Skip to main content

Reverse Proxy

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/reverse-proxy

In short

A reverse proxy is a server that sits in front of web servers, accepts client requests on their behalf, and forwards each request to the right backend server.

What is a reverse proxy?

A reverse proxy is a server placed between the internet and your application servers. Clients connect to the reverse proxy as if it were the website itself, and the proxy forwards each request to a backend server, waits for the response, and passes it back. The client usually never sees or connects to the backend servers directly.

Because every request flows through it, a reverse proxy is a convenient place for shared tasks: terminating HTTPS so backends can use plain HTTP on a private network, caching and compressing responses, routing requests by domain name or URL path to different services, load balancing, and shielding internal servers from direct attacks. Common reverse proxies include NGINX, Apache HTTP Server, HAProxy, Caddy, Traefik, and Envoy, and a Kubernetes ingress controller is a reverse proxy for a whole cluster.

Think of a company receptionist: visitors speak only to the front desk, which passes each request to the right department and returns the answer, so visitors never need to know which office handled it. The word reverse distinguishes it from a forward proxy, which works on behalf of clients instead: a forward proxy sits in front of users, for example on a school or company network, and makes requests to the internet for them.

A reverse proxy is often confused with a load balancer or an API gateway. Load balancing, spreading requests across several identical servers, is one job a reverse proxy can do, while an API gateway is a specialized reverse proxy for APIs that adds features such as authentication, rate limiting, and request transformation. A CDN is also a kind of reverse proxy, spread across many locations around the world.

At a glance

Clients on the internet connect over HTTPS to a reverse proxy at example.com, which ends HTTPS, caches responses and balances load, and passes each request over plain HTTP to one of two app servers hidden on a private network.InternetPrivate networkHTTPSHTTPSHTTPHTTPClientClientReverse proxyexample.comHTTPS terminationCachingLoad balancingApp server10.0.0.2App server10.0.0.3
Clients only ever talk to the proxy. The servers behind it stay private and can be swapped, added or removed without clients noticing.

Key takeaways

  • A reverse proxy receives requests on behalf of backend servers and forwards them.
  • It commonly handles HTTPS termination, caching, compression, and routing.
  • Backend servers can stay hidden on a private network.
  • A forward proxy acts for clients; a reverse proxy acts for servers.
  • Load balancers, API gateways, and CDNs often work as reverse proxies.

Example

An NGINX reverse proxy routing to two local servicesnginx
# Terminate HTTPS here and forward plain HTTP to local backends
server {
    listen 443 ssl;
    server_name example.com;
    ssl_certificate     /etc/ssl/example.com.pem;
    ssl_certificate_key /etc/ssl/example.com.key;

    location /api/ {
        proxy_pass http://127.0.0.1:4000;   # API service
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }
    location / {
        proxy_pass http://127.0.0.1:3000;   # frontend app
    }
}

Readers ask

What is the difference between a forward proxy and a reverse proxy?

A forward proxy sits in front of clients and makes requests to the internet on their behalf, for example to filter or cache traffic on a company network. A reverse proxy sits in front of servers and receives requests from the internet on their behalf.

Is a reverse proxy the same as a load balancer?

Not exactly. A reverse proxy forwards requests to backend servers and can add features like caching and TLS termination, while load balancing is the specific job of spreading requests across several servers. Many reverse proxies also load balance, so the same software often handles both roles.

Why put a reverse proxy in front of a Node.js app?

A reverse proxy can handle HTTPS certificates, compression, static files, and slow clients more efficiently than most application servers. It also lets you run several apps on one server behind a single public port.

Often compared

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings