Use Nginx as a reverse proxy to forward Tor traffic to your application while adding caching, compression, and security headers:
# /etc/nginx/sites-available/onion-proxy
upstream backend {
server 127.0.0.1:3000;
keepalive 32;
}
server {
listen 127.0.0.1:8080;
# Compression - reduces data over Tor circuits
gzip on;
gzip_types text/plain text/css application/json application/javascript;
gzip_min_length 256;
# Proxy headers
proxy_set_header Host $host;
proxy_set_header X-Real-IP "";
proxy_set_header X-Forwarded-For "";
proxy_set_header X-Forwarded-Proto http;
# Timeouts tuned for Tor latency
proxy_connect_timeout 30s;
proxy_read_timeout 120s;
proxy_send_timeout 120s;
# Static file caching
location ~* \.(css|js|png|jpg|gif|ico|woff2)$ {
root /var/www/static;
expires 30d;
add_header Cache-Control "public, immutable";
}
location / {
proxy_pass http://backend;
proxy_http_version 1.1;
proxy_set_header Connection "";
}
access_log off;
error_log /dev/null;
}Note the empty X-Real-IP and X-Forwarded-For headers - this prevents your application from seeing any IP address information (all Tor connections come from 127.0.0.1, but stripping these headers is a defense-in-depth measure). Gzip compression is especially valuable for Tor services because it reduces the data that must traverse the high-latency Tor circuit.