All Tools View Categories About Contact Privacy

Nginx Docker Reverse Proxy Generator

Reverse-proxy a Docker container by its network hostname.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your Docker reverse proxy will appear here.
-
lines
-
blocks

About Nginx Docker Reverse Proxy Generator

Containerized apps usually should not be exposed directly; instead nginx reverse-proxies them by their Docker network hostname. The tricky part is getting the hostname resolution, the upstream block, and the forwarded headers right - and a typo in the container name means a 502 at best. The Nginx Docker Reverse Proxy Generator builds an upstream plus a server block that proxy_pass to your container by hostname and port, then validates the result.

At the heart of the configuration are a handful of directives. upstream defines a named pool pointing at the container hostname and port. server (in upstream) adds the single container backend as host:port. proxy_pass forwards matched requests to the named upstream. proxy_set_header rewrites Host and the X-Forwarded-* chain so the app sees the real client. proxy_http_version pins HTTP/1.1 so keep-alive works through the proxy. server_name binds the public domain to this proxied server block. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. Proxying a port the container does not listen on yields 502s, so the generator validates the container port range. Using the published host port instead of the in-container port is a common mistake; the tool proxies the container port you give. Forgetting X-Forwarded-* hides the real client IP from the app, so they are added by default. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • upstream - defines a named pool pointing at the container hostname and port.
  • server (in upstream) - adds the single container backend as host:port.
  • proxy_pass - forwards matched requests to the named upstream.
  • proxy_set_header - rewrites Host and the X-Forwarded-* chain so the app sees the real client.
  • proxy_http_version - pins HTTP/1.1 so keep-alive works through the proxy.
  • server_name - binds the public domain to this proxied server block.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Enter the public domain the proxy serves.
  2. Enter the container hostname from the Docker network.
  3. Enter the container port the app listens on.
  4. Optionally set the upstream name (defaults to the hostname).
  5. Click Generate (or Load sample) and review the blocks.
  6. Drop it into conf.d and run nginx -t.
  7. Ensure nginx shares the container network.

Examples

Example 1 - Simple app domain example.com proxying container "app" on port 3000 - a standard Compose setup.

Example 2 - API container upstream named api proxying container api on 8080.

Example 3 - Bad hostname rejected a container hostname with a space is reported as an error.

Example 4 - Out-of-range port container port 70000 is rejected as invalid.

Example 5 - IPv4 container host a numeric container host is accepted as valid.

Benefits

  • Correct upstream + server block emitted together.
  • Container hostname and port validated.
  • X-Forwarded-* headers added by default.
  • Named upstream ready to scale to more replicas.
  • Self-checked output re-parsed before display.
  • Private: everything runs in your browser.

Frequently Asked Questions

What hostname do I use?
Use the service name from your Docker Compose file or the container name on the shared network; nginx resolves it via Docker DNS.
Why an upstream block?
An upstream named after the container keeps the proxy_pass clean and lets you add more servers later without rewriting the server block.
Does this require a custom network?
Yes - the container and nginx must share a user-defined bridge network so the hostname resolves.
Why HTTP/1.1 and X-Forwarded headers?
They preserve the client IP and protocol for the app and keep keep-alive working through the proxy.
Can I add more backend containers?
Yes - add extra server lines inside the upstream block; the generator emits one by default.
What port should I proxy?
Use the port your app listens on inside the container, not the published host port.
Is the output validated?
Yes - the config is re-parsed by a built-in tokenizer before display.
Is anything uploaded?
No. Everything runs locally in your browser.