Skip to content
Learn/

Reverse Proxies

1 / 3

One server pretending to be all of them

A reverse proxy sits in front of your backends and answers on their behalf. Clients only ever talk to it; they never learn that there are four application servers, or where they are, or that one was replaced this morning.

That indirection is worth more than it first appears. It gives you one place to terminate TLS, one place to compress responses, one place to serve static files without waking your application, one place to enforce request limits, and one certificate to renew instead of forty.

The security benefit is real too: your application servers can live on a private network with no direct route from the internet. The proxy remains a critical, internet-facing parser and policy point, so it needs hardening, patching, least privilege, and redundancy of its own.

                 ┌──────────────┐
  internet  ───► │ reverse      │ ──► app 1   (private network)
                 │ proxy        │ ──► app 2
   TLS ends here │              │ ──► app 3
                 └──────────────┘

One public address. One certificate.
Backends have no route from the internet.

3 components2 connections0:00

Traffic
4Kreq/s
p50
45ms
p99
101ms
Errors
0.06%
Dropped
2.4req/s
Cost
$534/mo