Architecture

Browser --HTTPS--> Reverse proxy --loopback--> Application worker

Network boundaries

Bind an internal application worker to localhost or a private interface, not all public interfaces, unless it is separately protected. Restrict firewall ingress to required public ports.

Trusted forwarded headers

Accept forwarding metadata only from known proxy addresses. Arbitrary clients must not be able to spoof origin protocol or identity through untrusted forwarded headers.

Required controls

  • A valid TLS certificate with functioning renewal
  • Bounded request bodies and connection timeouts
  • Health monitoring of both proxy and backend
  • Logs that do not expose credentials or full authorization headers
  • An explicit upgrade and rollback method

Final test

Check application URL generation, redirects, cookies, large uploads and backend unreachability. Follow Nginx documentation for exact configuration syntax.

Editorial note

Examples are starting points, not production security audits. Confirm dependencies, versions and pricing using linked vendor documentation.