What is a reverse proxy?
A reverse proxy is a middle person. Visitors talk to Nginx. Nginx passes the request to your app, gets the answer and sends it back. Your app might run on port 3000, which is a poor address for visitors. With a reverse proxy, they simply use yourdomain.com.
This guide assumes an app already runs at http://127.0.0.1:3000.
Steps
- Log in to your server with SSH as root or a user with
sudo. - Install Nginx:
sudo dnf install nginx -y
- Start it and make it start at boot:
sudo systemctl enable --now nginx
- Open web ports in the firewall:
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
- Create a settings file for your site:
sudo nano /etc/nginx/conf.d/myapp.conf
- Paste this in. Change the domain name:
server {
listen 80;
server_name yourdomain.com;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
The proxy_pass line sends traffic to your app. The proxy_set_header lines tell the app who the real visitor is.
- Save the file. In nano, press Ctrl + O, Enter, Ctrl + X.
- Allow Nginx to talk to your app. SELinux is a security guard on AlmaLinux that blocks this by default:
sudo setsebool -P httpd_can_network_connect 1
- Test the settings:
sudo nginx -t
- Reload Nginx:
sudo systemctl reload nginx
- Open your domain in a browser. You should see your app.
If you see "502 Bad Gateway"
- Check that your app is running on the port you wrote.
- Check that the SELinux command in step 8 was run.
Tip: Your domain's DNS must point to your server's IP address. Add HTTPS afterwards with a certificate tool such as Certbot.
Quick recap
- A reverse proxy passes visitors to your hidden app.
- Install Nginx, open the firewall, add a config file.
- Use
proxy_passto point to the app. - Enable the SELinux option, test and reload.