Architecture
Browser --HTTPS--> Reverse proxy --loopback--> Application worker
Network boundaries
Bind an internal application worker to localhost or a private interface, not all public interfaces, unless it is separately protected. Restrict firewall ingress to required public ports.
Trusted forwarded headers
Accept forwarding metadata only from known proxy addresses. Arbitrary clients must not be able to spoof origin protocol or identity through untrusted forwarded headers.
Required controls
- A valid TLS certificate with functioning renewal
- Bounded request bodies and connection timeouts
- Health monitoring of both proxy and backend
- Logs that do not expose credentials or full authorization headers
- An explicit upgrade and rollback method
Final test
Check application URL generation, redirects, cookies, large uploads and backend unreachability. Follow Nginx documentation for exact configuration syntax.
Editorial note
Examples are starting points, not production security audits. Confirm dependencies, versions and pricing using linked vendor documentation.