Self-Hosting on the Dark Web
5 hours ago
- The site is now accessible as a Tor hidden service via a .onion address that only resolves within the Tor network.
- Tor provides anonymity without certificate authorities, DNS, or exposed IPs; the address derives from a public key and connections are end-to-end encrypted by Tor.
- The Tor Project is a nonprofit that promotes human rights and open networks; users can support it or run a relay.
- Configuration requires editing /etc/tor/torrc with HiddenServiceDir and HiddenServicePort directives.
- Tor must own the hidden service directory (chmod 700, user debian-tor) and will refuse to start otherwise.
- After restarting Tor, the hostname file contains the generated .onion address.
- nginx listens on 127.0.0.1:8080 without TLS, HTTP/2, or QUIC since Tor handles encryption over plain TCP.
- For static sites, a second build with the onion address as baseURL prevents clearnet links from appearing on the Tor version.
- The deploy pipeline automatically builds and syncs separate clearnet and Tor copies to their respective web roots.
- The site can be read over Tor at the provided .onion address.