Sign inSign up

doingfedtime/hiddenforge

By doingfedtime

•Updated about 2 months ago

Hardened Tor hidden service container. Tor + Vanguards, reproducible, PQ + YubiKey signed.

Image
Networking
1

1.2K

doingfedtime/hiddenforge repository overview

⁠HiddenForge

A hardened Tor hidden service container. Tor 0.4.9.11 with the Vanguards addon on Alpine 3.23, every dependency pinned and hash-verified at build time, built for a state-level adversary threat model.

docker pull doingfedtime/hiddenforge

⁠Quick start

curl -O https://sambent.dev/sam/HiddenForge/raw/branch/master/docker-compose.yml
# edit the two lines marked <-- EDIT (your service name + your backend image)
mkdir -p ./tor-keys
docker compose up -d

# your .onion appears here once Tor bootstraps (first boot takes a couple of minutes)
docker compose exec tor cat /var/lib/tor/hidden_service/myapp/hostname

The compose file ships with every security flag pre-configured. Your backend is network-isolated and never exposed to the internet.

⁠What it does for you

LayerMechanism
Syscall filteringTor's Sandbox 1 (seccomp-bpf)
Privilege dropruns as the unprivileged tor user
Guard-discovery defenceVanguardsLiteEnabled 1, pinned so a consensus parameter cannot switch it off
DoS defenceproof-of-work at rendezvous + intro-point rate limiting
Debugger blockingDisableDebuggerAttachment 1
Disk minimisationAvoidDiskWrites 1, keys never paged to swap
Log scrubbingSafeLogging 1, no host-side log file
Filesystemread-only container, tmpfs for all writable paths
Key-volume tamperingprivileged startup refuses to follow symlinks out of the key directory
No relay/exitClientOnly 1, ExitPolicy reject *:*

⁠What's new in 2.0.4

  • Python runtime patched — six HIGH CVEs cleared; image is clean at every severity
  • VanguardsLiteEnabled 1 pinned, so guard-discovery protection can't be switched off by a consensus parameter
  • Privileged startup refuses to follow symlinks out of the key directory
  • One misconfigured service no longer prevents Tor from starting at all
  • Reproducible builds fixed and documented
  • Reading your .onion under rootless Podman now works as documented

Full changelog and every previous release: https://sambent.dev/sam/HiddenForge/releases⁠

⁠Verify before you run it

People's safety depends on this image being the one built from the public source. Every release is signed over its image digest two independent ways, with no transparency log and no third-party service:

  • ML-DSA-65 (FIPS 204, post-quantum)
  • SSH-FIDO2 (a physical YubiKey — cannot be produced by software alone)

The build is also reproducible: rebuild from the tag and you get the same digest.

Verification files and the step-by-step guide: https://sambent.dev/sam/HiddenForge⁠

⁠Where it lives

Source, issues, signatures and documentation are at https://sambent.dev/sam/HiddenForge⁠ (the maintainer's own forge).

The image is published to both this Docker Hub repository and the maintainer's own registry at sambent.dev/sam/hiddenforge. Both serve the identical digest — pull from whichever you prefer, and verify either against the same signatures.

⁠What this cannot protect you from

The Tor layer is hardened; the application behind it is not. Onion services are almost always located because the app told someone where it lives — an outbound clearnet request, an absolute URL, a real hostname in a redirect or error page, a server banner matchable against a clearnet scan, or a leaked timezone. Keep your backend on the internal network and audit what it emits.

Licensed under the terms in the repository.

Tag summary

Content type

Image

Digest

sha256:063d824c3…

Size

32.3 MB

Last updated

about 2 months ago

docker pull doingfedtime/hiddenforge