You probably want to add the Onion-Location header to the clearnet site so Tor Browser can automatically inform the visitor about it: <a href="https://community.torproject.org/onion-services/advanced/onion-location/" rel="nofollow">https://community.torproject.org/onion-services/advanced/oni...</a>
Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:<p>> HiddenServicePort 80 127.13.37.1:8080<p>> listen 127.13.37.1:8080;<p>This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.<p>You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.
It's also possible to use a Unix socket, which can have a descriptive pathname like /var/run/my-service.sock: <a href="https://stackoverflow.com/questions/69313114/using-nginx-to-host-tor-hidden-service-through-unix-socket" rel="nofollow">https://stackoverflow.com/questions/69313114/using-nginx-to-...</a>
What is the benefit of building the same website twice with different hostnames instead of using relative links to content on the same domain?
Besides accessing your page are random people able to use your server as an exit node? Am I thinking the right thing... I met someone in Switzerland that was hosting anonymous exit nodes to some anonymous network and he said that it was a pain having to explain what was happening to the police.
Exit node are an entirely optional part of the Tor network. If you run a relay or a hidden service you are not forced to participate in the exit node side of things. It's also not recommended to combine these roles because it could have security implications for your hidden service.
Running a Tor exit node is a manual process. Running a hidden service like a website, or chat server doesn't involve anything like that.
That'd be an exit relay, not doing that atm, just in case
No
Thanks for sharing! Happy to get feedback :)
Imagine if normal people could install a single normal application and just run a website from a folder. CLI makes it more difficult than hosting a normal website. Typing commands you don't understand doesn't seem all that of a great idea.
Nice thing is you skip port forwarding entirely, which matters a lot if your ISP has you behind CGNAT. Curious how people handle uptime though, since a hidden service going down isn't something you notice until someone tells you.
Ran a small onion site for a couple years and the nice part is you never touch a public IP or a cert. Downside is onion v3 addresses are impossible to share verbally and the latency makes anything chatty feel broken. Static pages only, honestly.