Self-Hosting a Personal Site as a Tor Hidden Service

Original: Self-Hosting on the Dark Web

Why This Matters

A rare, end-to-end practical example of dual-target static site deployment over Tor for personal infrastructure.

Developer David Álvarez Rosa published a walkthrough on configuring his personal blog as a Tor hidden service, reachable at a .onion address with no DNS, no certificate authority, and no exposed IP. The setup uses nginx on localhost port 8080, with Hugo building a separate copy of the site per deployment target.

Rosa's guide covers the full stack: editing /etc/tor/torrc to define a HiddenServiceDir and forwarding port 80 to 127.0.0.1:8080, then configuring nginx to serve plain HTTP on that loopback address — no TLS, no HTTP/2, since Tor handles encryption internally. The .onion address is derived from the service's public key and stored in a Tor-owned directory (chmod 700). A key subtlety: static site generators like Hugo bake an absolute base URL into every link, so serving a clearnet build over Tor would bounce visitors back to the clearnet domain. The fix is a second build pass with the .onion address as baseURL. Rosa's GitHub Actions pipeline automates this: each push builds and rsyncs both a clearnet and a Tor copy to separate web roots. The post also encourages readers to support the nonprofit Tor Project or run a relay, noting the network depends on volunteer participation. The full configuration is public in his homelab repository.

Source

david.alvarezrosa.com — Read original →