All Tools View Categories About Contact Privacy

Nginx Node.js Reverse Proxy Config Generator

Put nginx in front of a Node.js app with correct proxy headers.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your Node.js proxy block will appear here.
-
lines
-
blocks
-
backends

About Nginx Node.js Reverse Proxy Config Generator

Running a Node.js app behind nginx is the standard production topology, but a hand-written proxy block goes wrong in predictable ways: forgetting proxy_http_version 1.1 so keep-alive misbehaves, omitting X-Forwarded-* headers so your app logs every request as coming from localhost, a backend host that is not a valid IP or name, or a timeout so tight that slow endpoints get severed. The Nginx Node.js Reverse Proxy Config Generator builds a correct proxy server block and validates the result before you copy it.

At the heart of the configuration are a handful of directives. proxy_pass forwards matched requests to the Node backend at http://host:port. proxy_http_version sets HTTP/1.1 so connections to Node stay alive and behave correctly. proxy_set_header rewrites request headers such as Host and the X-Forwarded-* chain for the backend. proxy_read_timeout caps how long nginx waits for Node to send response data. proxy_connect_timeout caps how long nginx waits to open the connection to Node. server_name binds the block to the public domain that fronts the app. location selects which URIs are proxied to the backend. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. Using HTTP/1.0 by default breaks keep-alive to Node, so the generator pins proxy_http_version 1.1. Without X-Forwarded-* your app believes every visitor is nginx itself; the tool adds them by default. A backend host that is neither a valid IP nor domain makes nginx fail to start, so input is validated up front. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • proxy_pass - forwards matched requests to the Node backend at http://host:port.
  • proxy_http_version - sets HTTP/1.1 so connections to Node stay alive and behave correctly.
  • proxy_set_header - rewrites request headers such as Host and the X-Forwarded-* chain for the backend.
  • proxy_read_timeout - caps how long nginx waits for Node to send response data.
  • proxy_connect_timeout - caps how long nginx waits to open the connection to Node.
  • server_name - binds the block to the public domain that fronts the app.
  • location - selects which URIs are proxied to the backend.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Enter the public domain nginx serves.
  2. Enter the backend host (IP or domain) and port.
  3. Set the proxy path, usually /.
  4. Choose a proxy timeout in seconds.
  5. Toggle the X-Forwarded-* headers.
  6. Click Generate (or Load sample) and review the block.
  7. Drop it into conf.d, run nginx -t, then reload.

Examples

Example 1 - Local app domain proxied to 127.0.0.1:3000 with forwarded headers on.

Example 2 - Subpath only /app is proxied to a Node service on another port.

Example 3 - No headers X-Forwarded-* off for an internal trusted network.

Example 4 - Bad host rejected a host with a space is reported as invalid.

Example 5 - Bad port rejected a port above 65535 is caught before generation.

Benefits

  • Correct HTTP/1.1 proxy to Node every time.
  • X-Forwarded-* headers added by default.
  • Backend host and port validated up front.
  • Per-request timeout wired in one place.
  • Self-checked output re-parsed before display.
  • Private: everything runs in your browser.

Frequently Asked Questions

Why proxy instead of serving directly?
nginx terminates clients, serves static assets and load-balances, while Node handles dynamic requests - a robust production layout.
What do X-Forwarded headers do?
They tell your Node app the real client IP, original protocol and host, which libraries like express use for secure links and logging.
Why proxy_http_version 1.1?
HTTP/1.1 keeps connections alive to the backend and is required for correct keep-alive behaviour with many Node frameworks.
My app sees localhost as the IP
That is because X-Real-IP / X-Forwarded-For were missing; enable the headers and read them in your app.
How do I handle websockets?
This base block is for HTTP; the WebSocket proxy generator adds the Upgrade headers you need.
What timeout should I use?
Match it to your slowest expected request; too low cuts off long operations, too high ties up worker connections.
Is the output validated?
Yes - the block is re-parsed by a built-in tokenizer before display.
Is anything uploaded?
No. All generation runs locally in your browser.