While this is good advice and will help you in the event of your server accidentally leaking debugging/config information, it won't help if someone is able to get the hidden service to make a network request. For example, if they can get it to send an email or check if a page is online, then that email will obviously go through the gateway. And obviously if someone gains arbitrary code execution, they can just Google "my IP" and see the externally facing IP.
Some other useful advice: if you're setting up a Tor hidden service, make sure the HTTP server only accepts requests from the Tor network. The FBI claims that when they put the $_SERVER['SERVER_ADDR'] IP in their browser they got the SR home page right on port 80, which is extremely poor security on SR's part. Someone running a distributed scan of all web servers on the Internet could have found it on their own within a few weeks or less. And in fact, this is becoming more common as a technique to identify origin servers hidden behind reverse proxies and CDNs.