What is a reverse proxy?

A server that stands in front of your other servers, takes every request and decides who answers. What it does, when you need one, and a working Nginx example.

1–2 minutes
Network switch with many blue patch cables

A reverse proxy is a server that sits in front of one or more other servers and receives visitors’ requests on their behalf. The visitor talks only to the proxy. The proxy decides which server behind it should answer, passes the request along, and returns the reply as if it had produced it itself.

Forward proxy or reverse proxy?

Forward proxyReverse proxy
Works forThe people browsingThe website
Sits next toThe usersThe servers
HidesWhich user made the requestWhich server answered it
Typical useOffice web filters, privacy toolsHTTPS, load balancing, caching

What it is for

  • One public address, many apps. A blog, a shop and an API can each run on their own internal port while visitors only reach 80 and 443.
  • HTTPS in one place. The proxy holds the certificates; the apps behind it never deal with them.
  • Load balancing. The proxy shares traffic across several servers and skips any that fail.
  • Caching. It can serve stored copies of pages without waking the app. See caching.
  • A smaller attack surface. App servers are not reachable from the internet.

A working example with Nginx

A Node.js app listens on port 3000 of the same machine, and you want it at app.example.com:

server {
    listen 80;
    server_name app.example.com;

    location / {
        proxy_pass http://127.0.0.1:3000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

proxy_pass makes it a reverse proxy. The proxy_set_header lines pass along details the app would otherwise lose: the requested domain, the visitor’s real IP, and whether they used HTTPS.

sudo nginx -t
sudo systemctl reload nginx

502 Bad Gateway on AlmaLinux, Rocky or RHEL? SELinux stops Nginx connecting to other ports by default. Allow it with sudo setsebool -P httpd_can_network_connect 1. Do not switch SELinux off. More causes in fixing 502 Bad Gateway.

Do you need one?

A single WordPress or PHP site already has what it needs. A reverse proxy earns its place when you run several apps on one server, run an app with its own built-in web server (Node.js, Python, Go, Java), or spread traffic over more than one machine.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.