DevOps45-70 min
Nginx Reverse Proxy for Node.js
Configure Nginx as a reverse proxy, pass real client headers, enable gzip, and serve static assets efficiently.
NginxNode.jsLinuxTLS
Prerequisites
- A Linux server running your Node.js app on an internal port.
- A domain pointing to the server.
- Nginx installed.
1
Plan the implementation
Start by choosing the exact page, route, API, or deployment surface you want to improve. A narrow target makes the implementation measurable and easier to verify.
- Write down the current behavior and the user-facing problem it creates.
- Pick one measurable success signal such as bundle size, latency, error rate, security coverage, or UI responsiveness.
- Identify the files, routes, providers, and environment variables involved.
- Create a rollback note before changing production-sensitive configuration.
2
Set up the required tools
Install or configure only the tools needed for this implementation. Keep config close to the feature so future developers can find the moving parts quickly.
Implementation snippet
sudo nginx -t
sudo systemctl status nginxChecklist
- Dependencies are added to the correct workspace package.
- Environment variables are documented in `.env.example` when needed.
- Local development still starts without production-only secrets.
- The change is small enough to review in one pull request.
3
Implement the core pattern
- Run the Node.js app on localhost instead of binding it publicly.
- Create an Nginx server block for your domain.
- Proxy requests to the internal Node.js port.
- Forward host, protocol, and client IP headers.
- Add TLS with Certbot or your infrastructure provider.
Implementation snippet
server {
listen 80;
server_name example.com;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}4
Handle edge cases
Checklist
- Nginx config passes `nginx -t`.
- The app receives the correct original protocol and host.
- Static files use caching and compression.
- Only Nginx exposes public ports 80 and 443.
5
Verify before production
- Run the app locally and test the normal success path.
- Test one failure path, one empty state, and one slow-network or retry path.
- Run the project build and any related unit or integration tests.
- Check browser console, server logs, and network responses for hidden warnings.
- Document the final behavior, commands used, and any follow-up work.