Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A self-custodial Lightning node on Linux is a two-service stack: a synchronized Bitcoin Core node and one Lightning implementation such as LND or Core Lightning (CLN). The practical default is a 64-bit Ubuntu Server installation on a reliable SSD, with Bitcoin Core 31.0 or a newer release verified at installation time, LND or CLN, Tor or carefully firewalled clearnet networking, encrypted tested backups, and only a small amount of bitcoin kept online.

This guide uses Bitcoin Core and LND for the main walkthrough, then shows the important differences with CLN. It is an operations project as much as an installation: wallet recovery, channel liquidity, updates, monitoring and power-loss procedures matter as much as the first command.

What a Lightning node is—and is not

Bitcoin Core validates and relays the Bitcoin blockchain, provides the on-chain wallet and exposes authenticated RPC and ZeroMQ interfaces. A Lightning daemon uses that backend to create invoices, maintain payment channels and route payments. A Lightning wallet is therefore different from a custodial Lightning account, where a company controls the keys.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can run a private spending node with a few channels and no public routing ambition. A public routing node needs substantially more uptime, liquidity planning and operational attention. Running a node does not make payments automatically private, profitable, instant in every circumstance or risk-free. Lightning is a hot-wallet system: keep only an amount you can afford to keep online.

#1 Best Overall
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

Choose hardware, Linux and a backend

Practical baseline

  • 64-bit CPU and a supported 64-bit Linux distribution.
  • 4 GB RAM is a documented CLN minimum; 8 GB is a more comfortable target for a full installation.
  • A 1 TB or larger SSD gives a current full Bitcoin Core node growth headroom. CLN documents approximately 500 GB for a full backend, but storage requirements increase over time; its pruned or remote-backend baseline is substantially smaller. See CLN’s hardware guidance.
  • Wired networking, a UPS or graceful-shutdown capability, and separate backup storage.
  • Do not put the primary blockchain and Lightning databases on a fragile SD card.

Home server or VPS?

Home server VPS
Physical control, easy local hardware-wallet access and usually no monthly server fee. Data-center uptime, public networking and simpler inbound reachability.
May face carrier-grade NAT, changing addresses, outages and limited upload bandwidth. Provider snapshots, host access, disk-I/O limits and provider failure become part of your threat model.

A home server suits operators prioritizing physical control. A VPS suits those prioritizing uptime and reachability, but large balances require a clear provider and encrypted-backup risk plan.

Full versus pruned Bitcoin Core

A full node is the least surprising choice: it preserves historical data and works with the widest range of tools. Pruning reduces disk use, but Bitcoin.org’s full-node documentation notes that pruning is incompatible with txindex and rescan operations and disables some wallet functions; implementation support also varies. See the pruning documentation and CLN’s qualification at docs.corelightning.org. A remote backend saves local storage but adds dependency on another machine.

Choose LND or Core Lightning

LND Core Lightning
Interface lncli, gRPC and REST lightning-cli, Unix-socket JSON-RPC and plugins
Installation Official binaries or source Official binaries, Docker or source
Backup model Seed plus channel-backup workflow Implementation-specific wallet and database procedures
Best fit Integrated daemon and familiar command-line/API workflow Advanced operators who want modular plugins and Unix JSON-RPC

Use one implementation per data directory. LND 0.21-beta was announced on June 11, 2026 (release announcement); CLN’s current documented line is 26.06 (installation documentation). Check the project’s release page, signature and checksum immediately before downloading rather than relying on a permanently hard-coded version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install and synchronize Bitcoin Core

Use official Bitcoin Core binaries and verify their signatures and checksums. The official release page, rather than a stale package label, is the version authority: Bitcoin Core 31.0. Distribution packages and random PPAs may lag or use different service layouts.

  1. Create a dedicated account and data directories:

    sudo useradd --system --home /var/lib/bitcoin --create-home --shell /usr/sbin/nologin bitcoin
    sudo install -d -o bitcoin -g bitcoin -m 0750 /mnt/bitcoin
    sudo install -d -o bitcoin -g bitcoin -m 0750 /var/lib/bitcoin
  2. Install the verified bitcoind and bitcoin-cli binaries in a controlled location such as /usr/local/bin. Mount the SSD at /mnt/bitcoin and confirm ownership.

  3. Create a configuration containing local-only RPC and ZeroMQ endpoints:

    server=1
    daemon=0
    txindex=1
    
    zmqpubrawblock=tcp://127.0.0.1:28332
    zmqpubrawtx=tcp://127.0.0.1:28333
    
    rpcbind=127.0.0.1
    rpcallowip=127.0.0.1

    txindex=1 costs storage and synchronization time. Verify whether your selected Lightning release and tools require it before enabling it. Never expose Bitcoin RPC to the public internet.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
    Rank #2
    CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (4GB RAM)
    • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (4GB RAM)
    • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
    • CanaKit Turbine Black Case for the Raspberry Pi 5
    • CanaKit Low Noise Bearing System Fan
    • CanaKit Mega Heat Sink - Black Anodized
  4. Run Bitcoin Core under systemd:

    [Unit]
    Description=Bitcoin Core
    After=network-online.target
    Wants=network-online.target
    
    [Service]
    User=bitcoin
    Group=bitcoin
    ExecStart=/usr/local/bin/bitcoind -datadir=/mnt/bitcoin
    ExecStop=/usr/local/bin/bitcoin-cli -datadir=/mnt/bitcoin stop
    Restart=on-failure
    RestartSec=10
    TimeoutStopSec=300
    LimitNOFILE=65536
    
    [Install]
    WantedBy=multi-user.target
    sudo systemctl daemon-reload
    sudo systemctl enable --now bitcoind
    sudo systemctl status bitcoind
    sudo journalctl -u bitcoind -f
  5. Wait for initial block download. Check:

    bitcoin-cli -datadir=/mnt/bitcoin getblockchaininfo
    bitcoin-cli -datadir=/mnt/bitcoin getnetworkinfo
    bitcoin-cli -datadir=/mnt/bitcoin getrpcinfo

    In getblockchaininfo, watch initial_block_download, blocks, headers, verificationprogress, pruned and warnings. Do not begin mainnet Lightning operations until the backend is synchronized and healthy.

Install LND and connect it to Bitcoin Core

LND’s Linux documentation covers official binaries, ~/.lnd, Bitcoin Core integration and wallet initialization (LND installation guide; builder guide).

  1. Check the architecture and download the matching, signed release:

    uname -m

    Verify the checksum and signing key before installing lnd and lncli.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Create a private configuration directory:

    mkdir -p "$HOME/.lnd"
    chmod 700 "$HOME/.lnd"
  3. Use a release-appropriate template, not a blind copy:

    [Application Options]
    debuglevel=info
    listen=127.0.0.1:9735
    rpclisten=127.0.0.1:10009
    restlisten=127.0.0.1:8080
    
    [Bitcoin]
    bitcoin.active=1
    bitcoin.mainnet=1
    bitcoin.node=bitcoind
    
    [Bitcoind]
    bitcoind.rpchost=127.0.0.1:8332
    bitcoind.rpcuser=REPLACE_WITH_RPC_USER
    bitcoind.rpcpass=REPLACE_WITH_RPC_PASSWORD
    bitcoind.zmqpubrawblock=tcp://127.0.0.1:28332
    bitcoind.zmqpubrawtx=tcp://127.0.0.1:28333

    Option names, TLS behavior and defaults can change; check the documentation for the exact release. LND requires a Bitcoin Core build with ZMQ support.

  4. Start LND once interactively, then create the wallet from another terminal:

    Rank #3
    CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
    • CanaKit Raspberry Pi 5 Essentials Starter Kit
    lnd
    lncli --network=mainnet create

    The create prompts vary by release. Record the generated 24-word cipher seed offline; never put it in shell history, screenshots, cloud notes or an unencrypted server backup.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  5. After creation, verify the daemon:

    lncli --network=mainnet getinfo
    lncli --network=mainnet walletbalance
    lncli --network=mainnet channelbalance

Run LND under systemd

[Unit]
Description=LND Lightning Node
After=bitcoind.service
Requires=bitcoind.service

[Service]
User=lightning
Group=lightning
ExecStart=/usr/local/bin/lnd
ExecStop=/bin/kill -SIGINT $MAINPID
Restart=on-failure
RestartSec=10
LimitNOFILE=65536
TimeoutStopSec=300

[Install]
WantedBy=multi-user.target

A dedicated lightning user improves compartmentalization, but you must grant it the correct RPC credentials and paths. Running both daemons as one user is simpler, not as isolated.

Install Core Lightning instead

CLN supports Linux and macOS and offers binary, Docker and source paths (official installation guide). Its native API is JSON-RPC over a Unix-domain socket. Typical commands are:

lightning-cli getinfo
lightning-cli newaddr
lightning-cli listpeers
lightning-cli listfunds
lightning-cli fundchannel PEER_NODE_ID AMOUNT_SATOSHIS

The official Docker example uses elementsproject/lightningd:latest and ports 9735 and 9835 (source), but production deployments should pin an image tag, use persistent volumes, restrict RPC, set a restart policy, add health checks and document rollback and secret handling. Do not treat CLN wallet or channel backups as interchangeable with LND’s.

Network the node safely

Firewall and ports

  • Bitcoin P2P: TCP 8333.
  • Lightning P2P: TCP 9735.
  • Bitcoin RPC 8332, LND gRPC 10009 and LND REST 8080: keep local or behind a private network.
  • CLN API ports depend on the plugin and configuration.
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow 8333/tcp
sudo ufw allow 9735/tcp
sudo ufw enable

Open 9735 only when you want ordinary clearnet inbound peers. Router forwarding, VPS security groups, host firewall rules and carrier-grade NAT all affect reachability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Tor, clearnet or hybrid

Tor avoids publishing a residential IP and often works where forwarding is impossible, but adds a dependency and troubleshooting complexity. Clearnet is simpler when you have a stable public address and forwarding. A hybrid setup can improve reachability while increasing exposed surface. Never publish RPC, REST, gRPC or administration interfaces through a public Tor service without strong access controls.

Confirm identity and health

Check that the daemon is on mainnet, the backend height is current, the identity public key is stable, the advertised address is intentional and no management endpoint is public:

Rank #4
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
  • Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized
lncli --network=mainnet getinfo

For CLN, use lightning-cli getinfo. Before accepting real funds, make a small invoice and pay it from a separate wallet after synchronization and backup.

Fund the node and open a first channel

On-chain balance versus Lightning liquidity

  • Channel capacity: total funds on both sides.
  • Local balance: your current outbound amount.
  • Remote balance: inbound amount available to receive.
  • Spendable balance: usable after reserves, confirmations and pending states.

Generate an address and send a small amount:

lncli --network=mainnet newaddress p2wkh
lncli --network=mainnet walletbalance

CLN uses lightning-cli newaddr and lightning-cli listfunds. Channel funding is an on-chain transaction; confirmation requirements and usability depend on channel state and peer policy.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Select a peer deliberately

Evaluate uptime, responsiveness, useful connectivity, fee policy, network diversity, existing capacity, node type and what happens if the peer disappears. Avoid spending your whole balance on a first channel. On-chain opening and closing fees can be significant when Bitcoin fees are high.

LND example

lncli --network=mainnet connect PEER_PUBKEY@PEER_HOST:9735
lncli --network=mainnet openchannel 
  --node_key=PEER_PUBKEY 
  --local_amt=100000

Check flags against your installed LND release.

CLN example

lightning-cli connect PEER_NODE_ID PEER_HOST 9735
lightning-cli fundchannel PEER_NODE_ID 100000

A public channel advertises gossip information; a private channel does not provide the same public routing visibility. Neither is a guaranteed route for every payment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Obtain inbound liquidity

Opening a channel normally puts funds on your side, creating outbound liquidity. To receive payments, you need funds on the remote side. Options include another node opening a channel to you, purchasing inbound liquidity, circular rebalancing and receiving through existing channels. Services can introduce fees, uptime and counterparty or custody risks; rented inbound is not the same as owning capital.

Backups and recovery

LND recovery material

The seed is essential, but it does not necessarily restore the complete state of open channels. Keep current static or multi-channel backups such as channel.backup, and understand restorechanbackup, watchtowers and force-close recovery in the release documentation. Do not copy a live database while the daemon is writing and call that an application-consistent backup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CLN recovery

CLN has separate wallet and database procedures. Its configuration documentation describes an SQLite backup database path (CLN configuration); follow the project’s consistency and restoration instructions.

Best Value
CanaKit Raspberry Pi 5 Essentials Starter Kit (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 32GB EVO+ Micro SD Card pre-loaded with 64-bit Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit 45W PD Power Supply for the Raspberry Pi 5
  • Display Cable - 6 foot (Supports up to 4K 60p)

Minimum backup policy

  • One offline seed backup.
  • Encrypted, current channel-backup copies.
  • A second physical location.
  • Restricted permissions and no unencrypted cloud synchronization.
  • A documented restore test, performed before an emergency.
  • A backup before upgrades and major channel operations.

Operate and maintain the node

systemctl status bitcoind
systemctl status lnd
journalctl -u bitcoind -f
journalctl -u lnd -f
bitcoin-cli getblockchaininfo
lncli --network=mainnet getinfo
lncli --network=mainnet listchannels
lncli --network=mainnet pendingchannels
lncli --network=mainnet walletbalance
lncli --network=mainnet channelbalance

For CLN, use lightning-cli getinfo, listpeers, listchannels and listfunds. Apply Linux, Bitcoin Core and Lightning security updates; read migration notes; monitor disk space, clock synchronization, peer count and restart loops; and review fee and liquidity policy. Do not enable automatic major-version upgrades without a tested rollback and backup.

Troubleshoot common failures

Bitcoin Core will not finish syncing

Check storage, drive health, clock, memory, network restrictions and logs before deleting data:

bitcoin-cli getblockchaininfo
df -h
free -h
journalctl -u bitcoind --since "1 hour ago"

LND cannot connect to Bitcoin Core

Confirm Bitcoin Core is running and synchronized, RPC credentials and bind addresses match, ZMQ ports are identical, both daemons use the same network and the LND user can reach the RPC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Wallet opens but channels are missing

Check the data directory and network, then distinguish seed recovery from channel-state recovery. A seed restored without current channel backups may recover on-chain wallet funds while leaving channel state unavailable.

Port 9735 is unreachable

sudo ss -lntp | grep 9735
sudo ufw status verbose

Then inspect router forwarding, VPS security groups, carrier-grade NAT, loopback-only listening and stale advertised addresses.

Outbound exists but receiving fails

Your channels may be full on your side. You need inbound liquidity, not simply more bitcoin in the on-chain wallet.

Unexpected closure or power loss

Cooperative close, force close, pending close and sweep transactions have different timelines. Keep a journaling filesystem, shut down cleanly, use a UPS where practical and never remove power while a daemon is writing. If you change from LND to CLN, treat it as a migration: close or recover channels, create the new wallet, rebuild peers and reconfigure monitoring and backups. One implementation cannot simply use another’s data directory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When an appliance or managed platform makes sense

Umbrel, StartOS, RaspiBlitz and BTCPay Server can reduce command-line work, but they add a management layer and may abstract systemd units, paths and upgrades. Umbrel’s Core Lightning app lists umbrelOS 0.5 or later (app page; Umbrel). BTCPay Server is aimed at merchants who need payment processing (official site). These options do not remove the need for seed security, channel backups or recovery tests.

Start conservatively

Practice on signet or regtest first, then use a small mainnet balance. A successful installation is only the beginning: the node must remain synchronized, backed up, monitored and recoverable. Routing fees are uncertain and can be outweighed by rebalancing, hardware, hosting and on-chain costs, so do not treat a Lightning node as passive income.

Quick Recap

Bestseller No. 1
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$259.95
Bestseller No. 2
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (4GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (4GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (4GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$209.99
Bestseller No. 3
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
CanaKit Raspberry Pi 5 Essentials Starter Kit (4GB RAM)
CanaKit Raspberry Pi 5 Essentials Starter Kit
$189.99
Bestseller No. 4
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
CanaKit Raspberry Pi 5 16GB Starter Kit PRO - Turbine Black (128GB Edition) (16GB RAM)
Includes Raspberry Pi 5 16GB with 2.4Ghz 64-bit quad-core CPU (16GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$419.99
Bestseller No. 5
CanaKit Raspberry Pi 5 Essentials Starter Kit (8GB RAM)
CanaKit Raspberry Pi 5 Essentials Starter Kit (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); Includes 32GB EVO+ Micro SD Card pre-loaded with 64-bit Pi OS, USB MicroSD Card Reader
$229.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.