Operators running the Bitcoin payment software BTCPay Server through its standard Docker deployment must explicitly select Tor at their next setup or update if they want to retain onion access. The change removes Tor from the automatically included components, making it an optional configuration choice for administrators.

BTCPay announced the deployment change on Oct. 5 alongside version 2.4.5. The GitHub release page records the software release on Oct. 6. For existing Docker installations, the requirement applies the next time they perform a setup or update.

The shift matters to Docker operators who rely on Tor—including access via an onion address—because the service is no longer bundled by default. Instead, administrators must add the Tor fragment manually. Fragments are the configuration components that assemble the Docker stack.

BTCPay advises administrators to review the deployment changes before upgrading. After updating to 2.4.5, the command to enable Tor is:

sudo btcpay-fragments add opt-add-tor

Tor remains supported, and BTCPay states that existing data will stay in the current Tor volumes, preserving stored information. Continued onion access, however, still depends on including and running Tor in the deployment.

BTCPay Server documentation describes the optional Tor fragment opt-add-tor as adding hidden services and onion connectivity. Operators can inspect the configuration using btcpay-fragments show, which lists saved, excluded, and effective fragments without altering them.

Fragment-changing commands require root and reapply setup immediately.

Private Services Need Separate Exceptions

The 2.4.5 release notes also introduce a breaking change for outbound HTTP requests: private‑network destinations are blocked by default for Lightning connections, LNURL requests, invoice notification URLs and webhooks. This restriction aims to prevent server‑side request forgery (SSRF).

When the protection is enabled, operators who intentionally use private services must allow the required destinations via the ssrfexceptions setting.

BTCPay’s operator guide recommends restarting the application and testing the affected integration after modifying the setting.

Also Read

Source link

Exit mobile version