如何为现有网站配置多个Tor洋葱镜像链接?
Hey there! Let's talk about optimizing your Tor hidden service mirror setup. Your current configuration does the job, but we can make it cleaner, more maintainable, and aligned with modern Tor best practices.
First, let's validate your existing approach
Your current code block creates three separate hidden services, each with its own .onion address pointing to your local port 80:
HiddenServiceDir /var/lib/tor/a_service HiddenServicePort 80 HiddenServiceDir /var/lib/tor/b_service HiddenServicePort 80 HiddenServiceDir /var/lib/tor/c_service HiddenServicePort 80
This works, but it's repetitive, lacks clarity, and doesn't specify the hidden service version (critical since v2 addresses are no longer supported on the Tor network).
The optimized setup
Here's a better way to structure your config, with improvements for readability, maintainability, and security:
1. Structured, version-locked config
# Primary hidden service mirror HiddenServiceDir /var/lib/tor/primary_mirror/ HiddenServicePort 80 127.0.0.1:80 HiddenServiceVersion 3 # Secondary hidden service mirror HiddenServiceDir /var/lib/tor/secondary_mirror/ HiddenServicePort 80 127.0.0.1:80 HiddenServiceVersion 3 # Tertiary hidden service mirror HiddenServiceDir /var/lib/tor/tertiary_mirror/ HiddenServicePort 80 127.0.0.1:80 HiddenServiceVersion 3
HiddenServiceVersion 3: Forces Tor to generate modern, secure v3 .onion addresses (v2 is deprecated and no longer usable).- Explicit port mapping:
80 127.0.0.1:80makes it clear that incoming Tor traffic on port 80 is forwarded to your local web server on port 80. - Descriptive directory names: Replaces generic
a_servicewith meaningful names, making it easier to manage backups or troubleshoot later.
2. Scalable management for many mirrors
If you plan to add more mirrors down the line, split your config into modular files to avoid cluttering the main torrc:
- Create a directory for mirror configs:
mkdir -p /etc/tor/conf.d/mirrors - For each mirror, create a separate .conf file (e.g.,
/etc/tor/conf.d/mirrors/primary.conf):HiddenServiceDir /var/lib/tor/primary_mirror/ HiddenServicePort 80 127.0.0.1:80 HiddenServiceVersion 3 - Add this line to your main
torrcto include all mirror configs:Include /etc/tor/conf.d/mirrors/*.conf
This way, adding a new mirror just requires creating a new .conf file—no need to edit the main config.
Key best practices to remember
- Backup your service directories: Each
HiddenServiceDircontains aprivate_keyfile. If you lose this, you'll lose access to that .onion address. Store backups securely offline. - Keep Tor updated: Make sure you're running the latest stable Tor version to benefit from security patches and performance improvements.
- Test each mirror: After setting up, verify each .onion address loads your site correctly (you can find the address in each
HiddenServiceDir'shostnamefile).
内容的提问来源于stack exchange,提问作者Rick Cannon

