What is a reverse proxy?
A reverse proxy is like a receptionist. Visitors talk to Apache on the normal web ports. Apache then passes each request to another program running behind it and brings back the answer. Visitors never see the other program. This is useful for apps that listen on odd ports, like 3000.
mod_proxy is the Apache module that does this job. A module is a small add-on for Apache. Root is the all-powerful admin account. Sudo means "run this command as the admin".
Steps (Ubuntu or Debian)
- Log in to your server with SSH.
- Turn on the needed modules.
sudo a2enmod proxy proxy_http headers - Create a site file.
sudo nano /etc/apache2/sites-available/myapp.conf - Add this content. Change the domain and the port to match your app.
<VirtualHost *:80> ServerName app.example.com ProxyPreserveHost On ProxyPass / http://127.0.0.1:3000/ ProxyPassReverse / http://127.0.0.1:3000/ </VirtualHost>ProxyPasssends requests to your app.ProxyPassReversefixes the addresses in the replies.127.0.0.1means "this same server". - Save the file. In nano, press
Ctrl+O,Enter, thenCtrl+X. - Turn the site on.
sudo a2ensite myapp.conf - Test the config for typos.
You want to seesudo apachectl configtestSyntax OK. - Reload Apache.
sudo systemctl reload apache2 - Open your domain in a browser. You should see your app.
On CentOS-style systems
The modules are usually on already. Put the same VirtualHost block in a file inside /etc/httpd/conf.d/, for example myapp.conf. Test with httpd -t and reload with sudo systemctl reload httpd. If you see an error with SELinux on, run sudo setsebool -P httpd_can_network_connect 1.
Check that your app is running
Run curl http://127.0.0.1:3000 on the server. If it answers, the app is up. If not, start the app first.
Quick recap
- A reverse proxy passes visitors to a hidden app.
- Enable
proxyandproxy_http. - Use
ProxyPassandProxyPassReversein a VirtualHost. - Run a config test before you reload.