Setting up a Reverse Proxy
A reverse proxy is a web server that sits between the internet and the Panel or a Wings node. Visitors talk to the proxy on the standard HTTPS port (443), and the proxy forwards each request to the service behind it, which keeps listening on its own port where nobody else can reach it.
You want one because it:
- Serves the Panel or a node at
https://panel.example.cominstead ofhttp://1.2.3.4:8000. - Terminates TLS in one place, so the Panel or Wings itself never has to handle certificates.
- Lets one machine host the Panel next to other websites on the same ports.
- Enables features that need a secure origin, such as passkeys.
How It Fits Together
Three things happen at the proxy on every request:
- It decrypts the HTTPS connection using your certificate.
- It adds headers that tell the Panel or Wings who the real visitor is (
X-Forwarded-For,X-Real-IP). - It forwards the request over plain HTTP to the service on the loopback address, and streams the response back.
Because every request now arrives from the proxy, the Panel or Wings has to be told which address the proxy uses. Otherwise every visitor looks like they come from the same IP, which breaks per-IP rate limiting and fills the activity log with the proxy's address. Both guides start with that, along with closing off the port the service used to answer on directly.
All-in-One image
On the All-in-One image, the bundled Wings is reached through the Panel, so the Panel guide covers both; see All-in-One and Wings Proxy Mode. Only SFTP (port 2022) stays direct, because it is not HTTP.
Pick a Guide
| Guide | Set up | Covers |
|---|---|---|
| Panel | Once | The login page, dashboard and admin area, and on the All-in-One image the bundled Wings |
| Wings | Per standalone node | The browser's direct connections to the node: console, file manager, uploads and downloads |
Keeping the Configuration Current
The examples are written for the current stable release of each proxy. An older release can lack a directive or behave differently. The guides call out the differences that matter, such as Nginx before 1.25.1 and Apache before 2.4.47.
The Panel and Wings change too. A release can add an endpoint, a WebSocket route or a larger request that the proxy has to let through, so a configuration that worked before an update can stop working after it. Whenever you update the Panel or Wings, come back to its guide and compare your configuration with the current example.