Self-Hosting On The Dark Web
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

David Álvarez Rosa reports that his website is reachable both on the regular internet and as a Tor hidden service. His setup routes Tor traffic to a local Nginx server and automatically builds and deploys a separate site copy for the onion address.

David Álvarez Rosa says his website is now available as a Tor hidden service, reachable through an onion address from within the Tor network. The report describes a second, separately built copy of the site that Tor forwards to a local web server, adding an access route designed to conceal both the visitor’s network location and the server’s IP address.

The configuration uses Tor’s hidden-service feature to direct requests on onion port 80 to 127.0.0.1:8080, where Nginx serves the site. The report says Tor generates the onion address from a public key and stores the service’s private key and hostname in a dedicated directory owned by Tor. Álvarez Rosa cautions that this directory must not be the website’s document root.

For the web server, the article describes an Nginx block listening only on the local address and port. It serves static files from a separate web root. The configuration omits conventional web TLS and protocols such as HTTP/2 and QUIC; the author says Tor provides encryption for the connection within its network.

The site is built twice, once for its regular domain and once with the onion address as its base URL. That matters for static pages, whose links can otherwise point visitors back to the regular domain. Álvarez Rosa says a deployment pipeline automatically builds and copies each version to its own web root when the site changes.

At a glance
reportWhen: Reported in the source article; publica…
The developmentDavid Álvarez Rosa has published a Tor hidden-service version of his website and described how he configured and maintains it alongside the clearnet site.

A Second Route to the Site

The change gives readers who use Tor a way to reach the site without first leaving the Tor network for its regular web address. Tor routes and encrypts traffic through volunteer-run relays; a hidden service also allows the server to be reached through Tor without publishing its ordinary IP address in the way a conventional website does.

For site operators, the report illustrates that offering an onion address can fit into an existing static-site workflow. It requires a separate Tor service configuration and a build configured for the onion URL, while the automated deployment described here keeps the two published copies aligned. The article is one operator’s account, rather than an independent assessment of security or a claim that this approach suits every site.

How the Onion Copy Works

A Tor onion service is accessible through the Tor network rather than ordinary DNS. In the setup described by Álvarez Rosa, Tor accepts requests for the service and forwards them to a web server on the same machine. The web server does not need to listen on a publicly exposed address for this route.

The article focuses on a static site generated with Hugo. Because the generated pages contain links based on a configured base URL, the author creates a second build using the onion address. The deployment pipeline then sends that build to a separate directory from the regular site. The report points to the author’s homelab and website repositories for the underlying server configuration and workflow.

““The network only works because people use it.””

— David Álvarez Rosa

Limits of the Published Account

The source is a first-person technical report. It does not provide independent testing, traffic figures, or evidence about how many readers use the onion address. It also does not specify the report’s publication date in the supplied material, so the present operating status of the service cannot be confirmed from that material alone.

Tor can obscure the relationship between a visitor and a destination, but the report does not claim that the entire hosting environment or the author is immune to identification. It offers no audit of the server, deployment credentials, or operational security. The exact effect of the setup depends on how the site and server are maintained.

Ongoing Builds and Site Access

According to Álvarez Rosa, future site updates are handled by the existing deployment pipeline, which builds versions for the regular domain and Tor and deploys them to separate web roots. The report does not announce a further milestone or a planned expansion of the service. Readers seeking current access details or implementation specifics would need to consult the author’s site and linked repositories.

Key Questions

What changed on the website?

David Álvarez Rosa says the site now has an onion address that can be opened through the Tor network, alongside its regular web address.

Does the onion address use a separate site?

The report describes a separately generated copy. The deployment pipeline builds it with the onion address as its base URL and places it in a separate web root.

How does Tor reach the web server?

In the described setup, Tor forwards requests for the hidden service to a web server listening locally on 127.0.0.1:8080.

Does the report prove the hosting setup is secure?

No. It documents the author’s configuration but supplies no independent security audit or testing results.

Source: hn

EVERGREEN BESTSE

Evergreen bestsellers Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

How to Think About Guest Networks in a Small Office

A practical guide to small-office guest Wi-Fi: real isolation, passwords, captive portals, bandwidth, and the mistakes that quietly break separation.

Packet Capture Explained for Defensive Monitoring

Learn what packet captures reveal, where to collect them, how encryption limits visibility, and how to handle evidence safely.

9 Best Wi-Fi 7 Routers For Faster Home Networks In 2026

Discover the best Wi-Fi 7 routers of 2026, including the TP-Link Archer BE550 and mesh options, for improved speed and coverage at home.

Why Home Labs Are Useful for Learning Cybersecurity Safely

See how a home lab lets you practice cybersecurity, learn from mistakes, and build useful skills while keeping experiments away from everyday devices.