# Freqtrade clones onto develop, and its compose file starts live trading

> A GPL-3.0 Python crypto trading bot with backtesting, hyperopt, a web UI and Telegram control across a dozen spot exchanges and seven futures venues. The default branch is the one that may contain breaking changes, the shipped compose file runs the trade command with a sample strategy rather than a dry run, and a pip install resolves looser versions than the pinned container.

**freqtrade/freqtrade** — GitHub describes it as Free, open source crypto trading bot. The repository metadata lists Python as its primary language. The metadata lists the GPL-3.0 license. This article stays within the project description and details documented in the GitHub repository README.

- Repository: https://github.com/freqtrade/freqtrade
- Website: https://www.freqtrade.io
- Stars: 54,961 · Forks: 11,381
- Language: Python
- License: GPL-3.0
- Published: 2026-08-13 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/freqtrade-freqtrade

## The default branch is the one documented as a source of breaking changes

The repository's default branch is develop, and the same page explains what that means in three bullets. The develop branch often has new features but might also contain breaking changes, and the project says it tries hard to keep it stable. The stable branch holds the latest stable release and is generally well tested. Feature branches carry a feat prefix and the documentation asks you not to use them unless you want to test something specific. So the branch you get from a plain clone is the one carrying the caveat, while the branch it recommends is not the default. That is an unusual default and it has a concrete effect: a clone, a pip install from source, or a pull request opened against the default will all be working against the moving branch rather than the released one. The docker compose file makes the contrast visible in a single line, since it pins its image to the stable tag while the repository itself defaults to develop.

## The shipped compose file starts live trading with a sample strategy

This is the detail to read before the first run. The documentation is emphatic that you should always start in dry-run and not engage money until you understand how it works and what profit or loss to expect. The compose file that ships in the repository has a default command, and it is the trade subcommand, not a dry run.

```yaml
      trade
      --logfile /freqtrade/user_data/logs/freqtrade.log
      --db-url sqlite:////freqtrade/user_data/tradesv3.sqlite
      --config /freqtrade/user_data/config.json
      --strategy SampleStrategy
```

The database is a SQLite file inside the mounted user_data directory, the configuration is the one you edited, and the strategy is the sample that ships with the project. So the gap between the project's advice and its shipped default is the difference between a simulation and a real order path, and the mitigation is one word added to that command. The rest of the compose file is careful in ways worth copying: the API port is bound to localhost only rather than to all interfaces, and a comment points at the REST API documentation for what to do if you want to expose it.

## The container drops to a non-root user that can still chown anything

The Dockerfile is a three-stage build on a Python slim base, and the security posture is mostly deliberate. It installs a small set of system packages, creates an unprivileged user with a fixed uid, makes the working directory owned by that user, and switches to it before installing anything, so the image does not run its application as root. It also sets a handful of environment values with clear intent, including no bytecode writing, a fault handler, a user-local path and an application environment marker. Then there is one line that complicates the picture: it grants that user passwordless sudo for exactly one binary, chown. The consequence is bounded but real. A process that is compromised inside the container can change the ownership of files it can reach, and the user_data directory is bind-mounted from the host, so that reach includes your strategies, your config and your trade database. The grant is narrow and intentional; it is just not nothing.

## A pip install and a container run can resolve different library versions

The project manifest and the pinned requirements file describe different worlds, and the gap is easy to miss. In the manifest the dependencies are ranges: a minimum and a ceiling for the numeric stack, an open-ended minimum for the exchange library, and floors for the rest. The pinned file beside it is exact: one specific version each for the array library, the dataframe library, the columnar engine, the expression engine, the statistics library, the exchange library, the HTTP stack, the ORM, the Telegram client, the certificate bundle and dozens more, down to the release date of the certificate bundle. One file also carries a comment explaining why a single dependency cannot be hard-pinned, because the Telegram client constrains the HTTP client itself. The consequence is that installing the library from source gives you the newest versions satisfying the ranges, while the container gives you the pinned set, and a bug that reproduces in one will not reproduce in the other. Pin deliberately and know which world you are in.

## Six requirements files, and the default image ships neither plotting nor FreqAI

Optional capability is separated rather than bundled, and you can see the seams in the file list: a base requirements file plus separate ones for development, hyperopt, plotting, FreqAI and the reinforcement-learning extras. The Dockerfile then bakes in only two of them, the base file and the hyperopt file. The compose file offers the other capabilities as different images, with a plotting variant and a GPU variant both present but commented out, along with a commented GPU reservation block naming a specific driver and device count, and a commented custom build pointing at a separate Dockerfile for when you need extra dependencies. The consequence is that the default image gives you backtesting and hyperopt and not the other two, so a strategy that plots its results or uses the adaptive modelling will not run until you change the image or build your own. FreqAI is the feature most likely to surprise, since it is the one advertised in the feature list with its own documentation page.

## Backtesting ships two bias detectors, which is rarer than it should be

The command list is a single line of thirty-two subcommands, and buried in the tail of it are two worth knowing about. One is a lookahead analysis command and the other is a recursive analysis command. Both exist to test whether a strategy is cheating in backtesting, where a strategy accidentally uses information it would not have had at the moment it traded. That matters more than the headline features, because a backtest with lookahead bias will look excellent and mean nothing, and most retail backtesting tools do nothing to detect it. There is also an edge command alongside them and a test-pairlist command for checking a pair list. The rest of the list is the expected tooling: data download and conversion, backtesting with show and analysis variants, hyperopt with list and show variants, plotting for dataframes and profit, a web server, a strategy updater and configuration and pair and market listings. The consequence for a newcomer is that the tool for falsifying your own strategy is shipped in the same binary as the tool that generates it, which is the arrangement you want and rarely get.

## The project asks you to read the source, and its disclaimer is the strongest text here

The first substantive section of the page is a disclaimer, and it is unusually blunt. The software is for educational purposes only, you should not risk money you are afraid to lose, use it at your own risk, and the authors and all affiliates assume no responsibility for your trading results. It then tells you to start in dry-run and to have coding and Python knowledge, and to read the source code and understand the mechanism. That is a project asking to be audited rather than trusted, which is the right posture for something that places orders. It also puts a distance between itself and the questions people actually search for, most of which are about whether it is profitable, safe or legitimate, and none of which the documentation answers with a number. The exchange coverage is the other place the page is careful, separating officially supported spot and futures venues from two exchanges that are only community tested, and listing a long tail of others through a compatibility library with an explicit warning that they cannot be guaranteed to work.

## Conclusion

Adopt Freqtrade when you want to write and test a strategy in Python rather than configure one, because the backtesting, hyperopt and bias-detection tooling is the substance of the project and the web UI plus Telegram control make a long-running bot manageable. Do not adopt it expecting a turnkey profit, because the project's own disclaimer asks you not to risk money you are afraid to lose and says to start in dry-run, and nothing in its documentation claims a return. Three things to get right first. Clone the stable branch, not the default one, because the default is the branch its own documentation flags as a possible source of breaking changes. Change the compose command to a dry run before you start it, since the shipped default is live trading. And expect the versions you get from pip to differ from the ones in the container, because the declared ranges and the pinned requirements file disagree.

## FAQ

### What is Freqtrade used for?

It is a free, open source crypto trading bot written in Python, designed to support all major exchanges and be controlled through Telegram or a built-in web UI. It includes backtesting, plotting, money management and strategy optimisation by machine learning, with persistence through SQLite and dry-run support.

### How do I install Freqtrade?

The quick start points at a Docker quickstart page, and further native installation methods are documented separately. The project targets Python 3.11 and newer, and the repository ships both a shell setup script and a PowerShell one for Windows. There is also a systemd unit and a watchdog unit in the tree.

### Is Freqtrade safe?

The project does not claim that, and asks you to verify it yourself. The disclaimer says the software is for educational purposes only, that you should not risk money you are afraid to lose, and that the authors assume no responsibility for your trading results. It instructs you to start in dry-run and to read the source code to understand the mechanism.

### Is Freqtrade profitable?

Nothing in the documentation makes a profitability claim, and the disclaimer explicitly disclaims responsibility for trading results. What the project offers is the tooling to evaluate a strategy yourself: backtesting, hyperopt for parameter search, and separate commands for lookahead and recursive analysis to detect strategies that only look good in simulation.

## Sources

- [Official documentation](https://www.freqtrade.io)
- [Official README](https://github.com/freqtrade/freqtrade#readme)
- [Project repository](https://github.com/freqtrade/freqtrade)
- [Release notes](https://github.com/freqtrade/freqtrade/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/freqtrade-freqtrade
