Deploy a Service Behind Tor
Make any Elestio service reachable as a Tor onion site. You add a Tor sidecar to your Docker Compose setup, and the service becomes accessible from Tor-compatible browsers only.
Step 1: Set up your service
Deploy a new service on Elestio, or select one you already run.
Step 2: Open the editor
Go to the Tools tab of your service and open the built-in VS Code editor.
Step 3: Stop the current container
docker-compose down -v;
Step 4: Add a Tor service to Docker Compose
Add a Tor sidecar to your Docker Compose file. The example below runs a Nextcloud server reachable through a Tor onion address.
version: "3.9"
services:
app:
image: elestio/nextcloud:${SOFTWARE_VERSION_TAG}
restart: always
volumes:
- ./nextcloud:/var/www/html
- ./apps:/var/www/html/custom_apps
- ./config:/var/www/html/config
- ./data:/var/www/html/data
tor:
image: jakejarvis/tor:latest
restart: unless-stopped
volumes:
- ./tor-data:/var/lib/tor/
- ./torrc:/etc/tor/torrc:ro
depends_on:
- app
volumes:
tor-data:
This example uses jakejarvis/tor. You can swap it for any official or custom Tor image that fits your requirements.
Step 5: Create the torrc file
In the root of your project, create a file named torrc. It configures Tor as a hidden service and points it at your web container.
# Folder holding the hidden service keys (generated by Tor if missing).
HiddenServiceDir /var/lib/tor/hidden_service
# Point the hidden service at the web container listening on port 80.
HiddenServicePort 80 app:80
# SOCKS proxy, used only for the container internal healthcheck.
SocksPort 127.0.0.1:9050
Step 6: Start the services
docker-compose up -d;
This brings up both the app and Tor services, and Tor generates the onion address.
Step 7: Get your onion URL
cat tor-data/hidden_service/hostname
The output is an onion address (for example abcdefghijklmno.onion) that you can open in a Tor-compatible browser such as Tor Browser or Brave.
Step 8: Update your service URL
If your application stores a domain or base URL in its environment variables or config, replace it with your onion URL.
Optional: Block public internet access
To restrict access to Tor only, block port 443 in your firewall. Configure this from the Security tab of your service, or via your cloud provider firewall if you use a Bring Your Own VM (BYOVM).
- Protect your private keys. The hidden service keys live in
tor-data/hidden_service. - Stay updated. Keep your Tor image on the latest version for security patches.
- Watch your logs. Monitor both application and Tor service logs regularly.