[HN Gopher] Reverse proxy deep dive
       ___________________________________________________________________
        
       Reverse proxy deep dive
        
       Author : miggy
       Score  : 82 points
       Date   : 2025-07-08 07:49 UTC (4 days ago)
        
 (HTM) web link (medium.com)
 (TXT) w3m dump (medium.com)
        
       | shelajev wrote:
       | It took me an embarrassingly long time to internalize what the
       | reverse proxy is. My brain got stuck on the fact that it is just
       | proxying requests. What's so reverse about this? Silly.
        
         | rini17 wrote:
         | Since web proxy was originally used near clients, caching stuff
         | to save precious bandwidth of their kbps-tier connection.
        
         | happytoexplain wrote:
         | It's one of the classic cases of a thing being named relative
         | to what came before it, rather than being named on its own
         | merit. This makes sense to people working at the time the new
         | thing is introduced, but is confusing to every other learner in
         | the future.
        
           | nosianu wrote:
           | Could be worse. All the many things named after _people_
           | prevalent in some fields more than in others, biology
           | /medicine for example. When you read, for example, "loop of
           | Henle" or "circle of Willis" you don't even know where to
           | begin. You either know the term or not.
        
             | happytoexplain wrote:
             | True, though I think it's often a larger challenge to
             | capture the intrinsic quality of a medicinal compound or
             | physiological feature than a man-made tool.
        
           | raincom wrote:
           | What came before "reverse proxies"? Just curious to
           | understand the history.
        
             | p_ing wrote:
             | Forward proxies, proxies where client machines were
             | configured to route all their outbound traffic through
             | (similar to a router). Usually performed caching back in
             | the day when the Internet tube was slow, later on got SSL
             | decryption capabilities and filtering lists to make sure
             | you stay off of your naughty sites and so the proxy admin
             | could decrypt your banking credentials.
        
         | azaras wrote:
         | Nowadays, "reverse" is suppressed in most ways. I have heard
         | that Nginx is a proxy more often than a reverse proxy.
        
           | Valodim wrote:
           | Except in the configuration where you use the reversep_proxy
           | directive, of course
        
           | daveguy wrote:
           | How about service proxy vs web proxy rather than reverse
           | proxy and proxy? Makes more clear that one is a proxy on the
           | service side and the other is a proxy on the client side.
           | Service proxy and Client proxy might be even better.
        
       | MortyWaves wrote:
       | Caddy, Nginx, Traefik seem to be the most popular reverse proxies
       | in the self hosting/homelab communities.
       | 
       | I definitely prefer Caddy in my experience, so far.
        
         | lowwave wrote:
         | Is there a reverse proxies that can support DTLS support out of
         | box without some kind experimental patch[1]?
         | 
         | 1: https://nginx.org/patches/dtls/
        
         | joshbaptiste wrote:
         | Trying out ferron recently as a reverse proxy
         | https://www.ferronweb.org/.. config is super simple
        
         | ethan_smith wrote:
         | HAProxy deserves a mention alongside those - it's particularly
         | strong for high-traffic production environments where its
         | advanced load balancing algorithms and detailed metrics shine.
        
           | p_ing wrote:
           | I would argue this is the best mainstream proxy. Even better
           | when paired with OpenBSD and CARP.
        
         | somehnguy wrote:
         | Caddy has been excellent for me thus far as well. I'm using it
         | on a VPS to reverse proxy to the services I run at home via a
         | Tailscale tunnel. Coming from Nginx in the past Caddy was drop-
         | dead simple to configure.
         | 
         | The entire config for each vhost is 3 lines, including the
         | domain definition and closing brace - and that includes TLS!
        
           | MortyWaves wrote:
           | Just curious if you have Caddy running in Docker or normal?
        
       | leptons wrote:
       | How does this relate to "AI"? /s
        
       | vojtechrichter wrote:
       | Amazing read, I personally find it fascinating to make my own
       | load balancer.
        
       | jeffbee wrote:
       | I would say the bullet points at the top are not strictly
       | correct. The response does not necessarily transit the proxy.
       | Responses can be returned directly to the client (DSR).
        
         | nyrikki wrote:
         | > Note: For simplicity, we'll focus on Layer 7 (HTTP) reverse
         | proxy.
         | 
         | Layer 4 proxies are a very specific _sometimes_ food that most
         | people should actively avoid until they need it because of the
         | tradeoffs.
         | 
         | DSR is layer 4, and not in scope of this post.
        
           | jeffbee wrote:
           | Your comment, to me, only points out that the OSI layer model
           | is nonsense. Envoy in DSR mode routes traffic based on
           | application features, at "layer 7".
        
             | nyrikki wrote:
             | Envoy calls it Layer 4
             | 
             | https://blog.envoyproxy.io/introduction-to-modern-network-
             | lo...
        
               | jeffbee wrote:
               | That's fair. Of course that post also calls the OSI model
               | "unfortunate" and "a poor approximation".
        
             | philwelch wrote:
             | The model itself isn't nonsense because it's not a model of
             | load balancers; it's a model of network protocols. Load
             | balancers might handle multiple levels of the stack for the
             | same traffic, but so does any other networked program, eg
             | handling cross-domain redirects.
        
       | tdiff wrote:
       | Really looks like an ai-generated overview.
        
       | philwelch wrote:
       | Original, Medium-free URL is
       | https://startwithawhy.com/reverseproxy/2024/01/15/ReversePro...
       | 
       | Meta request: can we change the URL to the original source? This
       | isn't quite blogspam (since it's the same author reposting the
       | same piece onto Medium) but Medium is annoying enough that I'd
       | still rather resolve to the original source
        
         | imcotton wrote:
         | Thanks, I have being putting medium domain into dns blocklist
         | for years.
        
           | mdaniel wrote:
           | The alternative is the amazing scribe.rip ->
           | https://scribe.rip/@mitendra_mahto/cross-posted-from-
           | https-s...
        
       | raincom wrote:
       | What's the difference between Reverse proxy and forward proxy? Is
       | there something like "intermediate proxy"? Is this concept of L7
       | proxy, similar to DNAT/SNAT or Port forwarding in L3/L4?
        
         | p_ing wrote:
         | TL;DR: Forward Proxy == protects clients; Reverse Proxy ==
         | protects server
         | 
         | https://en.wikipedia.org/wiki/Proxy_server#Forward_proxy_vs....
        
       ___________________________________________________________________
       (page generated 2025-07-12 23:01 UTC)