IP—only your .onion address. For more anonymity, do not mix your real IP inbound connections and Tor inbound connections. 8. Summary of Key Points Tor Installation + Hidden Service in /etc/tor/torrc. Bitcoin Core configured to listen=1, externalip=<YOUR_ONION_ADDRESS>.onion, proxy=127.0.0.1:9050, and optionally onlynet=onion. No Port Forwarding is strictly necessary if you only want to be an onion-only node. Tor will handle inbound requests automatically. Optional Port Forwarding on 8333 if you want to also serve clearnet peers—which reveals your IP and requires extra care. Security: Use a guest network + strong Wi-Fi password. Keep Raspberry Pi OS and Bitcoin Core updated. Using Tor significantly hides your real IP and can protect you from some direct attacks. By following these steps, you should have a (1) working Bitcoin full node running on the Pi 5, (2) storing the blockchain on your SSD, (3) using Tor so that your IP address is not directly exposed, and (4) optionally port-forwarding if you want to offer clearnet connections. Further Resources Official Bitcoin Core documentation – outlines general full node requirements. Bitcoin Core and Tor Setup Docs – though slightly older, the principles are the same. Raspberry Pi Documentation – always check for OS-specific details. With that, you should have a solid template for running a secure, Tor-only Bitcoin node on a Raspberry Pi 5. Good luck, and happy node-running!
Checking account access…