http://y7egb5vi45k74makeixpfb7jnimfxm3gf233lb3ke2ldonozjk55nvad.onion/about_hidden_services.html
There are a lot of rules both
from an operational and security standpoint, so I recommend you read
this excellent guide to find the latest best practices all in one
place. Without diving into all of those steps, I do want to list a few
general-purpose guidelines here. First, you’ll want to make sure that
whatever service you are hosting is listening only on localhost
(127.0.0.1) and isn’t viewable via the regular internet.