Skip to main content
£0.00 0

Basket

No products in the basket.

ASIC mining articles and advice

Bitcoin Core Unix Permissions and Process Isolation

Bitcoin Core process isolation guide for dedicated users, data and configuration permissions, RPC-client groups, service managers and safe backups.

Bitcoin Core process isolation guide cover

This guide explains Bitcoin Core process isolation in plain English. It focuses on what the subject is, why it matters and what a beginner should remember.

TL;DR

  • What it is: Bitcoin Core’s official service examples assume a dedicated bitcoin user and group, controlled ownership of the data directory and configuration, and explicit startup management through systemd, OpenRC, Upstart or other platform facilities.
  • Why it matters: Process isolation is not one permission bit; it is the combined boundary around identity, files, sockets, startup and backups. A dedicated Bitcoin Core account with minimal paths and reviewed client access materially reduces the blast radius of adjacent-service compromise.
  • Current position: Bitcoin Core’s official service examples assume a dedicated bitcoin user and group, controlled ownership of the data directory and configuration, and explicit startup management through systemd, OpenRC, Upstart or other platform facilities.

Bitcoin Core process isolation in simple English

Bitcoin Core process isolation: Backups, core dumps, support bundles and snapshots can bypass live file permissions. Exclude RPC cookies and redact secrets.

Simple example

A node operator is checking Bitcoin Core process isolation. Disable or tightly control core dumps when process memory could contain keys or credentials. Wallet files and RPC credentials are sensitive even when balances are public.

Key terms in plain English

Bitcoin Core:
Widely used software that validates Bitcoin and can provide wallet, network and operator tools.
RPC:
A command that software sends to a node to request information or a local action.
Node:
A computer running Bitcoin software that checks data and communicates with other peers.

Dedicated service identity

Run the daemon under a non-login account that does not own unrelated applications. The user needs access to its binary, configuration, data, PID and runtime paths, not a general home directory or deployment credentials. A shared web-server account defeats the containment expected from a separate process.

Data and configuration permissions

The 0.12 guidance advised that configuration and data be readable only by the bitcoin user and its intentional group. Wallet files and RPC credentials are sensitive even when balances are public. Directory execute permission also controls traversal, so audit the full parent path rather than checking one file mode.

RPC client membership

Local clients can be authorised through access to the cookie or configuration credential. Group membership should represent a reviewed capability, not convenience. A monitoring reader may not need the same RPC surface as a pool coordinator or wallet, and modern deployments should use release-supported RPC permission separation where available.

Bitcoin Core process isolation technical diagram
RPC client membership: the fields, validation boundary and operational evidence that implementations need to agree.

Service-manager controls

A service unit should set the intended user, group, paths, restart policy and dependencies explicitly. Environment overrides and writable unit drop-ins can silently change binaries or arguments. Capture the effective configuration shown by the service manager, because reviewing only the vendor file can miss local modifications.

Writable-path and binary integrity

The daemon must not load a binary, shared library, configuration or wallet from a directory writable by a less-trusted account. Logs and PID files need bounded permissions without allowing symlink substitution. Package or release signatures establish provenance only before an attacker gains write access to the installed runtime.

Backups and crash artefacts

Backups, core dumps, support bundles and snapshots can bypass live file permissions. Exclude RPC cookies and redact secrets; encrypt wallet-bearing backups and test restoration under the dedicated identity. Disable or tightly control core dumps when process memory could contain keys or credentials.

Isolation audit

Enumerate the daemon process, supplementary groups, open files, listening sockets, writable directories and service-unit overrides. Attempt access from a web-service account and a monitoring account. Restart, rotate logs and restore a sanitised test backup, confirming no path becomes root-owned or broadly readable.

Frequently asked questions

What is the main point of Bitcoin Core process isolation?

Bitcoin Core process isolation: Backups, core dumps, support bundles and snapshots can bypass live file permissions.

For Bitcoin Core process isolation, what should a beginner know about dedicated service identity?

Run the daemon under a non-login account that does not own unrelated applications.

For Bitcoin Core process isolation, what should a beginner know about data and configuration permissions?

The 0.12 guidance advised that configuration and data be readable only by the bitcoin user and its intentional group.

For Bitcoin Core process isolation, what should a beginner know about rpc client membership?

Local clients can be authorised through access to the cookie or configuration credential.

Conclusion

Process isolation is not one permission bit; it is the combined boundary around identity, files, sockets, startup and backups. A dedicated Bitcoin Core account with minimal paths and reviewed client access materially reduces the blast radius of adjacent-service compromise.

Primary sources

Check the current specification status and the documentation for the exact implementation you operate before moving production funds or changing a mining node.

ASIC MINER PICKS

Recommended ASIC Mining Hardware

Compare three of our highest ranked ASIC miners currently available, with live product details and pricing.
Browse all ASIC miners
MORE MINING ADVICE

More ASIC Mining Articles

Read practical advice about choosing hardware, calculating electricity costs, setting up miners, hosting and maintenance.
MINER COMMUNITY

Join the ASIC Mining Discussion

Ask a question or share what has worked for you. Your experience may help another miner make a better decision.

Members can read and join the discussion

Log in to read comments from other miners. Create a free account if you would like to ask a question or share your experience.

Log in to read comments Register to join the discussion

Membership helps us protect the discussion from spam and keep answers useful.

ASIC MINING SUPPORT

Need Help Choosing an ASIC Miner?

Tell us what you want to mine, your electricity cost and where the machine will run. We can help you compare hardware, power requirements, hosting and repairs.
Contact our mining team
Browse ASIC miners