7 ms·
Reverse proxy deep dive (2024)
- shelajev 1y agoIt took me an embarrassingly long time to internalize what the reverse proxy is. My brain got stuck on the fact that it is just proxying requests. What's so reverse about this? Silly.
- rini17 1y agoSince web proxy was originally used near clients, caching stuff to save precious bandwidth of their kbps-tier connection.
- happytoexplain 1y agoIt's one of the classic cases of a thing being named relative to what came before it, rather than being named on its own merit. This makes sense to people working at the time the new thing is introduced, but is confusing to every other learner in the future.
- nosianu 1y agoCould be worse. All the many things named after people prevalent in some fields more than in others, biology/medicine for example. When you read, for example, "loop of Henle" or "circle of Willis" you don't even know where to begin. You either know the term or not.
- happytoexplain 1y agoTrue, though I think it's often a larger challenge to capture the intrinsic quality of a medicinal compound or physiological feature than a man-made tool.
- raincom 1y agoWhat came before "reverse proxies"? Just curious to understand the history.
- p_ing 1y agoForward proxies, proxies where client machines were configured to route all their outbound traffic through (similar to a router). Usually performed caching back in the day when the Internet tube was slow, later on got SSL decryption capabilities and filtering lists to make sure you stay off of your naughty sites and so the proxy admin could decrypt your banking credentials.
- azaras 1y agoNowadays, "reverse" is suppressed in most ways. I have heard that Nginx is a proxy more often than a reverse proxy.
- Valodim 1y agoExcept in the configuration where you use the reversep_proxy directive, of course
- daveguy 1y agoHow about service proxy vs web proxy rather than reverse proxy and proxy? Makes more clear that one is a proxy on the service side and the other is a proxy on the client side. Service proxy and Client proxy might be even better.
- MortyWaves 1y agoCaddy, Nginx, Traefik seem to be the most popular reverse proxies in the self hosting/homelab communities. I definitely prefer Caddy in my experience, so far.
- lowwave 1y agoIs there a reverse proxies that can support DTLS support out of box without some kind experimental patch[1]? 1: https://nginx.org/patches/dtls/ https://nginx.org/patches/dtls/
- joshbaptiste 1y agoTrying out ferron recently as a reverse proxy https://www.ferronweb.org/ https://www.ferronweb.org/.. config is super simple
- ethan_smith 1y agoHAProxy deserves a mention alongside those - it's particularly strong for high-traffic production environments where its advanced load balancing algorithms and detailed metrics shine.
- p_ing 1y agoI would argue this is the best mainstream proxy. Even better when paired with OpenBSD and CARP.
- somehnguy 1y agoCaddy has been excellent for me thus far as well. I'm using it on a VPS to reverse proxy to the services I run at home via a Tailscale tunnel. Coming from Nginx in the past Caddy was drop-dead simple to configure. The entire config for each vhost is 3 lines, including the domain definition and closing brace - and that includes TLS!
- MortyWaves 1y agoJust curious if you have Caddy running in Docker or normal?
- leptons 1y ago[flagged]
- vojtechrichter 1y agoAmazing read, I personally find it fascinating to make my own load balancer.
- jeffbee 1y agoI would say the bullet points at the top are not strictly correct. The response does not necessarily transit the proxy. Responses can be returned directly to the client (DSR).
- nyrikki 1y ago> Note: For simplicity, we’ll focus on Layer 7 (HTTP) reverse proxy. Layer 4 proxies are a very specific sometimes food that most people should actively avoid until they need it because of the tradeoffs. DSR is layer 4, and not in scope of this post.
- jeffbee 1y agoYour comment, to me, only points out that the OSI layer model is nonsense. Envoy in DSR mode routes traffic based on application features, at "layer 7".
- nyrikki 1y agoEnvoy calls it Layer 4 https://blog.envoyproxy.io/introduction-to-modern-network-load-balancing-and-proxying-a57f6ff80236 https://blog.envoyproxy.io/introduction-to-modern-network-lo...
- jeffbee 1y agoThat's fair. Of course that post also calls the OSI model "unfortunate" and "a poor approximation".
- nyrikki 1y agoAll models are wrong, some are useful. Layer 4 to 7 is useful in this case, as layer 4 involves forging tcp/udp packets, which is vastly different than say a http level reverse proxy.
- 1y ago
- tdiff 1y agoReally looks like an ai-generated overview.
- philwelch 1y agoOriginal, Medium-free URL is https://startwithawhy.com/reverseproxy/2024/01/15/ReverseProxy-Deep-Dive.html https://startwithawhy.com/reverseproxy/2024/01/15/ReversePro... Meta request: can we change the URL to the original source? This isn’t quite blogspam (since it’s the same author reposting the same piece onto Medium) but Medium is annoying enough that I’d still rather resolve to the original source
- imcotton 1y agoThanks, I have being putting medium domain into dns blocklist for years.
- mdaniel 1y agoThe alternative is the amazing scribe.rip -> https://scribe.rip/@mitendra_mahto/cross-posted-from-https-startwithawhy-com-reverseproxy-2024-01-15-reverseproxy-deep-dive-html-c3443dc3e0e5 https://scribe.rip/@mitendra_mahto/cross-posted-from-https-s...
- Quarrel 1y agoWow. Thanks for this. Setting up redirects now. Medium is terrible.
- luckman212 1y agoHow do you set up those automatic redirects if I might ask?
- Quarrel 1y agoIn the end I just used a greasemonkey script. There are several on greasyfork.
- tomhow 1y agoWe're late to this but have changed the URL now.
- raincom 1y agoWhat's the difference between Reverse proxy and forward proxy? Is there something like "intermediate proxy"? Is this concept of L7 proxy, similar to DNAT/SNAT or Port forwarding in L3/L4?
- p_ing 1y agoTL;DR: Forward Proxy == protects clients; Reverse Proxy == protects server https://en.wikipedia.org/wiki/Proxy_server#Forward_proxy_vs._reverse_proxy https://en.wikipedia.org/wiki/Proxy_server#Forward_proxy_vs....