Skip to main content

Deploy a Service Behind Tor

Make any Elestio service reachable as a Tor onion site. You add a Tor sidecar to your Docker Compose setup, and the service becomes accessible from Tor-compatible browsers only.

Step 1: Set up your service​

Deploy a new service on Elestio, or select one you already run.

Step 2: Open the editor​

Go to the Tools tab of your service and open the built-in VS Code editor.

Step 3: Stop the current container​

docker-compose down -v;

Step 4: Add a Tor service to Docker Compose​

Add a Tor sidecar to your Docker Compose file. The example below runs a Nextcloud server reachable through a Tor onion address.

version: "3.9"
services:
app:
image: elestio/nextcloud:${SOFTWARE_VERSION_TAG}
restart: always
volumes:
- ./nextcloud:/var/www/html
- ./apps:/var/www/html/custom_apps
- ./config:/var/www/html/config
- ./data:/var/www/html/data
tor:
image: jakejarvis/tor:latest
restart: unless-stopped
volumes:
- ./tor-data:/var/lib/tor/
- ./torrc:/etc/tor/torrc:ro
depends_on:
- app
volumes:
tor-data:
Use any Tor image

This example uses jakejarvis/tor. You can swap it for any official or custom Tor image that fits your requirements.

Step 5: Create the torrc file​

In the root of your project, create a file named torrc. It configures Tor as a hidden service and points it at your web container.

# Folder holding the hidden service keys (generated by Tor if missing).
HiddenServiceDir /var/lib/tor/hidden_service

# Point the hidden service at the web container listening on port 80.
HiddenServicePort 80 app:80

# SOCKS proxy, used only for the container internal healthcheck.
SocksPort 127.0.0.1:9050

Step 6: Start the services​

docker-compose up -d;

This brings up both the app and Tor services, and Tor generates the onion address.

Step 7: Get your onion URL​

cat tor-data/hidden_service/hostname

The output is an onion address (for example abcdefghijklmno.onion) that you can open in a Tor-compatible browser such as Tor Browser or Brave.

Step 8: Update your service URL​

If your application stores a domain or base URL in its environment variables or config, replace it with your onion URL.

Optional: Block public internet access​

To restrict access to Tor only, block port 443 in your firewall. Configure this from the Security tab of your service, or via your cloud provider firewall if you use a Bring Your Own VM (BYOVM).

Security notes
  • Protect your private keys. The hidden service keys live in tor-data/hidden_service.
  • Stay updated. Keep your Tor image on the latest version for security patches.
  • Watch your logs. Monitor both application and Tor service logs regularly.