Reverse Proxy

NGINX in front of the app. The app stays on its own port.

A Node, Docker or Apache service that should not be on port 80. We set the proxy, the websocket headers and the real client IP. The VPS stays yours.

What gets configured

Upstream, headers, the certificate on the edge

Upstream

127.0.0.1 and the port the app actually listens on. A 502 here is a dead upstream, not a DNS fault. We do not proxy to a public IP on the same machine.

Websockets and the client IP

Upgrade headers if the app needs them. X-Forwarded-For and the real IP, so logs and Fail2Ban are not full of 127.0.0.1.

TLS

The certificate terminates on NGINX. The upstream can stay HTTP on localhost. Terminating twice, without reason, is how a redirect loop starts.

Panel

A hand-written proxy in a generated vhost will disappear

Hestia and DirectAdmin rebuild site files. The proxy goes in a template or an include they keep. Cloudflare in front of this is a second proxy. We say if the second one is doing nothing.

NGINX support → · NGINX consulting →

Price

€55 an hour. One app is usually one hour.

Minimum 1 hour. Several apps, or a Docker network we have not seen, is quoted after the ports are known. We do not write the application.

Pricing →

App on a high port, and nothing answers on 443?

Tell us the port and whether a panel is installed. No root password in the first message.

Request Support → Contact Us