A server in front of servers.
WHAT IT IS
A server accepting requests on behalf of backends, and forwarding them.
WHAT IT PROVIDES
Distribution across several backends Encryption termination Caching Compression Request routing by path or hostname Filtering and rate limiting A single point for logging and metrics
WHY IT MATTERS ARCHITECTURALLY
Backends need not handle encryption, concurrency at the edge, or routing.
WHAT COMMON SOFTWARE IS USED
High-performance event-driven servers Dedicated load balancing software Cloud-managed equivalents
WHAT TO CONFIGURE CAREFULLY
Timeouts at each stage Buffer sizes Which headers are passed, added or stripped Health checking of backends
WHAT HEADERS MATTER
Those conveying the original client address and protocol.
WHY
Without them, backends see the proxy's address and believe every request is unencrypted.
WHAT TO NEVER DO
Trust those headers from arbitrary sources.
WHY
They can be forged, allowing address spoofing in your logs and access rules.
WHAT TO CONFIGURE
Which upstream addresses are trusted to set them.