Hardened Tor hidden service container. Tor + Vanguards, reproducible, PQ + YubiKey signed.
1.2K
A hardened Tor hidden service container. Tor 0.4.9.11 with the Vanguards addon on Alpine 3.23, every dependency pinned and hash-verified at build time, built for a state-level adversary threat model.
docker pull doingfedtime/hiddenforge
curl -O https://sambent.dev/sam/HiddenForge/raw/branch/master/docker-compose.yml
# edit the two lines marked <-- EDIT (your service name + your backend image)
mkdir -p ./tor-keys
docker compose up -d
# your .onion appears here once Tor bootstraps (first boot takes a couple of minutes)
docker compose exec tor cat /var/lib/tor/hidden_service/myapp/hostname
The compose file ships with every security flag pre-configured. Your backend is network-isolated and never exposed to the internet.
| Layer | Mechanism |
|---|---|
| Syscall filtering | Tor's Sandbox 1 (seccomp-bpf) |
| Privilege drop | runs as the unprivileged tor user |
| Guard-discovery defence | VanguardsLiteEnabled 1, pinned so a consensus parameter cannot switch it off |
| DoS defence | proof-of-work at rendezvous + intro-point rate limiting |
| Debugger blocking | DisableDebuggerAttachment 1 |
| Disk minimisation | AvoidDiskWrites 1, keys never paged to swap |
| Log scrubbing | SafeLogging 1, no host-side log file |
| Filesystem | read-only container, tmpfs for all writable paths |
| Key-volume tampering | privileged startup refuses to follow symlinks out of the key directory |
| No relay/exit | ClientOnly 1, ExitPolicy reject *:* |
VanguardsLiteEnabled 1 pinned, so guard-discovery protection can't be switched
off by a consensus parameter.onion under rootless Podman now works as documentedFull changelog and every previous release: https://sambent.dev/sam/HiddenForge/releases
People's safety depends on this image being the one built from the public source. Every release is signed over its image digest two independent ways, with no transparency log and no third-party service:
The build is also reproducible: rebuild from the tag and you get the same digest.
Verification files and the step-by-step guide: https://sambent.dev/sam/HiddenForge
Source, issues, signatures and documentation are at https://sambent.dev/sam/HiddenForge (the maintainer's own forge).
The image is published to both this Docker Hub repository and the maintainer's
own registry at sambent.dev/sam/hiddenforge. Both serve the identical digest —
pull from whichever you prefer, and verify either against the same signatures.
The Tor layer is hardened; the application behind it is not. Onion services are almost always located because the app told someone where it lives — an outbound clearnet request, an absolute URL, a real hostname in a redirect or error page, a server banner matchable against a clearnet scan, or a leaked timezone. Keep your backend on the internal network and audit what it emits.
Licensed under the terms in the repository.
Content type
Image
Digest
sha256:063d824c3…
Size
32.3 MB
Last updated
about 2 months ago
docker pull doingfedtime/hiddenforge