Run a Stake Pool Start here Guided mode

Start here

The picture, the dangers and how BRIAN runs it.

  1. Start hereThe picture, the dangers, how BRIAN runs it4 steps
  2. IInstallMachines, a hardened Ubuntu, the node5 steps
  3. IIConfigureChain, topology, offline machine, service5 steps
  4. IIIRegisterKeys, stake address, the pool5 steps
  5. IVRunKES, rewards, votes, upgrades8 steps
  6. VTipsPayments, files, swap, checklist4 steps

O-1 Your pool at a glance

Relays face the world, the block producer hides behind them, the cold keys never go online.

Your pool at a glance Cardano network Relay 1public · port 6000 Relay 2other country Relay 3other provider firewall Block producer private · relays only VRF · KES · certificate Air-gapped machine cold keys · never online USB stick only Your pool at a glance Cardano network Relay 1port 6000 Relay 22nd country Relay 32nd provider firewall Block producer private · relays only VRF · KES · certificate USB stick only Air-gapped machine cold keys · signs never online
Your pool at a glance: the Cardano network reaches three public relays; only the relays reach the private block producer behind a firewall; the cold keys live on an air-gapped machine that is connected by USB stick only.

Every code block below names the machine it runs on. A testnet run first costs nothing: use --testnet-magic 2 (Preview) instead of --mainnet.

Next: Watch out for attackers →

O-2 Watch out for attackers

A pool holds real ADA and real keys. These six tricks are how pools get robbed.

  • Fake downloads

    Look-alike sites and repositories ship node binaries with a backdoor.

    Download only from github.com/IntersectMBO and check the SHA-256 before you run anything.

  • Fake support

    “Admins” write first in Discord, Telegram or X and ask for keys, a seed phrase or remote access.

    Nobody genuine ever asks. Never share a .skey file, a seed phrase or a screen.

  • Keys on a server

    A cold key on an online machine means a stolen pool and stolen rewards.

    Cold, payment and stake keys exist only on the air-gapped machine and its backups.

  • Password guessing

    Bots try SSH passwords on every server, day and night.

    Keys only, no root login, another port, fail2ban.

  • Copy-paste traps

    Clipboard malware swaps addresses; web pages hide extra commands in what you copy.

    Paste into an editor first, read every command, check every address after pasting.

  • Exposed block producer

    A block producer reachable from the internet can be flooded or attacked.

    Firewall: port 6000 only from your relays. Its IP is never published.

Important Never paste a key, a seed phrase or a .skey file into any chat, form or AI — ours included. A genuine helper never needs one.

Next: How BRIAN runs it →

O-3 How BRIAN runs it

The setup behind BRIAN since August 2024 — our recommendations, from practice.

  • Three relays, three countriesFrance, United Kingdom, United States — one data centre going dark does not stop the pool.
  • Hosted at ContaboRented servers with a static IP; the relays run there.
  • Private block producerReachable only from the three relays, its address published nowhere.
  • Cold keys offlineCreated and kept on an air-gapped machine; every signature happens there.
  • Mithril signerHelps certify the snapshots other nodes sync from.
  • Monitored dailyPeers, sync, KES and blocks checked every day; updates promptly, relays first.

See it live on the Pool Info board.

Next: Before you start →

O-4 Before you start

Checked versions, and two settings every online command uses.

Every command was run against cardano-node 11.1.3 and cardano-cli 11.2.3 on 3 October 2026. All start with cardano-cli latest (the Conway era).

Block producer or relay
echo 'export CARDANO_NODE_SOCKET_PATH=/run/cardano/node.socket' >> ~/.bashrc
echo 'export CARDANO_NODE_NETWORK_ID=mainnet' >> ~/.bashrc
source ~/.bashrc

Caution Not financial advice. Read each command before you run it.

Sources and license

Text, pictures and order are BRIAN's. Commands for system setup, the firewall, Mithril and the service file are adapted from the Cardano Developer Portal; every cardano-cli command was written for and run against cardano-cli 11.2.3. The node's own documentation always takes precedence.

Developer Portal license (MIT) — Copyright (c) 2021 Cardano Foundation

Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.