[HN Gopher] Reverse proxy deep dive
___________________________________________________________________
Reverse proxy deep dive
Author : miggy
Score : 82 points
Date : 2025-07-08 07:49 UTC (4 days ago)
(HTM) web link (medium.com)
(TXT) w3m dump (medium.com)
| shelajev wrote:
| It took me an embarrassingly long time to internalize what the
| reverse proxy is. My brain got stuck on the fact that it is just
| proxying requests. What's so reverse about this? Silly.
| rini17 wrote:
| Since web proxy was originally used near clients, caching stuff
| to save precious bandwidth of their kbps-tier connection.
| happytoexplain wrote:
| It's one of the classic cases of a thing being named relative
| to what came before it, rather than being named on its own
| merit. This makes sense to people working at the time the new
| thing is introduced, but is confusing to every other learner in
| the future.
| nosianu wrote:
| Could be worse. All the many things named after _people_
| prevalent in some fields more than in others, biology
| /medicine for example. When you read, for example, "loop of
| Henle" or "circle of Willis" you don't even know where to
| begin. You either know the term or not.
| happytoexplain wrote:
| True, though I think it's often a larger challenge to
| capture the intrinsic quality of a medicinal compound or
| physiological feature than a man-made tool.
| raincom wrote:
| What came before "reverse proxies"? Just curious to
| understand the history.
| p_ing wrote:
| Forward proxies, proxies where client machines were
| configured to route all their outbound traffic through
| (similar to a router). Usually performed caching back in
| the day when the Internet tube was slow, later on got SSL
| decryption capabilities and filtering lists to make sure
| you stay off of your naughty sites and so the proxy admin
| could decrypt your banking credentials.
| azaras wrote:
| Nowadays, "reverse" is suppressed in most ways. I have heard
| that Nginx is a proxy more often than a reverse proxy.
| Valodim wrote:
| Except in the configuration where you use the reversep_proxy
| directive, of course
| daveguy wrote:
| How about service proxy vs web proxy rather than reverse
| proxy and proxy? Makes more clear that one is a proxy on the
| service side and the other is a proxy on the client side.
| Service proxy and Client proxy might be even better.
| MortyWaves wrote:
| Caddy, Nginx, Traefik seem to be the most popular reverse proxies
| in the self hosting/homelab communities.
|
| I definitely prefer Caddy in my experience, so far.
| lowwave wrote:
| Is there a reverse proxies that can support DTLS support out of
| box without some kind experimental patch[1]?
|
| 1: https://nginx.org/patches/dtls/
| joshbaptiste wrote:
| Trying out ferron recently as a reverse proxy
| https://www.ferronweb.org/.. config is super simple
| ethan_smith wrote:
| HAProxy deserves a mention alongside those - it's particularly
| strong for high-traffic production environments where its
| advanced load balancing algorithms and detailed metrics shine.
| p_ing wrote:
| I would argue this is the best mainstream proxy. Even better
| when paired with OpenBSD and CARP.
| somehnguy wrote:
| Caddy has been excellent for me thus far as well. I'm using it
| on a VPS to reverse proxy to the services I run at home via a
| Tailscale tunnel. Coming from Nginx in the past Caddy was drop-
| dead simple to configure.
|
| The entire config for each vhost is 3 lines, including the
| domain definition and closing brace - and that includes TLS!
| MortyWaves wrote:
| Just curious if you have Caddy running in Docker or normal?
| leptons wrote:
| How does this relate to "AI"? /s
| vojtechrichter wrote:
| Amazing read, I personally find it fascinating to make my own
| load balancer.
| jeffbee wrote:
| I would say the bullet points at the top are not strictly
| correct. The response does not necessarily transit the proxy.
| Responses can be returned directly to the client (DSR).
| nyrikki wrote:
| > Note: For simplicity, we'll focus on Layer 7 (HTTP) reverse
| proxy.
|
| Layer 4 proxies are a very specific _sometimes_ food that most
| people should actively avoid until they need it because of the
| tradeoffs.
|
| DSR is layer 4, and not in scope of this post.
| jeffbee wrote:
| Your comment, to me, only points out that the OSI layer model
| is nonsense. Envoy in DSR mode routes traffic based on
| application features, at "layer 7".
| nyrikki wrote:
| Envoy calls it Layer 4
|
| https://blog.envoyproxy.io/introduction-to-modern-network-
| lo...
| jeffbee wrote:
| That's fair. Of course that post also calls the OSI model
| "unfortunate" and "a poor approximation".
| philwelch wrote:
| The model itself isn't nonsense because it's not a model of
| load balancers; it's a model of network protocols. Load
| balancers might handle multiple levels of the stack for the
| same traffic, but so does any other networked program, eg
| handling cross-domain redirects.
| tdiff wrote:
| Really looks like an ai-generated overview.
| philwelch wrote:
| Original, Medium-free URL is
| https://startwithawhy.com/reverseproxy/2024/01/15/ReversePro...
|
| Meta request: can we change the URL to the original source? This
| isn't quite blogspam (since it's the same author reposting the
| same piece onto Medium) but Medium is annoying enough that I'd
| still rather resolve to the original source
| imcotton wrote:
| Thanks, I have being putting medium domain into dns blocklist
| for years.
| mdaniel wrote:
| The alternative is the amazing scribe.rip ->
| https://scribe.rip/@mitendra_mahto/cross-posted-from-
| https-s...
| raincom wrote:
| What's the difference between Reverse proxy and forward proxy? Is
| there something like "intermediate proxy"? Is this concept of L7
| proxy, similar to DNAT/SNAT or Port forwarding in L3/L4?
| p_ing wrote:
| TL;DR: Forward Proxy == protects clients; Reverse Proxy ==
| protects server
|
| https://en.wikipedia.org/wiki/Proxy_server#Forward_proxy_vs....
___________________________________________________________________
(page generated 2025-07-12 23:01 UTC)