Nginx Proxy Manager is a web panel that sets up Nginx as a reverse proxy and issues certificates on its own. It is useful when you would rather configure things with a mouse than edit text files by hand.
What a reverse proxy is, briefly
A reverse proxy accepts a request on one domain and port, then forwards it to the right server inside the network, hiding that server's real address. If you need the actual config with directives, the details are in the article on reverse proxy in Nginx.
NPM, hand-written configs, and Traefik
All three approaches solve the same task differently, and the choice depends on how many rules there are and how often they change.
| Criterion | NPM | Hand-written configs | Traefik |
|---|---|---|---|
| What is configured | through a web panel | in text config files | through container labels or files |
| Who gets certificates | the panel itself | a separate client that you set up | Traefik itself, from labels |
| Where state is stored | in the panel's own database | in text config files | in config and container labels |
| Who it suits | those who do not want to edit config by hand | those who need full control | those with many containers and frequent changes |
The separate approach based on container labels is covered in the article on Traefik.
Installing the panel as a container
The panel is set up as a container, with ports for web traffic and a separate port for signing in to the panel itself, plus volumes for data and certificates.
services:
app:
image: jc21/nginx-proxy-manager:latest
restart: unless-stopped
ports:
- '80:80'
- '443:443'
- '81:81'
volumes:
- ./data:/data
- ./letsencrypt:/etc/letsencrypt
First sign-in and changing the admin details
After startup the panel opens on the sign-in port, and the first thing to do is sign in with the default administrator details and immediately change both the email and the password, which is the most common mistake when setting up the panel.
First proxy host, step by step
- Enter the domain the proxy host will serve.
- Enter the address and port of the server the panel should forward requests to.
- Turn on issuing an SSL certificate for that domain.
- Turn on redirecting from plain HTTP to the secure connection.
What breaks most often
| Problem | Likely cause | What to check |
|---|---|---|
| The certificate is not issued | the confirmation port is busy or the domain does not point to the server | whether the port is reachable from outside and the domain record |
| The backend is unreachable | the container address is used instead of the address the panel can see | the backend address and port in the proxy host settings |
| WebSocket does not work | WebSocket support is not turned on for that proxy host | the WebSocket support switch on that proxy host |
| The panel is exposed to the outside | the panel's sign-in port is reachable by anyone, not just the administrator | restricting access to the panel's port |
When NPM does not fit
The panel becomes awkward once there are so many rules that the interface is hard to follow, when you need non-standard directives the panel does not expose, or when the config must live in version control together with the rest of the code.