Nginx Reverse Proxy Generator
Put Nginx in front of your application servers with a configuration that handles the details: routes from URL paths to upstream groups, load balancing with passive health checks, WebSocket upgrades, X-Forwarded headers, timeouts and keep-alive connections, upload limits, per-IP rate limiting, optional response caching, HTTPS with Let’s Encrypt and security headers.
- Runs in your browser
- No sign-up
- Free to use
How to use Nginx Reverse Proxy Generator
- Enter the domain and HTTPS choice.
- List routes as /path -> host:port (add “websocket” where needed).
- Choose load balancing, limits, caching and headers.
- Save the file, test with nginx -t and reload.
Nginx Reverse Proxy Generator features
Path routing
Each path to its own upstream group.
Load balancing
Round robin, least connections or ip_hash with failover.
WebSockets
Upgrade handling and long timeouts per route.
Correct headers
Host, X-Real-IP, X-Forwarded-For and -Proto.
Protection
Rate limiting, upload size and security headers.
Caching
proxy_cache that skips logged-in requests.
When to use Nginx Reverse Proxy Generator
- Serving a Node.js, Python or Java app behind Nginx.
- Splitting / and /api/ between front end and back end.
- Load balancing several application servers.
- Adding HTTPS in front of an app that only speaks HTTP.
Nginx Reverse Proxy Generator FAQ
Why do WebSockets need special settings?
WebSockets start as an HTTP request with an Upgrade header, which Nginx must forward, and connections stay open for a long time, so the read timeout is raised.
What does the trailing slash in proxy_pass change?
Without a URI in proxy_pass, the full path is forwarded (/api/users stays /api/users). With a trailing slash, the matching location prefix is replaced, so /api/users becomes /users.
How does the app see the client IP?
From X-Real-IP or X-Forwarded-For. Configure the app to trust the proxy, otherwise it sees 127.0.0.1 for every request.
Is caching safe for logged-in users?
The generated cache is bypassed for requests with an Authorization header or a session cookie, so personal pages are not shared.
How do I get the certificate?
Use certbot with the webroot method shown in the notes; the HTTP server block already serves the ACME challenge folder.
Is anything uploaded?
No. The configuration is generated in your browser.
Nginx as a reverse proxy
A reverse proxy sits between clients and application servers. It terminates HTTPS, routes requests to the right backend, balances load, protects backends from slow clients and abuse, and can cache responses. Nginx is the most common choice, but a working configuration needs many directives in the right places.
Routes map URL prefixes to named upstream groups. Each upstream can contain several servers, balanced round robin, by least connections or by client IP, and servers that fail three times are taken out of rotation for 30 seconds. Keep-alive connections to the upstreams avoid opening a new TCP connection for every request.
Every proxied request carries the headers backends need: the original Host, the client’s address in X-Real-IP and X-Forwarded-For, and the scheme in X-Forwarded-Proto, so applications generate correct URLs and log real client addresses. WebSocket routes also forward the Upgrade header through a map and keep idle connections open for an hour.
Protection is built in: client_max_body_size limits uploads, limit_req applies a per-IP request rate with a burst allowance, connect, send and read timeouts stop hanging requests, and security headers such as HSTS, X-Content-Type-Options and X-Frame-Options are added to responses.
With HTTPS from Let’s Encrypt, a port 80 server answers ACME challenges and redirects everything else to HTTPS, and the HTTPS server uses modern TLS versions with HTTP/2. Optionally, www is redirected to the bare domain.