Why X-Forwarded Headers are Essential
When Nginx proxies traffic to backend applications (Node.js, Go, Python), all connections appear to originate from `127.0.0.1`. Omitting `X-Real-IP` and `X-Forwarded-Proto` blinds backend logs and security rate limiters to the client’s real IP address.
WebSocket Upgrade Mechanics
Standard HTTP/1.0 proxy directives drop hop-by-hop headers. Enabling WebSockets requires HTTP/1.1 and forwarding the `Upgrade` and `Connection: "upgrade"` headers to prevent immediate disconnection.