how to install frigate on raspibolt
frigate allows you to privately receive bitcoin silent payments.
installation
- check the latest release of frigate and download it, alongside with signatures.
$ VERSION="1.5.3" $ cd /tmp $ wget https://github.com/sparrowwallet/frigate/releases/download/$VERSION/frigate_${VERSION}_arm64.deb $ wget https://github.com/sparrowwallet/frigate/releases/download/$VERSION/frigate-$VERSION-manifest.txt $ wget https://github.com/sparrowwallet/frigate/releases/download/$VERSION/frigate-$VERSION-manifest.txt.asc - import craigraw’s key.
$ curl https://keybase.io/craigraw/pgp_keys.asc | gpg --import - check the signature.
$ sha256sum -b frigate_${VERSION}_arm64.deb > b690812a1c5212471038918694b6a3ca473631494ce2b75927218b3766b003bd *frigate_1.5.3_arm64.deb $ cat frigate-$VERSION-manifest.txt | grep arm64.deb > b690812a1c5212471038918694b6a3ca473631494ce2b75927218b3766b003bd *frigate_1.5.3_arm64.deb $ gpg --verify frigate-$VERSION-manifest.txt.asc frigate-$VERSION-manifest.txt > gpg: Signature made Sat 30 May 2026 10:30:31 AM CEST > gpg: using RSA key D4D0D3202FC06849A257B38DE94618334C674B40 > gpg: Good signature from "Craig Raw <craig@sparrowwallet.com>" [unknown] > gpg: Signature notation: manu=2,2.5+1.12,0,3 > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the owner. > Primary key fingerprint: D4D0 D320 2FC0 6849 A257 B38D E946 1833 4C67 4B40 - install.
$ sudo dpkg -i frigate_${VERSION}_arm64.deb - create the
frigateuser.$ sudo adduser --disabled-password --gecos "" frigate $ sudo adduser frigate bitcoin - create the data directory for the
frigateuser.$ sudo mkdir /data/frigate $ sudo chown -R frigate:frigate /data/frigate
reconfiguring electrs
we want to have all electrum requests going to frigate first, so we will redirect electrs to another port.
- open the configruation file.
$ sudo nano /data/electrs/electrs.conf - change the
electrum_rpc_addrport to 60001.# Electrs settings electrum_rpc_addr = "127.0.0.1:60001" db_dir = "/data/electrs/db" - restart electrs.
$ sudo systemctl restart electrs
running frigate
- switch to
frigateuser.$ sudo su - frigate - create the configuration file.
$ nano /data/frigate/config.toml
# Frigate configuration
[core]
connect = true
server = "http://127.0.0.1:8332"
authType = "COOKIE" # COOKIE or USERPASS
dataDir = "/data/bitcoin"
# auth = "user:password" # only needed for USERPASS
zmqSequenceEndpoint = "tcp://127.0.0.1:28336" # bitcoind -zmqpubsequence endpoint for low-latency mempool ingestion
# rpcRequestTimeoutSeconds = 60 # per-RPC read timeout (raise on slow/remote bitcoind, lower on fast LAN)
# rpcBatchSize = 100 # max sub-requests per JSON-RPC array batch (mempool fill)
[index]
# startHeight = 0 # default: 709632 on mainnet (Taproot activation), 0 on testnet
cacheSize = "1M" # scriptPubKey cache entries (1M, ~400MB RAM)
[scan]
# batchSize = 300000 # rows per GPU dispatch (reduce if scanning hangs on older GPUs)
# computeBackend = "AUTO" # AUTO, GPU, or CPU
# dbThreads = 4 # limit DuckDB threads (reduces CPU load when computeBackend = "CPU")
# memoryLimit = "8GB" # cap DuckDB memory usage (default: 80% of system RAM)
# maxLabels = 10 # maximum number of labels accepted per silent payments subscription
# maxSubscriptions = 100 # maximum number of silent payments subscriptions per connection
# metricsEnabled = true # hourly aggregate scan stats log line (default: true)
[server]
# host = "ssl://xyz.com:50002" # advertised in server.features; use array for multiple. Omit to advertise nothing.
tcp = "tcp://127.0.0.1:50001" # plaintext listener bind URL; omit (or "") to disable. Default if neither tcp nor ssl is set.
# ssl = "ssl://0.0.0.0:50002" # SSL listener bind URL; omit to disable
# sslCert = "cert.pem" # PEM certificate (chain allowed); bare filename resolves under Frigate's home dir, or use an absolute path
# sslKey = "key.pem" # PEM-encoded PKCS#8 private key; bare filename resolves under Frigate's home dir, or use an absolute path
backendElectrumServer = "tcp://localhost:60001" # backend must listen on a port distinct from Frigate's tcp/ssl listeners above
- run frigate.
$ /opt/frigate/bin/frigate -d /data/frigate - check if it works.
> 2026-08-10 13:12:10,516 INFO Using configured Frigate home folder of /data/frigate > 2026-08-10 13:12:10,548 INFO Starting Frigate v1.5.3 on mainnet > 2026-08-10 13:12:10,549 INFO Using home directory /data/frigate > 2026-08-10 13:12:12,313 INFO Using CPU backend for scanning (no GPU detected) > 2026-08-10 13:12:12,571 INFO Indexing 252237 blocks (709632 to 961868)... > 2026-08-10 13:12:42,715 INFO Indexing progress: 95 / 252237 blocks (0.0%, height 709726) > 2026-08-10 13:13:13,004 INFO Indexing progress: 187 / 252237 blocks (0.1%, height 709818) > ^C2026-08-10 13:13:24,236 INFO Frigate shutting down... - exit the
frigateuser session.
systemd daemon
- create the configuration.
$ sudo nano /etc/systemd/system/frigate.service
[Unit]
Description=Frigate Electrum Server
After=network-online.target bitcoind.service
Wants=network-online.target
[Service]
Type=simple
User=frigate
StateDirectory=frigate
ExecStart=/opt/frigate/bin/frigate -d /data/frigate
Restart=on-failure
RestartSec=5
# Directory creation and permissions
####################################
User=frigate
# /run/frigate
RuntimeDirectory=frigate
RuntimeDirectoryMode=0710
# Hardening measures
####################
# Provide a private /tmp and /var/tmp.
PrivateTmp=true
# Use a new /dev namespace only populated with API pseudo devices
# such as /dev/null, /dev/zero and /dev/random.
PrivateDevices=true
[Install]
WantedBy=multi-user.target
- enable and start
frigateservice.$ sudo systemctl enable frigate $ sudo systemctl start frigate - check the logs.
$ sudo journalctl -f -u frigate - wait for the blockchain to be indexed. it should take around two to three days.
blasere's blog