Reverse Proxy
In short
A reverse proxy is a server that sits in front of web servers, accepts client requests on their behalf, and forwards each request to the right backend server.
What is a reverse proxy?
A reverse proxy is a server placed between the internet and your application servers. Clients connect to the reverse proxy as if it were the website itself, and the proxy forwards each request to a backend server, waits for the response, and passes it back. The client usually never sees or connects to the backend servers directly.
Because every request flows through it, a reverse proxy is a convenient place for shared tasks: terminating HTTPS so backends can use plain HTTP on a private network, caching and compressing responses, routing requests by domain name or URL path to different services, load balancing, and shielding internal servers from direct attacks. Common reverse proxies include NGINX, Apache HTTP Server, HAProxy, Caddy, Traefik, and Envoy, and a Kubernetes ingress controller is a reverse proxy for a whole cluster.
Think of a company receptionist: visitors speak only to the front desk, which passes each request to the right department and returns the answer, so visitors never need to know which office handled it. The word reverse distinguishes it from a forward proxy, which works on behalf of clients instead: a forward proxy sits in front of users, for example on a school or company network, and makes requests to the internet for them.
A reverse proxy is often confused with a load balancer or an API gateway. Load balancing, spreading requests across several identical servers, is one job a reverse proxy can do, while an API gateway is a specialized reverse proxy for APIs that adds features such as authentication, rate limiting, and request transformation. A CDN is also a kind of reverse proxy, spread across many locations around the world.
At a glance
Key takeaways
- A reverse proxy receives requests on behalf of backend servers and forwards them.
- It commonly handles HTTPS termination, caching, compression, and routing.
- Backend servers can stay hidden on a private network.
- A forward proxy acts for clients; a reverse proxy acts for servers.
- Load balancers, API gateways, and CDNs often work as reverse proxies.
Example
# Terminate HTTPS here and forward plain HTTP to local backends
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/ssl/example.com.pem;
ssl_certificate_key /etc/ssl/example.com.key;
location /api/ {
proxy_pass http://127.0.0.1:4000; # API service
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
location / {
proxy_pass http://127.0.0.1:3000; # frontend app
}
}Readers ask
What is the difference between a forward proxy and a reverse proxy?
A forward proxy sits in front of clients and makes requests to the internet on their behalf, for example to filter or cache traffic on a company network. A reverse proxy sits in front of servers and receives requests from the internet on their behalf.
Is a reverse proxy the same as a load balancer?
Not exactly. A reverse proxy forwards requests to backend servers and can add features like caching and TLS termination, while load balancing is the specific job of spreading requests across several servers. Many reverse proxies also load balance, so the same software often handles both roles.
Why put a reverse proxy in front of a Node.js app?
A reverse proxy can handle HTTPS certificates, compression, static files, and slow clients more efficiently than most application servers. It also lets you run several apps on one server behind a single public port.
Often compared
- Reverse Proxy vs Load BalancerA reverse proxy forwards requests to the servers behind it and adds TLS, caching and security, while a load balancer spreads load so no server is overloaded.
- Proxy vs Reverse ProxyA forward proxy sits in front of clients and sends their requests to the internet; a reverse proxy sits in front of servers and takes requests for them.
See also
- Load BalancerDevOps & Cloud, p. 34A load balancer is a server or service that spreads incoming traffic across several backend servers so no single one is overloaded and the app stays available.
- API GatewayBackend & APIs, p. 3An API gateway is a server that sits in front of a group of backend services and acts as the single entry point that receives, checks, and routes API requests.
- CDNDevOps & Cloud, p. 7A CDN is a network of servers spread around the world that stores copies of website content and delivers it to each user from the nearest location.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- CacheBackend & APIs, p. 8A cache is a fast, temporary storage layer that keeps copies of frequently used data so later requests can be served quickly without repeating slow work.
- NginxBackend & APIs, p. 31Nginx is a fast, open-source web server that is also widely used as a reverse proxy, load balancer and HTTP cache in front of application servers.
- Proxy ServerNetworking, p. 23A proxy server is an intermediary that receives network requests on behalf of clients or servers and passes them on, adding control, caching, or privacy.
Spotted a mistake or something missing on this page?Suggest an edit