← Stack
LEARNING·Since 2026

Nginx

Web server, reverse proxy, TLS termination

About

A high-performance web server and reverse proxy. Accepts public HTTP and HTTPS connections, terminates TLS, serves static files, forwards requests to internal services, and can distribute traffic across multiple backend instances.

Why

Needed a public entry point for the webhook API. Nginx handles HTTPS and forwards traffic to the backend, so the application doesn't need to deal with certificates or public ports directly.

Notes

First real deployment where I configured the whole path: DNS → Nginx → HTTPS → Docker backend. Seeing proxy_pass forward a request into the container and return a real response was the moment reverse proxies stopped being abstract.

Nginx owns the public boundary. The backend only listens inside the Docker network, while Nginx handles TLS termination, redirects HTTP to HTTPS, and passes the original host and client information through headers.

The config is small, but every line has a purpose. Certbot handles the certificate, Nginx serves the public endpoint, and the application stays focused on application logic.