This repo builds reddcoind in an auditable way, and packages it into a minimal Docker containers provided for various CPU architectures.
The work here was initially based on lncm/docker-bitcoind and ruimarinho/docker-bitcoin-core, but has significantly diverged since.
- All
git-tags(and most commits) are signed byABEDC4489B9188E45C2342A82E91240B293BA5D3 - All
git-tags(and most commits) areopentimestamps-ed - All builds aim to be maximally auditable. After
git tag push, the entire process is automated, with each step printed, and the code aiming to be easy to follow - All builds are based on Alpine
- Cross-compiled builds are done using our (also auditable)
qemu - To fit build and complete
make checktest suite, BerkeleyDB is build separately here - Each build produces binaries for:
amd64,arm64v8, andarm32v7 - All architectures are aggregated under an easy-to-use Docker Manifest
- All
git-tagsare build automatically, and with an auditable trace - Each successful build of a
git tagpushes result Docker image to Docker Hub - Images pushed to Docker Hub are never deleted (even if
lndversion gets overridden, previous one is preserved) - All
finalimages are based on Alpine for minimum base size - All binaries are
stripped - Each
git-tagbuild is tagged with a unique tag number - Each minor version is stored in a separate directory (for the ease of backporting patches)
NOTE: ZMQ
blockandtxports are set to28332and28333respectively.
NOTE: For an always up-to-date list see: https://hub.docker.com/repository/docker/reddcoincore/reddcoind/tags
v4.22.9.5v4.22.9.4v4.22.9v4.22.9rc2v4.22.9rc1v4.22.8v4.22.7
First pull the image from Docker Hub:
docker pull reddcoincore/reddcoind:v4.22.9.5NOTE: Running above will automatically choose native architecture of your CPU.
Or, to pull a specific CPU architecture:
docker pull reddcoincore/reddcoind:v4.22.9.5-arm64v8First of all, create a directory in your home directory called .reddcoin
Next, create a config file. You can take a look at the following sample: thebox-compose-system (1).
Some guides on how to configure reddcoin can be found here (reddcoin git repo)
Then to start reddcoind, run:
docker run -it --rm --detach \
-v ~/.reddcoin:/home/reddcoind/.reddcoin \
-p 45444:45444 \
-p 18444:18444 \
-p 28333:28333 \
--name reddcoind \
reddcoincore/reddcoind:v4.22.9.5That will run reddcoind such that:
- all data generated by the container is stored in
~/.reddcoinon your host machine, - RPC will only be reachable from inside the container (see RPC access to expose it),
- port
45444will be reachable for the peer-to-peer communication, - port
28332will be reachable for ZMQ block notifications, - port
28333will be reachable for ZMQ transaction notifications, - created container will get named
reddcoind, - within the container,
reddcoindbinary is run as unprivileged userreddcoind(UID=1000), - that command will run the container in the background and print the ID of the container being run.
To issue any commands to a running container, do:
docker exec -it reddcoind BINARY COMMANDWhere:
BINARYis eitherreddcoind,reddcoin-cli,reddcoin-tx, (orreddcoin-walletonv0.18+) andCOMMANDis something you'd normally pass to the binary
Examples:
docker exec -it reddcoind reddcoind --help
docker exec -it reddcoind reddcoind --version
docker exec -it reddcoind reddcoin-cli --help
docker exec -it reddcoind reddcoin-cli -getinfo
docker exec -it reddcoind reddcoin-cli getblockcountBy default the image sets no RPC username or password, and RPC only listens inside the container. reddcoind then uses cookie authentication (a .cookie file in the data directory), so docker exec reddcoind reddcoin-cli ... works without any credentials.
To reach RPC from the host or from other containers, set all of these when the container is first created:
| Variable | Example | Purpose |
|---|---|---|
RPC_USERNAME |
reddcoinrpc |
RPC user name. Must be set together with RPC_PASSWORD |
RPC_PASSWORD |
a long random string | RPC password |
RPC_BIND |
0.0.0.0 |
Listen on the container's network interface, not just inside the container |
RPC_ALLOW_IP |
172.16.0.0/12 |
Addresses allowed to connect. 172.16.0.0/12 covers Docker's default networks, which is where connections from other containers, and from the host through a published port, come from |
Publish the RPC port on the host's loopback interface only, for example -p 127.0.0.1:45443:45443, unless other machines need to reach it.
NOTE: These variables are only used when
reddcoin.confdoes not exist yet. An existing config file is never rewritten: edit it, or delete it to have it regenerated. Older versions of this image wroterpcpassword=rpcpasswordandrpcallowip=0.0.0.0/0intoreddcoin.conf. The container now logs a warning at startup when it finds settings like these.
Here is a docker-compose.yml for mainnet
version: '3'
services:
reddcoin:
container_name: reddcoind
user: 1000:1000
image: reddcoincore/reddcoind:v4.22.9.5
volumes:
- ./reddcoin:/home/reddcoind/.reddcoin
restart: on-failure
environment:
- RPC_SERVER=1
- RPC_USERNAME=[create a user name]
- RPC_PASSWORD=[UseALongAndHardToGuessPassWord]
- RPC_PORT=45443
- RPC_BIND=0.0.0.0
- RPC_ALLOW_IP=172.16.0.0/12
stop_grace_period: 15m30s
ports:
- "127.0.0.1:45443:45443"
- "45444:45444"
- "28332:28332"
- "28333:28333"First, ensure that the reddcoin/ folder is in the directory containing docker-compose.yml.
Then, Docker Compose will mount the reddcoin/ folder to /home/reddcoind/.reddcoin.
Here are some possible reasons why.
The permissions for the reddcoin data direct is assumed to be UID 1000 (first user).
If you have a different setup, please do the following
# where ".reddcoin" is the data directory
sudo chown -R 1000.1000 $HOME/.reddcoin