Comprehensive Setup Guide: Reverse Proxy to Tor for Services like BTCPay and Ghost

Comprehensive Setup Guide: Reverse Proxy to Tor for Services like BTCPay and Ghost

Comprehensive Setup Guide: Reverse Proxy to Tor for Services like BTCPay and Ghost

This guide provides a cleaned-up, step-by-step instruction set for creating reverse proxy access to .onion services (like BTCPay, LNbits, or Ghost instances) through clearnet subdomains (e.g. btcpay.cryptospiracy.com, ghost.bitmainstreetmarket.com) using Socat + NGINX securely.

  1. Install Prerequisites
sudo apt update
sudo apt install -y tor nginx socat certbot python3-certbot-nginx

Copy

  1. Create the socat Systemd Proxy Template
sudo nano /etc/systemd/system/[email protected]

Copy

[Unit]
Description=HTTP-to-SOCKS proxy
After=network.target

[Service]
EnvironmentFile=/etc/http-to-socks-proxy/%i.conf
ExecStart=/usr/bin/socat tcp4-LISTEN:${LOCAL_PORT},reuseaddr,fork,keepalive,bind=127.0.0.1 \
  SOCKS4A:${PROXY_HOST}:${REMOTE_HOST}:${REMOTE_PORT},socksport=${PROXY_PORT}

[Install]
WantedBy=multi-user.target

Copy

  1. Create Socat Proxy Configs (Per Onion Service)
sudo mkdir -p /etc/http-to-socks-proxy
sudo nano /etc/http-to-socks-proxy/btcpayserver.conf

Copy

PROXY_HOST=127.0.0.1
PROXY_PORT=9050
LOCAL_PORT=9081
REMOTE_HOST=chwtrjbg6o5arw5qftdmbqw2xee556zwvoexm5sywmq2nlf36omzpmid.onion
REMOTE_PORT=80

Copy

  1. Enable and Start the Socat Tunnel
sudo systemctl daemon-reload
sudo systemctl enable http-to-socks-proxy@btcpayserver
sudo systemctl start http-to-socks-proxy@btcpayserver
sudo systemctl status http-to-socks-proxy@btcpayserver

Copy

  1. Configure NGINX Proxy
sudo nano /etc/nginx/sites-available/btcpayserver.conf

Copy

server {
  listen 80;
  server_name btcpayserver.mydomain.com;

  # Let's Encrypt verification requests
  location ^~ /.well-known/acme-challenge/ {
    allow all;
    root /var/lib/letsencrypt/;
    default_type "text/plain";
    try_files $uri =404;
  }

  # Redirect everything else to https
  location / {
    return 301 https://$server_name$request_uri;
  }
}

Copy

sudo apt update
sudo apt install -y tor nginx socat certbot python3-certbot-nginx

Copy

sudo ln -s /etc/nginx/sites-available/btcpayserver.conf /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx

Copy

  1. Get SSL Certificate (Only after HTTP block is active)
sudo certbot --nginx -d btcpay.cryptospiracy.com

Copy

  1. Optional: Strengthen TLS (DH Params)
sudo openssl dhparam -out /etc/ssl/certs/dhparam.pem 4096

Copy

  1. Firewall Setup (Limit Access to Socat Port)
sudo ufw allow from 127.0.0.1 to any port 9081
sudo ufw deny 9081
sudo ufw reload
sudo ufw status numbered

Copy

  1. Repeat for Additional Services
  • Change the port (9082, 9083, etc.)
  • Change the .onion address
  • Use a different systemd config like ghostserver.conf
  • Adjust NGINX site block and domain accordingly (e.g. ghost.bitmainstreetmarket.com)
  1. Health Check
netstat -tulpn | grep socat
sudo systemctl status http-to-socks-proxy@btcpayserver
curl -I https://btcpay.cryptospiracy.com

Copy

You now have a production-ready, secure reverse proxy to a Tor .onion service available via clearnet subdomain using Socat + NGINX + SSL. Repeat for each Tor app you want to expose.

For deeper reference you can visit https://docs.btcpayserver.org/Deployment/ReverseProxyToTor/ on BTCpay Server - #Reverse proxy to Tor

Away designs can explore colours beyond a club's usual home palette. For collectors examining club history, Paris Saint-Germain football jerseys(camisetas del Paris Saint-Germain) names the specific shirt theme under discussion. Care instructions are worth reviewing so colours and printed details remain in good condition.