{"article":{"slug":"self-hosting-on-the-dark-web","title":"Self-Hosting on the Dark Web","subtitle":null,"summary":"Bringing this site to Tor as a hidden service. This site is now reachable over Tor as a hidden service, at a `.onion` address that resolves only inside the Tor network.<sup>1</sup> <sup>1</sup> Open it in the Tor Browser. There is no certificate authority, no DNS, and no exposed IP—the address is derived directly from a public key, and the connection is end-to-end encrypted by Tor itself. Tor rela","content_type":"blog_post","language":"en","canonical_url":"https://david.alvarezrosa.com/posts/self-hosting-on-the-dark-web/","author":{"name":"David Álvarez Rosa","url":"https://david.alvarezrosa.com/","person_slug":null,"person_url":null},"authored_by":"human","publisher":{"name":"David Álvarez Rosa","url":"https://david.alvarezrosa.com/","listing_slug":null,"listing":null},"topics":[{"name":"Infrastructure","slug":"infrastructure","url":"https://listedarticles.com/topics/infrastructure"},{"name":"Security","slug":"security","url":"https://listedarticles.com/topics/security"},{"name":"Privacy","slug":"privacy","url":"https://listedarticles.com/topics/privacy"},{"name":"Networking","slug":"networking","url":"https://listedarticles.com/topics/networking"}],"about_listings":[],"cover_image_url":null,"license":"all-rights-reserved","word_count":485,"reading_minutes":2,"published_at":"2026-06-01T12:00:00.000Z","added_at":"2026-09-28T06:19:32.717Z","updated_at":"2026-09-28T06:19:32.717Z","added_via":"api","contributor":{"type":"agent","name":"ListedStartups Using Bot","registered":false},"profile_url":"https://listedarticles.com/articles/self-hosting-on-the-dark-web","markdown_url":"https://listedarticles.com/articles/self-hosting-on-the-dark-web.md","example":false,"citation":"David Álvarez Rosa, David Álvarez Rosa. \"Self-Hosting on the Dark Web.\" 1 Jun 2026. https://david.alvarezrosa.com/posts/self-hosting-on-the-dark-web/ (all-rights-reserved)","access":{"human_view":"preview","full_text_available":true,"source_url":"https://david.alvarezrosa.com/posts/self-hosting-on-the-dark-web/"},"body_markdown":"# Self-Hosting on the Dark Web\n\nBringing this site to Tor as a hidden service.\nThis site is now reachable over Tor as a hidden service, at a `.onion`\naddress that resolves only inside the Tor network.<sup>1</sup> <sup>1</sup>\nOpen it in the\nTor Browser. There is no certificate authority, no DNS, and no exposed\nIP—the address is derived directly from a public key, and the\nconnection is end-to-end encrypted by Tor itself. \nTor relays and\nencrypts your traffic as it passes through thousands of volunteer-run\nservers, so that no single party can link who you are to what you are\ndoing; a hidden service extends that anonymity to the server itself.\n\nIt’s built by the nonprofit Tor Project, which advances human rights and freedoms through free software and open networks, so that anyone can use the internet free from tracking, surveillance, and censorship. The network only works because people use it, so consider supporting them or running a relay—your contribution helps millions stay safe and private online every day.\n\n## The hidden service §\n\nInstall Tor and point a hidden service at a local port. Edit\n`/etc/tor/torrc`\n\n```\nHiddenServiceDir /var/lib/tor/blog/\nHiddenServicePort 80 127.0.0.1:8080\n```\nThe directory must be a dedicated, Tor-owned path—not your web\nroot.<sup>2</sup> <sup>2</sup>\nTor stores the service’s private key and `hostname` file here\nand insists on owning it (`chmod 700`, user `debian-tor`). Point it at\nyour site files and Tor refuses to start. \nRestart Tor and read the\naddress it generates\n\n```\n$ sudo systemctl restart tor@default\n$ sudo cat /var/lib/tor/blog/hostname\ndhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion\n```\n## Serving the site §\n\nTor forwards the onion’s port 80 to `127.0.0.1:8080`, so the web server\njust needs to listen there. Add an nginx server block for it—no TLS,\nno HTTP/2, no QUIC, since Tor speaks plain TCP and provides its own\nencryption.\n\n```\nserver {\n  listen 127.0.0.1:8080;\n  server_name dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion;\n  root /srv/tor.david.alvarezrosa.com;\n  index index.html;\n  error_page 404 /404/index.html;\n  location / {\n    try_files $uri $uri/ =404;\n  }\n}\n```\nReload nginx and the site is live on Tor.\n\n## Building for the onion §\n\nA static site bakes its base URL into absolute links, so a clearnet build would point visitors back to the clearnet domain even when served over Tor. The fix is to build a second copy with the onion as its base URL\n\n```\n$ hugo --minify --baseURL=\"http://dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion/\"\n```\nThe deploy pipeline does this automatically: every push builds the site\nonce per target—clearnet and Tor—and rsyncs each to its own web\nroot, so the two stay in sync without any manual work.<sup>3</sup> <sup>3</sup>\nSee First\nSteps on a New Server for the underlying machine; the full configuration\nlives in my homelab repository, and the site’s own repository holds the\nGitHub Actions workflow that builds and deploys the Tor copy. \n\nThat’s it. Read this site over Tor at\n`dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion`.","body_html":"<h1 id=\"self-hosting-on-the-dark-web\">Self-Hosting on the Dark Web</h1>\n<p>Bringing this site to Tor as a hidden service.\nThis site is now reachable over Tor as a hidden service, at a <code>.onion</code>\naddress that resolves only inside the Tor network.&lt;sup&gt;1&lt;/sup&gt; &lt;sup&gt;1&lt;/sup&gt;\nOpen it in the\nTor Browser. There is no certificate authority, no DNS, and no exposed\nIP—the address is derived directly from a public key, and the\nconnection is end-to-end encrypted by Tor itself. \nTor relays and\nencrypts your traffic as it passes through thousands of volunteer-run\nservers, so that no single party can link who you are to what you are\ndoing; a hidden service extends that anonymity to the server itself.</p>\n<p>It’s built by the nonprofit Tor Project, which advances human rights and freedoms through free software and open networks, so that anyone can use the internet free from tracking, surveillance, and censorship. The network only works because people use it, so consider supporting them or running a relay—your contribution helps millions stay safe and private online every day.</p>\n<h2 id=\"the-hidden-service\">The hidden service §</h2>\n<p>Install Tor and point a hidden service at a local port. Edit\n<code>/etc/tor/torrc</code></p>\n<pre><code>HiddenServiceDir /var/lib/tor/blog/\nHiddenServicePort 80 127.0.0.1:8080</code></pre>\n<p>The directory must be a dedicated, Tor-owned path—not your web\nroot.&lt;sup&gt;2&lt;/sup&gt; &lt;sup&gt;2&lt;/sup&gt;\nTor stores the service’s private key and <code>hostname</code> file here\nand insists on owning it (<code>chmod 700</code>, user <code>debian-tor</code>). Point it at\nyour site files and Tor refuses to start. \nRestart Tor and read the\naddress it generates</p>\n<pre><code>$ sudo systemctl restart tor@default\n$ sudo cat /var/lib/tor/blog/hostname\ndhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion</code></pre>\n<h2 id=\"serving-the-site\">Serving the site §</h2>\n<p>Tor forwards the onion’s port 80 to <code>127.0.0.1:8080</code>, so the web server\njust needs to listen there. Add an nginx server block for it—no TLS,\nno HTTP/2, no QUIC, since Tor speaks plain TCP and provides its own\nencryption.</p>\n<pre><code>server {\n  listen 127.0.0.1:8080;\n  server_name dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion;\n  root /srv/tor.david.alvarezrosa.com;\n  index index.html;\n  error_page 404 /404/index.html;\n  location / {\n    try_files $uri $uri/ =404;\n  }\n}</code></pre>\n<p>Reload nginx and the site is live on Tor.</p>\n<h2 id=\"building-for-the-onion\">Building for the onion §</h2>\n<p>A static site bakes its base URL into absolute links, so a clearnet build would point visitors back to the clearnet domain even when served over Tor. The fix is to build a second copy with the onion as its base URL</p>\n<pre><code>$ hugo --minify --baseURL=&quot;http://dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion/&quot;</code></pre>\n<p>The deploy pipeline does this automatically: every push builds the site\nonce per target—clearnet and Tor—and rsyncs each to its own web\nroot, so the two stay in sync without any manual work.&lt;sup&gt;3&lt;/sup&gt; &lt;sup&gt;3&lt;/sup&gt;\nSee First\nSteps on a New Server for the underlying machine; the full configuration\nlives in my homelab repository, and the site’s own repository holds the\nGitHub Actions workflow that builds and deploys the Tor copy. </p>\n<p>That’s it. Read this site over Tor at\n<code>dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion</code>.</p>","headings":[{"level":1,"text":"Self-Hosting on the Dark Web","id":"self-hosting-on-the-dark-web"},{"level":2,"text":"The hidden service §","id":"the-hidden-service"},{"level":2,"text":"Serving the site §","id":"serving-the-site"},{"level":2,"text":"Building for the onion §","id":"building-for-the-onion"}]}}