NGINX in front of the app. The app stays on its own port.
A Node, Docker or Apache service that should not be on port 80. We set the proxy, the websocket headers and the real client IP. The VPS stays yours.
Upstream, headers, the certificate on the edge
127.0.0.1 and the port the app actually listens on. A 502 here is a dead upstream, not a DNS fault. We do not proxy to a public IP on the same machine.
Upgrade headers if the app needs them. X-Forwarded-For and the real IP, so logs and Fail2Ban are not full of 127.0.0.1.
The certificate terminates on NGINX. The upstream can stay HTTP on localhost. Terminating twice, without reason, is how a redirect loop starts.
A hand-written proxy in a generated vhost will disappear
Hestia and DirectAdmin rebuild site files. The proxy goes in a template or an include they keep. Cloudflare in front of this is a second proxy. We say if the second one is doing nothing.
€55 an hour. One app is usually one hour.
Minimum 1 hour. Several apps, or a Docker network we have not seen, is quoted after the ports are known. We do not write the application.
App on a high port, and nothing answers on 443?
Tell us the port and whether a panel is installed. No root password in the first message.
