在暗网上进行自托管
Self-Hosting on the Dark Web

原始链接: https://david.alvarezrosa.com/posts/self-hosting-on-the-dark-web/

本网站现已通过 Tor 网络作为隐藏服务提供访问,从而确保了更高的隐私性、匿名性以及对审查的抵御能力。与标准网站不同,.onion 地址无需传统的域名系统(DNS)或证书颁发机构,而是利用端到端加密和去中心化中继系统来隐藏用户与服务器的身份。 在技术实现上,该设置涉及配置 Tor,将隐藏服务目录映射到本地端口(例如 127.0.0.1:8080)。随后,如 Nginx 等标准 Web 服务器在本地端口上托管该网站。由于加密由 Tor 处理,Web 服务器无需 TLS 或高级协议。 为保持一致性,该网站的部署流程实现了专用 Tor 兼容版本的自动化构建。通过在构建过程中为 .onion 地址设置特定的基准 URL,该网站与明网版本保持了完美同步。此次过渡支持了 Tor 项目的使命,即提供一个免受追踪和监控的互联网环境。您现在可以通过以下地址安全地访问本网站:`dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion`。

相关文章

原文

This site is now reachable over Tor as a hidden service, at a .onion address that resolves only inside the Tor network.1 1 Open it in the Tor Browser. There is no certificate authority, no DNS, and no exposed IP—the address is derived directly from a public key, and the connection is end-to-end encrypted by Tor itself.  Tor relays and encrypts your traffic as it passes through thousands of volunteer-run servers, so that no single party can link who you are to what you are doing; a hidden service extends that anonymity to the server itself.

It’s built by the nonprofit Tor Project, which advances human rights and freedoms through free software and open networks, so that anyone can use the internet free from tracking, surveillance, and censorship. The network only works because people use it, so consider supporting them or running a relay—your contribution helps millions stay safe and private online every day.

The hidden service §

Install Tor and point a hidden service at a local port. Edit /etc/tor/torrc

HiddenServiceDir /var/lib/tor/blog/
HiddenServicePort 80 127.0.0.1:8080

The directory must be a dedicated, Tor-owned path—not your web root.2 2 Tor stores the service’s private key and hostname file here and insists on owning it (chmod 700, user debian-tor). Point it at your site files and Tor refuses to start.  Restart Tor and read the address it generates

$ sudo systemctl restart tor@default
$ sudo cat /var/lib/tor/blog/hostname
dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion

Serving the site §

Tor forwards the onion’s port 80 to 127.0.0.1:8080, so the web server just needs to listen there. Add an nginx server block for it—no TLS, no HTTP/2, no QUIC, since Tor speaks plain TCP and provides its own encryption.

server {
  listen 127.0.0.1:8080;
  server_name dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion;

  root /srv/tor.david.alvarezrosa.com;
  index index.html;
  error_page 404 /404/index.html;

  location / {
    try_files $uri $uri/ =404;
  }
}

Reload nginx and the site is live on Tor.

Building for the onion §

A static site bakes its base URL into absolute links, so a clearnet build would point visitors back to the clearnet domain even when served over Tor. The fix is to build a second copy with the onion as its base URL

$ hugo --minify --baseURL="http://dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion/"

The deploy pipeline does this automatically: every push builds the site once per target—clearnet and Tor—and rsyncs each to its own web root, so the two stay in sync without any manual work.3 3 See First Steps on a New Server for the underlying machine; the full configuration lives in my homelab repository, and the site’s own repository holds the GitHub Actions workflow that builds and deploys the Tor copy. 

That’s it. Read this site over Tor at dhevt6e4rtgbtr3jh53xrpwmgtilkah6nyjujocsspssrsexc7omxhid.onion.

联系我们 contact @ memedata.com