Glossary Term
Reverse Proxy
A reverse proxy sits in front of origin servers and forwards client requests to them. Learn the headers it adds, nginx proxy_pass pitfalls and 502/504 causes.
TL;DR: A reverse proxy is the server clients actually connect to. It forwards requests to one or more backends and returns their responses, adding TLS, routing, caching or load balancing on the way.
A reverse proxy is an intermediary that sits in front of one or more origin servers and presents itself to clients as if it were the origin. nginx, HAProxy, Envoy, Caddy, Traefik and cloud load balancers all play this role. The client never sees the backend address, and the backend sees the proxy as its client.
A typical nginx configuration
location /api/ {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
The backend then receives headers like these, with the real client address only available in the forwarded header:
GET /api/me HTTP/1.1
Host: www.example.com
X-Forwarded-For: 203.0.113.9
X-Forwarded-Proto: https
Non-obvious facts
- nginx rewrites
Hostby default. Withoutproxy_set_header Host $host, the upstream receivesHost: $proxy_host(theproxy_passhostname), so apps that build absolute URLs or route by virtual host misbehave. - Upstream connections are not kept alive by default. nginx talks to upstreams over HTTP/1.0 and closes the connection each time. For keep-alive to a backend you need
proxy_http_version 1.1;,proxy_set_header Connection "";and anupstreamblock withkeepalive. - Client IP headers are spoofable. A client can send its own
X-Forwarded-For. Configure your app to trust only the proxy addresses or hop count you operate. - The proxy generates 502 and 504, not your app. If the error page body is the proxy’s, the backend never answered properly. Check the proxy error log first.
- Proxies can cache. A caching reverse proxy distributed across regions is a CDN.
Go deeper
Frequently asked questions
What is the difference between a forward proxy and a reverse proxy?
A forward proxy acts for clients and reaches out to many servers. A reverse proxy acts for servers: clients talk to it as if it were the site, and it chooses the backend.
How does the backend learn the real client IP behind a reverse proxy?
From headers the proxy adds, typically X-Forwarded-For or the standard Forwarded header. The backend must only trust them when the request came from its own proxy.
Why do I get 502 or 504 from a reverse proxy?
502 means the proxy got an invalid response or could not connect to the upstream. 504 means the upstream did not answer within the proxy timeout.
Can a reverse proxy terminate TLS?
Yes, and it commonly does. The proxy handles HTTPS with the client and talks plain HTTP or a second TLS connection to the backend, which is why X-Forwarded-Proto matters.
Sources
Related
X-Forwarded-For
X-Forwarded-For carries the client IP through proxies and load balancers, but clients can forge it. Trust it safely in nginx, Express, Cloudflare and AWS.
nginx 502 Bad Gateway: Causes and Fixes by Error Log
Fix nginx 502 Bad Gateway by matching the error log: connection refused, prematurely closed connection, php-fpm socket permissions, too big header, keepalive.
nginx 504 Gateway Timeout: Fix Upstream Timed Out (110)
Fix nginx 504 Gateway Time-out and 'upstream timed out (110)': proxy_read_timeout, fastcgi_read_timeout, ALB idle timeout, and Cloudflare 524 compared.
Forwarded
Learn how the Forwarded header preserves original client information (IP, protocol, host) that would otherwise be lost when requests pass through proxies.