[{"data":1,"prerenderedAt":193},["ShallowReactive",2],{"seo-verification":3,"blog-nginx-proxy-manager-vps-reverse-proxy-setup-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-nginx-proxy-manager-vps-reverse-proxy-setup-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":27,"featuredImage":29,"bgImage":30,"posterImage":31,"relatedSolution":29,"intro":32,"sections":33,"ctaTitle":134,"ctaBody":135,"ctaButton":136,"ctaUrl":137,"relatedPosts":138},384,"nginx-proxy-manager-vps-reverse-proxy-setup",{"fr":12,"en":10,"ar":13,"es":14},"nginx-proxy-manager-vps-reverse-proxy","nginx-proxy-manager-على-vps-إعداد-reverse-proxy","nginx-proxy-manager-vps-proxy-inverso","Nginx Proxy Manager on VPS: Reverse Proxy with Auto SSL","Set up a visual reverse proxy on your VPS with Nginx Proxy Manager: automatic Let's Encrypt SSL, multi-app Docker routing, no nginx.conf editing required.",9,0,false,"2026-09-26T00:00:00+00:00","2026-09-29T14:40:42+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},3,"Deployment","deploiement","bg-success\u002F10 text-success",[28],{"id":23,"name":24,"slug":25,"color":26,"icon":25},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fnginx-proxy-manager-vps-reverse-proxy-poster.svg","When several applications run on the same VPS, each one listens on a different port and SSL becomes a headache to manage manually. Nginx Proxy Manager (NPM) solves this problem with a web interface that automates Let's Encrypt certificates, routes domains to the right containers, and requires no nginx configuration file editing. This guide covers installation, proxy host configuration, and a comparison with Caddy and Traefik to help you choose the right tool for your situation.",[34,38,48,51,67,82,85,88,92,131],{"type":35,"title":36,"body":37},"h2","Why a reverse proxy on a VPS","A VPS exposes a single public IP address. If you run three Docker applications — an API, a front-end and an admin tool — each occupies a different port: `3000`, `8080`, `9000`. Without a reverse proxy, your visitors must type the port in the URL, SSL certificates must be managed application by application, and exposing all those ports publicly increases the attack surface.\n\nA **reverse proxy** centralizes traffic entry: it receives all requests on ports 80 and 443, inspects the domain name or path, then forwards the request to the right container on the internal network. Applications no longer expose public ports. SSL terminates at the proxy level, which redistributes plain HTTP over the private Docker network.\n\nThis architecture offers three concrete benefits: a single certificate management point, network isolation of applications, and the ability to add or remove an app without touching the others.",{"type":39,"title":40,"items":41},"ul","What Nginx Proxy Manager simplifies",[42,43,44,45,46,47],"**Web interface**: add, modify and delete proxy hosts without command line or manual reload","**One-click Let's Encrypt SSL**: NPM requests, renews and deploys certificates automatically via HTTP-01 or DNS-01","**Wildcard DNS**: a single certificate for `*.mydomain.com` if your DNS provider supports the Certbot API","**Access lists**: HTTP basic authentication or IP whitelisting directly from the interface","**Redirects and custom URLs**: HTTP to HTTPS, 301\u002F302 redirects, without modifying nginx.conf","**Reload without interruption**: NPM reloads the nginx configuration in the background, without downtime",{"type":35,"title":49,"body":50},"Prerequisites","To follow this guide, you need a VPS running **Ubuntu 22.04** or **Debian 12** with at least 1 GB of RAM (2 GB recommended if multiple apps run simultaneously). Docker Engine and Docker Compose v2 must be installed.\n\n**Ports 80 and 443** must be accessible from outside. Check that your firewall (`ufw` or control panel rules) allows them. If you use a cloud firewall (security group, VPS firewall), open these two ports for inbound traffic.\n\nFinally, you must own at least one **domain name or subdomain** pointing to your VPS IP. NPM can manage multiple domains simultaneously — the minimum requirement is that a DNS A record exists for each domain you want to proxy.",{"type":52,"title":53,"steps":54},"steps","Installing NPM with Docker Compose",[55,58,61,64],{"title":56,"body":57},"Create the directory structure","Create a dedicated folder and navigate into it:\n\n```bash\nmkdir -p \u002Fopt\u002Fnpm && cd \u002Fopt\u002Fnpm\n```\n\nThis folder will contain the Compose file and NPM's persistent volumes (SQLite database, certificates, logs).",{"title":59,"body":60},"Write docker-compose.yml","Create the file `\u002Fopt\u002Fnpm\u002Fdocker-compose.yml` with the following content:\n\n```yaml\nservices:\n  app:\n    image: jc21\u002Fnginx-proxy-manager:latest\n    restart: unless-stopped\n    ports:\n      - \"80:80\"\n      - \"443:443\"\n      - \"81:81\"\n    volumes:\n      - .\u002Fdata:\u002Fdata\n      - .\u002Fletsencrypt:\u002Fetc\u002Fletsencrypt\n\nnetworks:\n  default:\n    name: proxy-net\n    external: false\n```\n\nPort `81` is the administration interface. The `proxy-net` network will be shared with your other containers so they can be reached without exposing public ports.",{"title":62,"body":63},"Start NPM","Launch the container in the background:\n\n```bash\ndocker compose up -d\n```\n\nWait 30 to 60 seconds for NPM to initialize its database. Verify that the three ports are listening:\n\n```bash\nss -tlnp | grep -E ':(80|81|443)'\n```",{"title":65,"body":66},"First login and password change","Open `http:\u002F\u002FYOUR_VPS_IP:81` in your browser. Default credentials are `admin@example.com` \u002F `changeme`.\n\nNPM forces you to change the email address and password on first login. Use a valid address: it will be used for Let's Encrypt certificate expiry notifications.\n\n**Note**: port 81 is publicly exposed. Immediately configure an access list (see \"Access Lists\" section) or filter this port at the firewall level to restrict it to your IP.",{"type":52,"title":68,"steps":69},"Adding a first proxy host",[70,73,76,79],{"title":71,"body":72},"Create a new proxy host","In the NPM interface, click **Proxy Hosts** then **Add Proxy Host**. Fill in the **Domain Names** field with your domain, for example `app.mydomain.com`. Make sure the DNS A record for this subdomain already points to your VPS IP — Let's Encrypt will verify this resolution.",{"title":74,"body":75},"Configure the destination","In the **Forward Hostname \u002F IP** and **Forward Port** fields, enter the host and port of your application. If the application runs in a Docker container on the same `proxy-net` network, use the Docker **service name** as the hostname (example: `myapp` and port `3000`). Check **Block Common Exploits** to enable basic filtering rules.",{"title":77,"body":78},"Enable Let's Encrypt","Switch to the **SSL** tab in the same window. From the dropdown, select **Request a new SSL Certificate**. Check **Force SSL** to automatically redirect HTTP to HTTPS, and **HTTP\u002F2 Support** to enable HTTP\u002F2. Enter your email address, accept the Let's Encrypt terms, then click **Save**.\n\nNPM immediately launches the certificate request via the HTTP-01 challenge. In less than a minute, your domain is accessible via HTTPS with a valid certificate.",{"title":80,"body":81},"Verify the result","The proxy host list now shows your entry with a green **SSL** badge. Test from your browser or with curl:\n\n```bash\ncurl -I https:\u002F\u002Fapp.mydomain.com\n```\n\nThe response should contain `HTTP\u002F2 200` and a `server: nginx` header. Certificate renewal is automatic — NPM relaunches the request 30 days before expiry.",{"type":35,"title":83,"body":84},"Configure a subdomain with forced HTTPS redirect","Forcing HTTPS is not just a best practice: it is the foundation of transport security. When creating or editing a proxy host, the **SSL** tab exposes three complementary options.\n\n**Force SSL**: NPM automatically generates a `return 301 https:\u002F\u002F$host$request_uri;` block in the nginx vhost configuration. Any HTTP request is redirected server-side before even reaching your application.\n\n**HSTS** (HTTP Strict Transport Security): by checking this option, NPM adds the `Strict-Transport-Security: max-age=63072000; includeSubDomains; preload` header to HTTPS responses. The browser remembers that this domain must always be contacted via HTTPS, even if the user types `http:\u002F\u002F`. Only enable HSTS if you are certain of maintaining SSL — disabling HSTS afterwards has no immediate effect on browsers that have already cached it.\n\n**HTTP\u002F2 Support**: enables the HTTP\u002F2 protocol on the client side, without any modification on the application side. Multiplexing reduces perceived latency, especially on pages with many resources.",{"type":35,"title":86,"body":87},"Advanced case: proxy for a Docker app without exposed port","One of the most underrated advantages of NPM is the ability to proxy containers that expose no public port. Communication takes place solely on the internal Docker network.\n\nFor a container to be reachable by NPM without public exposure, both services must share the same Docker network. Example with a Node.js app in `\u002Fopt\u002Fmyapp\u002Fdocker-compose.yml`:\n\n```yaml\nservices:\n  web:\n    image: my-image:latest\n    restart: unless-stopped\n    # No 'ports' section — the container is not accessible from the host\n    networks:\n      - proxy-net\n\nnetworks:\n  proxy-net:\n    external: true\n```\n\nBy declaring `proxy-net` as an external network and attaching the service to this network, the `web` container becomes reachable from NPM by its service name. In the NPM interface, **Forward Hostname** will simply be `web` and **Forward Port** the app's internal port (for example `3000`).\n\nThis architecture means that even if an attacker compromises a container, they cannot reach other services directly from outside — everything goes through the proxy.",{"type":89,"title":90,"body":91},"tip","Access Lists: protecting the backoffice with authentication","NPM allows restricting access to certain proxy hosts via **access lists**. Go to **Access Lists** then **Add Access List**. Give the list a name, add entries under the **Authorization** tab (username + hashed password), and\u002For restrict by IP under **Access**.\n\nThen edit the proxy host you want to protect and select this list in the **Access List** field. NPM automatically injects an `auth_basic` block into the nginx vhost configuration. This is particularly useful for exposing admin tools (Portainer, Grafana, internal API interfaces) without deploying a full authentication server.\n\nFor port 81 itself (the NPM interface), protection goes through the firewall — restrict access to this port to your fixed IP or a VPN.",{"type":93,"title":94,"headers":95,"rows":100},"comparison","Comparison: Nginx Proxy Manager vs Caddy vs Traefik",[96,97,98,99],"Criterion","Nginx Proxy Manager","Caddy","Traefik",[101,106,111,116,121,126],[102,103,104,105],"Configuration","Graphical web interface, no files to edit","Declarative Caddyfile, concise syntax","YAML\u002FTOML or Docker labels, steeper learning curve",[107,108,109,110],"Automatic SSL","Let's Encrypt HTTP-01 and DNS-01, graphical interface","Built-in natively, HTTP-01 and DNS-01 without plugin","Built-in ACME, requires YAML configuration",[112,113,114,115],"Docker auto-discovery","No, manual configuration per host","Not native, possible via labels with caddy-docker-proxy","Native via Docker labels, detects services at startup",[117,118,119,120],"Ideal use case","Developer managing fewer than 20 apps, prefers UI over config","Simple to medium stack, readable file-based config","Microservices, Kubernetes, dynamic environments",[122,123,124,125],"Advanced customization","Limited — custom nginx snippets possible but not recommended","High via modules and Caddyfile directives","Very high, chainable middlewares, rich plugins",[127,128,129,130],"Resources","~50 MB RAM at rest","~30 MB RAM at rest","~40 MB RAM at rest, more depending on plugins",{"type":35,"title":132,"body":133},"NPM's limits and when to migrate to Traefik","NPM covers the vast majority of use cases for developers managing a dozen applications on one or two VPS. It starts to show its limits in several scenarios.\n\n**Advanced nginx configuration**: NPM generates its configuration files and regenerates them with each change from the interface. It is technically possible to add custom snippets, but they can be overwritten during an update. If you need fine-grained nginx configurations — per-route rate limiting, complex proxy cache, advanced rewrite logic — NPM becomes a friction layer rather than a help.\n\n**Dynamic environments**: in a microservices architecture where containers appear and disappear frequently, manually configuring each host in NPM becomes a bottleneck. \u003Ca href=\"\u002Fblog\u002Fdeployer-avec-haproxy-vps\">HAProxy\u003C\u002Fa> or Traefik, which automatically detect services via Docker labels, are better suited to this context.\n\n**Kubernetes**: NPM has no place in a Kubernetes cluster. Traefik has a native Ingress Controller; `ingress-nginx` is the other common option.\n\n**Practical rule**: if your configuration fits in the NPM interface and does not require automation scripts to stay current, NPM is the right choice. As soon as you find yourself writing scripts to interact with the NPM API or managing configuration files outside the interface, that is the signal to evaluate \u003Ca href=\"\u002Fblog\u002Fdeployer-avec-caddy\">Caddy\u003C\u002Fa> or Traefik depending on your context.","A VPS ready for your Docker containers","ServOrbit.com offers cloud VPS starting at 99 DH\u002Fmonth, with high-availability networking, snapshots and technical support included. Deploy Nginx Proxy Manager in minutes.","Deploy on VPS","\u002Fvps-cloud",[139,159,177],{"id":140,"slug":141,"slugs":142,"title":146,"excerpt":147,"readTime":148,"views":149,"isPinned":19,"publishedAt":150,"updatedAt":151,"category":152,"categories":153,"featuredImage":29,"bgImage":30,"posterImage":155,"relatedSolution":156},39,"deploy-your-applications-with-caddy-on-a-vps",{"fr":143,"en":141,"ar":144,"es":145},"deployer-avec-caddy","انشر-تطبيقاتك-باستخدام-caddy-على-خادم-vps","desplegar-con-caddy","Caddy as a reverse proxy on VPS: complete guide","Install and configure Caddy as a reverse proxy on your VPS: automatic Let's Encrypt HTTPS, multi-app setup, security hardening and common error troubleshooting.",8,1,"2026-05-12T00:00:00+00:00","2026-09-25T23:43:04+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},[154],{"id":23,"name":24,"slug":25,"color":26,"icon":25},"\u002Fblog\u002Fcovers\u002Fdeployer-avec-caddy-poster.svg",{"categorySlug":157,"appSlug":158},"application-deployment-devops","caddy",{"id":160,"slug":161,"slugs":162,"title":166,"excerpt":167,"readTime":23,"views":18,"isPinned":19,"publishedAt":168,"updatedAt":169,"category":170,"categories":171,"featuredImage":29,"bgImage":30,"posterImage":173,"relatedSolution":174},142,"haproxy-on-a-vps-load-balancing-and-high-availability",{"fr":163,"en":161,"ar":164,"es":165},"deployer-avec-haproxy-vps","haproxy-على-خادم-vps-موازنة-الأحمال-والتوافر-العالي","haproxy-en-un-vps-balanceo-de-carga","HAProxy on a VPS: load balancing and high availability","Install HAProxy on a VPS to distribute traffic, monitor backends and prepare a more resilient web architecture.","2026-02-03T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},[172],{"id":23,"name":24,"slug":25,"color":26,"icon":25},"\u002Fblog\u002Fcovers\u002Fdeployer-avec-haproxy-vps-poster.svg",{"categorySlug":175,"appSlug":176},"infra","haproxy",{"id":178,"slug":179,"slugs":180,"title":184,"excerpt":185,"readTime":186,"views":18,"isPinned":19,"publishedAt":187,"updatedAt":188,"category":189,"categories":190,"featuredImage":29,"bgImage":30,"posterImage":192,"relatedSolution":29},229,"docker-compose-in-production-10-point-checklist",{"fr":181,"en":179,"ar":182,"es":183},"docker-compose-production-checklist","docker-compose-في-الإنتاج-قائمة-التحقق-من-10-نقاط","checklist-docker-compose-en-produccion","Docker Compose in Production: 10-Point Checklist","Docker Compose production checklist: 10 essential settings, health checks, secrets without downtime, rollback strategy, common error troubleshooting, CVE-2026-17106.",12,"2026-08-06T00:00:00+00:00","2026-09-29T14:40:45+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},[191],{"id":23,"name":24,"slug":25,"color":26,"icon":25},"\u002Fblog\u002Fcovers\u002Fdocker-compose-production-checklist-poster.svg",1790693270293]