DevOps & Config Tools

Nginx Reverse Proxy Generator

Put Nginx in front of your application servers with a configuration that handles the details: routes from URL paths to upstream groups, load balancing with passive health checks, WebSocket upgrades, X-Forwarded headers, timeouts and keep-alive connections, upload limits, per-IP rate limiting, optional response caching, HTTPS with Let’s Encrypt and security headers.

  • Runs in your browser
  • No sign-up
  • Free to use
Start from an example

Add “websocket” to a route for WebSocket upgrades. Several servers are load-balanced.

Options

    How to use Nginx Reverse Proxy Generator

    1. Enter the domain and HTTPS choice.
    2. List routes as /path -> host:port (add “websocket” where needed).
    3. Choose load balancing, limits, caching and headers.
    4. Save the file, test with nginx -t and reload.

    Nginx Reverse Proxy Generator features

    Path routing

    Each path to its own upstream group.

    Load balancing

    Round robin, least connections or ip_hash with failover.

    WebSockets

    Upgrade handling and long timeouts per route.

    Correct headers

    Host, X-Real-IP, X-Forwarded-For and -Proto.

    Protection

    Rate limiting, upload size and security headers.

    Caching

    proxy_cache that skips logged-in requests.

    When to use Nginx Reverse Proxy Generator

    • Serving a Node.js, Python or Java app behind Nginx.
    • Splitting / and /api/ between front end and back end.
    • Load balancing several application servers.
    • Adding HTTPS in front of an app that only speaks HTTP.

    Nginx Reverse Proxy Generator FAQ

    Why do WebSockets need special settings?

    WebSockets start as an HTTP request with an Upgrade header, which Nginx must forward, and connections stay open for a long time, so the read timeout is raised.

    What does the trailing slash in proxy_pass change?

    Without a URI in proxy_pass, the full path is forwarded (/api/users stays /api/users). With a trailing slash, the matching location prefix is replaced, so /api/users becomes /users.

    How does the app see the client IP?

    From X-Real-IP or X-Forwarded-For. Configure the app to trust the proxy, otherwise it sees 127.0.0.1 for every request.

    Is caching safe for logged-in users?

    The generated cache is bypassed for requests with an Authorization header or a session cookie, so personal pages are not shared.

    How do I get the certificate?

    Use certbot with the webroot method shown in the notes; the HTTP server block already serves the ACME challenge folder.

    Is anything uploaded?

    No. The configuration is generated in your browser.

    Nginx as a reverse proxy

    A reverse proxy sits between clients and application servers. It terminates HTTPS, routes requests to the right backend, balances load, protects backends from slow clients and abuse, and can cache responses. Nginx is the most common choice, but a working configuration needs many directives in the right places.

    Routes map URL prefixes to named upstream groups. Each upstream can contain several servers, balanced round robin, by least connections or by client IP, and servers that fail three times are taken out of rotation for 30 seconds. Keep-alive connections to the upstreams avoid opening a new TCP connection for every request.

    Every proxied request carries the headers backends need: the original Host, the client’s address in X-Real-IP and X-Forwarded-For, and the scheme in X-Forwarded-Proto, so applications generate correct URLs and log real client addresses. WebSocket routes also forward the Upgrade header through a map and keep idle connections open for an hour.

    Protection is built in: client_max_body_size limits uploads, limit_req applies a per-IP request rate with a burst allowance, connect, send and read timeouts stop hanging requests, and security headers such as HSTS, X-Content-Type-Options and X-Frame-Options are added to responses.

    With HTTPS from Let’s Encrypt, a port 80 server answers ACME challenges and redirects everything else to HTTPS, and the HTTPS server uses modern TLS versions with HTTP/2. Optionally, www is redirected to the bare domain.

    Other useful tools