Capture the current CyberLux UI, commerce, messaging, and Tor ops updates so local main can be pushed to the remote. Made-with: Cursor
4.3 KiB
CyberLux — production on Tor (.onion)
This app is designed to run behind nginx on loopback, with one Tor v3 hidden service per logical site (hub, wiki, dedicated verticals, shadow /w node). Nginx listens on 127.0.0.1:8080–8122 (see scripts/onion-nodes.json); Tor forwards port 80 on each onion to the matching loopback port. Next.js binds only 127.0.0.1:3000 — never expose 3000 or the nginx loopback ports to the public internet.
Onion hostnames are created locally when Tor first starts; there are no fixed .onion URLs in the repo. Back up /var/lib/tor/*/hs_ed25519_secret_key (the install flow uses scripts/backup-onion-keys.sh).
One-time server setup (Debian/Ubuntu-style)
sudo apt update
sudo apt install -y tor nginx curl nodejs npm build-essential
# Or install Node.js LTS from NodeSource / nvm — `node` and `npm` must be on PATH.
Deploy the app
From the repo root (as the user that will own the process):
./start.sh
This will: regenerate Tor/nginx maps from scripts/onion-nodes.json, npm install, npm run build, install Tor+nginx configs (sudo), wait for hostname files, print every .onion URL, then foreground next start on 127.0.0.1:3000.
For a one-shot prepare (build + Tor/nginx, no Next.js — for systemd):
CYBERLUX_PREPARE_ONLY=1 ./start.sh
systemd — start on boot
- Ensure
./start.shorCYBERLUX_PREPARE_ONLY=1 ./start.shhas been run at least once so.nextexists and Tor directories are populated. - Install the unit (run as root; set user to the account that owns the repo):
sudo CYBERLUX_USER=youruser bash scripts/install-systemd.sh
# optional: sudo CYBERLUX_CHOWN_REPO=1 CYBERLUX_USER=youruser bash scripts/install-systemd.sh
- Enable Tor, nginx, and CyberLux at boot:
sudo systemctl enable tor.service nginx.service cyberlux.service
# if your distro uses tor@default instead of tor:
# sudo systemctl enable tor@default.service nginx.service cyberlux.service
sudo systemctl start tor.service nginx.service cyberlux.service
- Check logs:
journalctl -u cyberlux.service -f
- Health check (local):
npm run health:stack
- List every
.onionURL and check that each nginx loopback vhost answers (needs Tor running; usesudoif hostname files are root-only):
npm run onions:status
# or:
sudo node scripts/onion-status.cjs
Changing the onion map
- Edit
scripts/onion-nodes.json. - Run
node scripts/generate-onion-config.cjs(ornpm run build, which runs it inprebuild). sudo bash scripts/install-tor-onion.sh- Rebuild/restart the app:
npm run buildandsudo systemctl restart cyberlux.service
502 Bad Gateway on .onion sites
Tor and nginx are working, but nginx proxies to Next.js on 127.0.0.1:3000. A 502 means nothing is listening there (Next is stopped, crashed, or never started after reboot).
-
Confirm (from the repo):
curl -sS -o /dev/null -w "%{http_code}\n" http://127.0.0.1:3000/000= connection refused → Next is down. -
Start Next (pick one):
- Foreground (dev / quick test):
cd /path/to/cyberlux && npm run start:onion— leave the terminal open. - systemd (production):
sudo systemctl start cyberlux.service— ensure the unit is installed (scripts/install-systemd.sh) and enabled. - Full stack script:
./start.sh(builds, configures Tor/nginx if needed, then starts Next).
- Foreground (dev / quick test):
-
Verify again:
npm run health:stackYou want
Next.js: OKandhub vhost: OK(HTTP 200/301/302/304). -
If it still fails:
journalctl -u cyberlux.service -n 80 --no-pager— look for crash loops, missing.next(runnpm run build), or wrongWorkingDirectoryin the unit.
Verification
npm run verify
Security & compliance
- You are responsible for local law, hosting terms, and Tor / relay policies. This repo is a parody web app; treat operational security seriously if you run it on a real server.
Security notes
- Only Tor should be reachable from outside; bind nothing to
0.0.0.0for this stack. - Prefer firewall defaults that deny incoming except what you need for SSH.
- Optional:
sudo bash scripts/classroom-ufw.sh(if present) for a restrictive UFW profile.