The sidecar pattern runs a Tor container alongside your application container in the same pod. Both containers share the localhost network, so Tor forwards .onion traffic directly to your app:
# tor-deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: onion-service
spec:
replicas: 1
selector:
matchLabels:
app: onion-service
template:
metadata:
labels:
app: onion-service
spec:
containers:
- name: web
image: nginx:alpine
ports:
- containerPort: 80
volumeMounts:
- name: site-content
mountPath: /usr/share/nginx/html
- name: tor
image: custom-tor:latest
volumeMounts:
- name: tor-keys
mountPath: /var/lib/tor/hidden_service
volumes:
- name: tor-keys
persistentVolumeClaim:
claimName: tor-keys-pvc
- name: site-content
configMap:
name: site-contentThe Tor container uses a PersistentVolumeClaim to store onion keys, ensuring your .onion address persists across pod restarts and rescheduling. The web container is only accessible via localhost within the pod - no Kubernetes Service or Ingress is needed.