|

BTCPay Docker users must opt into Tor at their next update to keep onion access

BTCPay Docker maintenance flow showing Tor configuration inspection, the post-update opt-add-tor command, preserved Tor volumes and the distinction between data retention and uninterrupted onion access.

Operators working the Bitcoin cost software program BTCPay Server by means of its normal Docker deployment must explicitly choose Tor at their next setup or update if they need to retain onion access. The change removes Tor from the mechanically included parts, making a beforehand bundled service an administrator’s configuration alternative.

BTCPay detailed the deployment change in its Oct. 5 announcement accompanying model 2.4.5. The official GitHub launch web page information the software program launch on Oct. 6. For present installations, the related set off is their next Docker setup or update.

Related Reading

Malicious bots are actively probing exposed Bitcoin payment servers to steal master administrative keys


The change issues to Docker operators who depend on Tor, together with access by means of their server’s onion deal with, however beforehand obtained it by means of the core BTCPay Server fragment. Fragments are the configuration parts used to assemble the Docker stack.

BTCPay advises directors to evaluate the deployment modifications earlier than updating. After updating to 2.4.5, its instruction for enabling Tor is:

sudo btcpay-fragments add opt-add-tor

Tor stays supported, and BTCPay says present information stays within the present Tor volumes. That preserves saved information; continued onion access nonetheless depends upon together with and working Tor within the deployment.

Related Reading

Bitcoin Core’s privacy fix reaches v32 code while the v31 patch remains open


BTCPay Server documentation describes the optional Tor fragment opt-add-tor as including hidden providers and chosen onion connectivity. Operators can examine configuration utilizing btcpay-fragments present, which doesn’t change configuration and studies saved further and excluded fragments alongside the efficient fragments from the final generated manifest.

Fragment-changing instructions require root and reapply setup instantly.

BTCPay Docker maintenance flow showing Tor configuration inspection, the post-update opt-add-tor command, preserved Tor volumes and the distinction between data retention and uninterrupted onion access.

Private providers want separate exceptions

The 2.4.5 release notes additionally establish a breaking change for outbound HTTP requests: private-network locations are blocked by default for Lightning connections, LNURL requests, bill notification URLs and webhooks. The restriction is meant to stop server-side request forgery, or SSRF.

With that safety enabled, operators deliberately utilizing personal providers must enable the wanted locations by means of ssrfexceptions.

BTCPay’s operator guide says to restart the appliance and train the affected integration after altering the setting.

Related Reading

Lightning Labs discloses critical bug marking canceled invoices paid, risking free product delivery


The publish BTCPay Docker users must opt into Tor at their next update to keep onion access appeared first on CryptoSlate.

Similar Posts