Creating a Bitcoin Lightning node on Linux means operating two connected services: Bitcoin Core, which validates and relays the Bitcoin blockchain, and a Lightning implementation such as LND or Core Lightning (CLN). The practical default is a 64-bit Ubuntu Server installation on a reliable SSD, with Bitcoin Core fully synchronized before you create a Lightning wallet or channel.
This guide uses Bitcoin Core and LND for the main walkthrough, then explains the CLN differences. It covers installation, RPC and ZeroMQ, systemd, Tor and firewalls, funding, channels, liquidity, backups, monitoring and recovery. A Lightning node is a hot-wallet system: keep only an amount you can afford to have online.
What a Lightning node does
A Bitcoin full node and a Lightning node are different. Bitcoin Core validates the on-chain network; LND or CLN uses that backend to create and manage off-chain payment channels. A Lightning wallet controls keys and channel funds, while a custodial Lightning account leaves key control with a service.
You can run a private spending node with a few channels. You do not have to become a public routing business, accept inbound channels from strangers or expect routing income. Payments are not automatically private, profitable, instant in every circumstance or risk-free.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
- Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
- CanaKit Turbine Black Case for the Raspberry Pi 5
- CanaKit Low Noise Bearing System Fan
- Mega Heat Sink - Black Anodized
Choose hardware, Linux and a backend
Practical baseline
- 64-bit CPU and a supported Linux distribution.
- At least 8 GB RAM is a comfortable target; CLN documents 4 GB as a minimum baseline.
- A 1 TB or larger SSD gives a full node growth headroom. CLN documents approximately 500 GB for a Bitcoin Core full node, but disk use grows over time; a pruned or remote backend needs substantially less local storage. See CLN’s hardware guidance.
- Wired networking, a UPS or graceful-shutdown plan, and separate backup storage.
- Do not put the primary blockchain directory on an unreliable SD card or removable flash drive.
Home server or VPS
| Choice | Advantages | Trade-offs |
|---|---|---|
| Home server | Physical control, no recurring hosting fee and easier local hardware-wallet integration. | Power outages, changing IP addresses, poor upload speeds and carrier-grade NAT can prevent inbound connections. |
| VPS | Data-center uptime, public networking and convenient monitoring. | The provider controls the host; snapshots may expose wallet data, and disk I/O, bandwidth and cryptocurrency-workload policies vary. |
Full or pruned Bitcoin Core
A full node is the least surprising choice for Lightning integrations and future tooling. Pruning reduces storage, but Bitcoin Core pruning has limitations: it is incompatible with txindex and some rescans and wallet operations. CLN describes pruning as only partially supported. Use it only after checking the requirements of your chosen implementation and recovery workflow. Bitcoin Core documents pruning and its 550 MiB minimum setting at bitcoin.org’s full-node guide.
Choose LND or Core Lightning
| Criterion | LND | Core Lightning |
|---|---|---|
| Interface | lncli, gRPC and REST |
lightning-cli, Unix-socket JSON-RPC and plugins |
| Installation | Official binaries and source paths | Official binaries, Docker and source |
| Best fit | Operators wanting an integrated daemon and familiar command-line client | Advanced operators wanting modularity and plugins |
| Backups | Seed plus implementation-specific channel backups | Implementation-specific wallet and database procedures |
Do not install both implementations into the same data directory. The versions identified in current project material include Bitcoin Core 31.0, LND 0.21-beta (announced June 11, 2026) and the CLN 26.06 release line. Verify the current release, architecture, checksum and upgrade notes immediately before installation: Bitcoin Core releases, LND’s announcement and CLN installation documentation.
Install and synchronize Bitcoin Core
1. Verify and install the binaries
Download Bitcoin Core from the project’s release page, verify the signed checksum and install the binaries into a controlled path such as /usr/local/bin. Avoid treating an unverified PPA or app-store package as the default; distribution packages may lag or use different service conventions.
uname -m
# Download the matching official archive, then verify its signature and checksum.
sudo install -m 0755 bin/bitcoind bin/bitcoin-cli /usr/local/bin/
2. Create a dedicated user and data directories
sudo useradd --system --home /var/lib/bitcoin --create-home --shell /usr/sbin/nologin bitcoin
sudo install -d -o bitcoin -g bitcoin -m 0750 /mnt/bitcoin
sudo install -d -o bitcoin -g bitcoin -m 0750 /var/lib/bitcoin
sudo install -d -o bitcoin -g bitcoin -m 0700 /var/lib/bitcoin-backups
Mount the SSD at /mnt/bitcoin before starting the service and confirm ownership with ls -ld.
Recommended Free Tools
3. Configure Bitcoin Core for local Lightning access
server=1
daemon=0
txindex=1
zmqpubrawblock=tcp://127.0.0.1:28332
zmqpubrawtx=tcp://127.0.0.1:28333
rpcbind=127.0.0.1
rpcallowip=127.0.0.1
This is a template, not a universal requirement. LND uses ZeroMQ with Bitcoin Core and requires a build with ZMQ support; see the LND installation documentation. Keep RPC on loopback. Confirm whether your LND release and workflow require txindex=1; it increases storage and synchronization cost.
4. Run Bitcoin Core with systemd
[Unit]
Description=Bitcoin Core
After=network-online.target
Wants=network-online.target
[Service]
User=bitcoin
Group=bitcoin
ExecStart=/usr/local/bin/bitcoind -datadir=/mnt/bitcoin
ExecStop=/usr/local/bin/bitcoin-cli -datadir=/mnt/bitcoin stop
Restart=on-failure
RestartSec=10
TimeoutStopSec=300
LimitNOFILE=65536
[Install]
WantedBy=multi-user.target
Save as /etc/systemd/system/bitcoind.service, adjust paths for your distribution, then run:
Rank #2
- Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (4GB RAM)
- Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
- CanaKit Turbine Black Case for the Raspberry Pi 5
- CanaKit Low Noise Bearing System Fan
- CanaKit Mega Heat Sink - Black Anodized
sudo systemctl daemon-reload
sudo systemctl enable --now bitcoind
sudo systemctl status bitcoind
sudo journalctl -u bitcoind -f
5. Wait for initial block download
bitcoin-cli -datadir=/mnt/bitcoin getblockchaininfo
bitcoin-cli -datadir=/mnt/bitcoin getnetworkinfo
bitcoin-cli -datadir=/mnt/bitcoin getrpcinfo
In getblockchaininfo, monitor initial_block_download, blocks, headers, verificationprogress, pruned and warnings. Do not start mainnet Lightning operations until the backend is synchronized and healthy.
Install LND
Download the matching release
Check the architecture with uname -m, download the matching official LND archive, verify its signing key and checksum, and install lnd and lncli. LND’s Linux instructions are at GitHub and its builder guide at docs.lightning.engineering.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallsudo install -m 0755 lnd lncli /usr/local/bin/
mkdir -p "$HOME/.lnd"
chmod 700 "$HOME/.lnd"
Create a mainnet configuration
[Application Options]
debuglevel=info
listen=127.0.0.1:9735
rpclisten=127.0.0.1:10009
restlisten=127.0.0.1:8080
[Bitcoin]
bitcoin.active=1
bitcoin.mainnet=1
bitcoin.node=bitcoind
[Bitcoind]
bitcoind.rpchost=127.0.0.1:8332
bitcoind.rpcuser=REPLACE_WITH_RPC_USER
bitcoind.rpcpass=REPLACE_WITH_RPC_PASSWORD
bitcoind.zmqpubrawblock=tcp://127.0.0.1:28332
bitcoind.zmqpubrawtx=tcp://127.0.0.1:28333
Release-specific option names, defaults and TLS behavior can change. Check the installed version’s documentation before copying this template. Use a separate lightning system user for stronger compartmentalization, or document and deliberately accept the simpler shared-user arrangement.
Run LND under systemd
[Unit]
Description=LND Lightning Node
After=bitcoind.service
Requires=bitcoind.service
[Service]
User=lightning
Group=lightning
ExecStart=/usr/local/bin/lnd
ExecStop=/bin/kill -SIGINT $MAINPID
Restart=on-failure
RestartSec=10
LimitNOFILE=65536
TimeoutStopSec=300
[Install]
WantedBy=multi-user.target
Save as /etc/systemd/system/lnd.service, ensure the lightning user can read its configuration and reach Bitcoin Core RPC, then run:
sudo systemctl daemon-reload
sudo systemctl enable --now lnd
sudo journalctl -u lnd -f
Create and protect the Lightning wallet
In another terminal, initialize the wallet:
lncli --network=mainnet create
The command is interactive and prompts vary by release. LND generates a 24-word cipher seed. Write it down offline and protect it from fire, theft and unauthorized access. Never put it in shell history, a screenshot folder, an unencrypted cloud note or an ordinary server backup. The seed is essential recovery material, but it is not necessarily a complete record of every open channel; preserve the channel-backup files described below.
After creation, check the daemon:
lncli --network=mainnet getinfo
lncli --network=mainnet walletbalance
lncli --network=mainnet channelbalance
Confirm identity and network health
Verify that the node reports mainnet, a current block height, a stable identity public key and the expected listening addresses. Check that Bitcoin Core is synchronized, peers are present and RPC, REST and gRPC are not publicly reachable. Before real funds, create a small invoice and pay it from a separate wallet after making a backup.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteRank #3
- CanaKit Raspberry Pi 5 Essentials Starter Kit
Configure Tor, clearnet and the firewall
Public ports
| Service | Typical port | Exposure |
|---|---|---|
| Bitcoin P2P | TCP 8333 | Public when you want ordinary Bitcoin peer connectivity |
| Lightning P2P | TCP 9735 | Public for clearnet inbound peers; not required for Tor-only operation |
| Bitcoin RPC | TCP 8332 | Keep private |
| LND gRPC | TCP 10009 | Keep private or place behind a tightly controlled private network |
| LND REST | TCP 8080 | Keep private |
Basic UFW policy
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow 8333/tcp
sudo ufw allow 9735/tcp
sudo ufw enable
If you use Tor-only connectivity, do not open clearnet port forwarding merely because the daemon has a Lightning port. Tor avoids publishing a residential IP and can bypass carrier-grade NAT, but adds another dependency to troubleshoot. A hybrid Tor/clearnet setup can improve reachability while increasing the networking surface. Never publish RPC, REST, gRPC or administration interfaces through a public address without strong authentication and access controls.
Fund the node
On-chain balance, channel capacity, local balance, remote balance, spendable balance and pending channel funds are different quantities. Generate an address and send a small amount:
lncli --network=mainnet newaddress p2wkh
lncli --network=mainnet walletbalance
For CLN, use lightning-cli newaddr and lightning-cli listfunds. A channel is funded by an on-chain transaction; it may require confirmations before normal use, depending on channel state and peer policy.
Connect to a peer and open a channel
Select a peer deliberately
- Check uptime, responsiveness and network diversity.
- Consider the peer’s fee policy, existing connectivity and likely payment routes.
- Prefer a modest first channel over committing your entire Bitcoin balance.
- Account for on-chain fees when opening, closing or rebalancing channels.
- Do not assume a popular node is currently reliable or suitable without checking it yourself.
LND example
lncli --network=mainnet connect PEER_PUBKEY@PEER_HOST:9735
lncli --network=mainnet openchannel
--node_key=PEER_PUBKEY
--local_amt=100000
Check the installed LND version for exact flags. A channel can be public or private, and confirmation state determines when it is usable.
CLN example
lightning-cli connect PEER_NODE_ID PEER_HOST 9735
lightning-cli fundchannel PEER_NODE_ID 100000
CLN uses a Unix-domain JSON-RPC socket and its own wallet and channel procedures. Its operational commands include getinfo, listpeers, listchannels and listfunds; see the CLN beginner’s guide.
Obtain inbound liquidity
Opening a channel normally places funds on your side, creating outbound liquidity. To receive Lightning payments, you need funds on the remote side: inbound liquidity. Options include having another node open a channel to you, purchasing inbound capacity, circular rebalancing or receiving payments through existing channels. Liquidity services vary in price, uptime, refund terms and counterparty risk; rented capacity is not the same as owning liquid capital.
Rank #4
- Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM)
- Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
- CanaKit Turbine Black Case for the Raspberry Pi 5
- CanaKit Low Noise Bearing System Fan
- Mega Heat Sink - Black Anodized
Back up and recover safely
LND recovery material
- Keep the 24-word wallet seed offline.
- Maintain current static channel backups, including multi-channel backups where applicable.
- Understand
restorechanbackup, force-close recovery and sweep timing before you need them. - Consider watchtowers or an equivalent response plan for prolonged outages.
Do not copy a live database while the daemon is writing and assume it is application-consistent. Follow release-specific backup procedures in the LND documentation.
CLN recovery material
CLN has separate wallet and database procedures. Its configuration supports an SQLite backup database path, but you must understand consistency and restoration before relying on it; see CLN configuration documentation.
Backup policy
- Keep one offline seed copy and encrypted channel-backup copies in a second physical location.
- Use restrictive permissions and never synchronize unencrypted secrets to a cloud account.
- Back up before upgrades and major channel operations.
- Perform a documented restore test on a separate system.
Operate and maintain the node
systemctl status bitcoind
systemctl status lnd
journalctl -u bitcoind -f
journalctl -u lnd -f
bitcoin-cli getblockchaininfo
lncli --network=mainnet getinfo
lncli --network=mainnet listchannels
lncli --network=mainnet pendingchannels
lncli --network=mainnet walletbalance
lncli --network=mainnet channelbalance
Apply Linux, Bitcoin Core and Lightning security updates; read migration notes; watch disk space, clock synchronization, peer count, channel health and restart loops. Review fee and liquidity policy as conditions change. Do not enable automatic major-version upgrades without a tested backup and rollback plan.
Troubleshoot common failures
Bitcoin Core will not finish syncing
Check storage, drive health, memory, clock, network restrictions and logs before deleting data:
bitcoin-cli getblockchaininfo
df -h
free -h
journalctl -u bitcoind --since "1 hour ago"
LND cannot connect to Bitcoin Core
Confirm Bitcoin Core is running and synchronized, RPC credentials match, RPC is bound to the expected interface, ZMQ endpoints match, permissions are correct and both services use the same network.
Channels disappear after wallet recovery
Restoring a seed can restore wallet keys without restoring complete channel state. Check the correct data directory, network and current channel-backup files; database corruption or a stale backup may require force-close recovery.
Best Value
- Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
- Includes 32GB EVO+ Micro SD Card pre-loaded with 64-bit Pi OS, USB MicroSD Card Reader
- CanaKit Turbine Black Case for the Raspberry Pi 5
- CanaKit 45W PD Power Supply for the Raspberry Pi 5
- Display Cable - 6 foot (Supports up to 4K 60p)
Port 9735 is unreachable
sudo ss -lntp | grep 9735
sudo ufw status verbose
Then check router forwarding, VPS security groups, carrier-grade NAT, the daemon’s listen address and any stale advertised address.
You cannot receive payments
More on-chain funds do not automatically create inbound liquidity. Inspect channel balances and obtain remote-side capacity.
A channel closes unexpectedly or the server loses power
Distinguish cooperative close, force close, pending close and sweep transactions. Use a journaling filesystem, graceful shutdown, a UPS where practical and current backups. Never remove power or storage while the daemon is writing.
Changing from LND to CLN
This is a migration project, not a configuration switch. Close or migrate channels, recover funds, create a new wallet, rebuild peer relationships and re-create monitoring and backup procedures. Never point one implementation at the other’s data directory.
Alternatives to manual installation
Umbrel, StartOS, RaspiBlitz, BTCPay Server and Docker can reduce setup work. Umbrel lists Core Lightning for umbrelOS 0.5 or later at its official app page. CLN’s Docker example is documented at docs.corelightning.org; for production, pin an image tag, use persistent volumes, restrict RPC, manage secrets, add health checks and maintain a rollback plan rather than using latest blindly. These platforms trade some conventional Linux transparency for convenience.
For hardware, prioritize a reliable SSD, 8 GB or more RAM, wired Ethernet, replaceable storage and low idle power. For a VPS, assess guaranteed SSD I/O, transfer limits, snapshots, private networking and provider terms. A provider snapshot is not a substitute for an encrypted wallet backup.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




