As for the backend servers - if all machines are connected through OpenVPN with TLS-Auth they can use private IP space and are not accessible from outside. The OpenVPN tunnels are configured outside of the onion VM and Tor VM and the backend machines are also in a VM that pipes all outgoing traffic (except OpenVPN traffic) to the internet through Tor.
This setup should at least omit the problem of leaking public IP addresses on compromise or did I overlook something? Let's ignore VM outbreak exploits (ksplice/unattenend-upgrades should help here if it's not the NSA).
With TLS-Auth and a default DROP firewall rule all machines should not even appear in scans on the internet. So any outside contact to any machines is only possible if you know the OpenVPN TLS-Key + Certificates. An intruder would only see local IP addresses even if he manages to compromise a backend server. All created outgoing traffic to find the machines would be routed through Tor.
As the Tor onion VM is separate from the webserver only a Tor remote exploit or a VM outbreak exploit would be critical. Maybe encryption can help here.
Another point is using dedicated hardware with Full Disk Encryption and just enter the passphrase via the provider console. There are cold boot attacks but VPS servers allow to dump a memory image while running - that's not so easy with dedicated hardware.