Besides using a separate port, I would also suggest running the hidden service on a non-127.0.0.1 bind address, just in case you ever host something else on that port and forget to disable the hidden service:
> HiddenServicePort 80 127.13.37.1:8080
> listen 127.13.37.1:8080;
This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.
You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.
It's also possible to use a Unix socket, which can have a descriptive pathname like /var/run/my-service.sock: <a href="https://stackoverflow.com/questions/69313114/using-nginx-to-host-tor-hidden-service-through-unix-socket" rel="nofollow">https://stackoverflow.com/questions/69313114/using-nginx-to-...
AFAIK TCP outperforms Unix sockets for some odd reason, but it's irrelevant anyway because you aren't getting that much bandwidth through Tor.
mzajc · · focus · HN ↗
> HiddenServicePort 80 127.13.37.1:8080
> listen 127.13.37.1:8080;
This way, strangers won't be able to connect to a service bound to 127.0.0.1, should you ever decide to re-use the port and forget to disable the hidden service.
You'll also need to use separate ports and/or bind addresses if you host multiple hidden services and don't want people to correlate them - if nginx doesn't match the Host header, it will serve whichever site comes first alphabetically.
someonebaggy · · focus · HN ↗
m00dy · · focus · HN ↗
BonerWiener · · focus · HN ↗
Tepix · · focus · HN ↗
someonebaggy · · focus · HN ↗