How to Configure Nginx as a Reverse Proxy and Load Balancer on Ubuntu 24.04

 Setting up a reliable web infrastructure requires both security and high availability. Nginx is one of the most powerful and lightweight web servers used globally to handle heavy HTTP traffic, act as a reverse proxy, and distribute loads effectively across backend servers.


In this guide, we will walk through setting up Nginx as a Reverse Proxy and Load Balancer on Ubuntu 24.04 LTS step by step.


---


## What is a Reverse Proxy and Load Balancer?


- **Reverse Proxy:** Acts as an intermediary between client requests and backend application servers. It masks backend server details, handles SSL termination, and enhances overall security.

- **Load Balancer:** Distributes incoming network traffic across multiple backend servers to prevent any single server from becoming a bottleneck, ensuring high availability and uptime.


---


## Step 1: Updating system packages and Installing Nginx


Before installing Nginx, update your Ubuntu system repositories to ensure you receive the latest updates:


```bash

sudo apt update && sudo apt upgrade -y

sudo apt install nginx -y

Verify that Nginx is active and running:

sudo systemctl status nginx

Step 2: Configuring Nginx as a Reverse Proxy

Suppose you have an application running locally on port 3000 (Node.js, Python Flask, or Docker container), and you want Nginx to route external port 80 traffic to it.

Create a new server block configuration file: sudo nano /etc/nginx/sites-available/myapp.conf

Add the following reverse proxy configuration:server {

    listen 80;

    server_name yourdomain.com [www.yourdomain.com](https://www.yourdomain.com);


    location / {

        proxy_pass [http://127.0.0.1:3000](http://127.0.0.1:3000);

        proxy_http_version 1.1;

        proxy_set_header Upgrade $http_upgrade;

        proxy_set_header Connection 'upgrade';

        proxy_set_header Host $host;

        proxy_cache_bypass $http_upgrade;

        proxy_set_header X-Real-IP $remote_addr;

        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_

for  }

Enable the site and test the configuration:

sudo ln -s /etc/nginx/sites-available/myapp.conf /etc/nginx/sites-enabled/

sudo nginx -t

sudo systemctl reload nginx

Step 3: Configuring Nginx as a Load Balancer

If you have multiple backend application servers running on different IP addresses or ports (e.g., 10.0.0.1:8080 and 10.0.0.2:8080), you can configure Nginx to balance traffic between them using the upstream directive.

Edit your configuration file:sudo nano /etc/nginx/sites-available/myapp.conf

Replace the file contents with the following load-balancing block:upstream backend_servers {

    # Round-Robin load balancing algorithm (default)

    server 10.0.0.1:8080;

    server 10.0.0.2:8080;

    server 10.0.0.3:8080;

}


server {

    listen 80;

    server_name loadbalancer.yourdomain.com;


    location / {

        proxy_pass http://backend_servers;

        proxy_set_header Host $host;

        proxy_set_header X-Real-IP $remote_addr;

        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

    }

}

Test and restart Nginx:sudo nginx -t

sudo systemctl reload nginx

Step 4: Securing Nginx with Free Let's Encrypt SSL

To secure your reverse proxy or load balancer with HTTPS, install Certbot and configure an SSL certificate:sudo apt install certbot python3-certbot-nginx -y

sudo certbot --nginx -d yourdomain.com -d [www.yourdomain.com](https://www.yourdomain.com)

Certbot will automatically update your Nginx configuration and manage automatic SSL renewals.

Conclusion

Configuring Nginx as a reverse proxy and load balancer is an essential skill for system administrators and DevOps engineers. It significantly improves app performance, scalability, and security with minimal overhead. Test your updates using nginx -t after every configuration change to maintain high uptime.



Comments

Popular posts from this blog

Linux Server Hardening Best Practices: Essential Steps to Secure Your Server

Top 10 Essential Linux Commands for DevOps Engineers

Quantum Computing in 2026: Why Traditional Encryption is Facing Its Biggest Threat