Set up a Git bare repository on your Tor server that triggers automatic deployments on push. All Git operations happen over Tor SSH, keeping your server anonymous:
# On the server - create bare repo with post-receive hook
mkdir -p /var/git/onion-site.git
cd /var/git/onion-site.git
git init --bare
# Create post-receive hook
cat > hooks/post-receive << 'HOOK'
#!/bin/bash
GIT_WORK_TREE=/var/www/onion git checkout -f main
# Restart application if needed
systemctl restart onion-app
echo "Deployment complete at $(date -u +'%Y-%m-%d %H:%M UTC')"
HOOK
chmod +x hooks/post-receive# On your local machine - configure Git remote over Tor
# Requires torsocks and SSH .onion access
# ~/.ssh/config
Host onion-server
HostName your56charaddress.onion
User deploy
ProxyCommand torsocks nc %h %p
IdentityFile ~/.ssh/onion_deploy_key
# Add remote and push
git remote add onion onion-server:/var/git/onion-site.git
git push onion mainEvery git push to the onion remote triggers the post-receive hook, which checks out the latest code to the web root and restarts the application. The entire process happens over Tor - your development machine's IP is never exposed to the server.