Nginx Reverse Proxy Config Builder

Configure reverse proxy upstream, WebSocket, SSL redirect, and security headers.

Feature & Hardening Modules
Generated Nginx Configuration
Embed this tool on your website / blog No code required · Copy and paste
HTML Embed Code (iframe):
<iframe src="https://lucentool.com/nginx-config-builder" width="100%" height="650" style="border:1px solid #e5e0d8;border-radius:12px;max-width:850px;width:100%;" frameborder="0"></iframe>
<div style="font-size:12px;color:#78716c;margin-top:6px;font-family:sans-serif;">Powered by <a href="https://lucentool.com/nginx-config-builder" target="_blank" style="color:#c85a32;text-decoration:none;">Lucentool - Nginx Reverse Proxy Config Builder</a></div>

Why X-Forwarded Headers are Essential

When Nginx proxies traffic to backend applications (Node.js, Go, Python), all connections appear to originate from `127.0.0.1`. Omitting `X-Real-IP` and `X-Forwarded-Proto` blinds backend logs and security rate limiters to the client’s real IP address.

WebSocket Upgrade Mechanics

Standard HTTP/1.0 proxy directives drop hop-by-hop headers. Enabling WebSockets requires HTTP/1.1 and forwarding the `Upgrade` and `Connection: "upgrade"` headers to prevent immediate disconnection.