Skip to content
BotServBotServ
NginxReverse ProxyWeb UILet's EncryptDockerSelf-Hosting

Nginx Proxy Manager: Reverse Proxy Made Simple

Nginx Proxy Manager web UI for reverse proxy, Let's Encrypt SSL, and access control. Easy setup.

S

schutzgeist

8 min read
Nginx Proxy Manager: Reverse Proxy Made Simple

Nginx Proxy Manager: Reverse Proxy Made Simple

What This Article Covers

  • What Nginx Proxy Manager is and why it helps beginners
  • How to set up a reverse proxy in Docker with just a few clicks
  • How automatic Let’s Encrypt certificates work
  • Which security options are available for your AI services
  • Where the biggest beginner pitfalls are and how to avoid them

Introduction

If you want to run local AI tools like Ollama, websites, or other services on your home network, you’ll eventually encounter the term “reverse proxy.” A reverse proxy accepts requests from the internet and forwards them to the appropriate internal service. It sounds technical, but it’s the foundation for clean domains, HTTPS, and better security.

Nginx Proxy Manager, or NPM, is a graphical web interface for exactly this task. Behind it sits the well-known Nginx web server, but you don’t need to write configuration files by hand. Instead, you click through input forms, get free TLS certificates issued via Let’s Encrypt, and manage access lists. For self-hosting, that’s a real advantage because it saves a lot of time.

In this article, you’ll learn how to install Nginx Proxy Manager with Docker, set up your first domain, and make your Ollama or other AI service securely accessible from the outside. Topics like TLS certificates and networking can be found in the relevant sections on our site. An alternative that works without port forwarding is Tailscale.

Why Nginx Proxy Manager?

Nginx Proxy Manager significantly simplifies working with a reverse proxy. In traditional setups, you edit text files, test the syntax, and restart the service. With NPM, you do all of that in a browser window. You create a proxy host, choose the domain, enter the internal address and port, and decide whether SSL should be active.

The best part: you can request and renew Let’s Encrypt certificates directly from the web interface. You get valid HTTPS connections for your subdomains without buying certificates or managing them manually. For AI services like Ollama, this means your browser connection stays encrypted while you can use nice domains like ollama.example.de.

Nginx Proxy Manager Explained

Nginx is a very popular web server and reverse proxy. Nginx Proxy Manager is a Docker container that bundles Nginx, a graphical backend, and a database. After starting it, you access the web interface through your browser. From there, you manage hosts, certificates, redirects, and access lists.

Each proxy host consists of a domain, a forwarding destination address, and optional settings like SSL, HSTS, or advanced locations. Once you save an entry, NPM generates the appropriate Nginx configuration in the background and reloads it. You won’t notice anything except that your service is accessible.

Who Is This Article For?

This article is for beginners in self-hosting who already know Docker or want to learn it quickly. You should have your own server, a NAS, or a Raspberry Pi with Linux and Docker. Basic knowledge of Linux and Docker helps but isn’t strictly necessary. If you haven’t set up Docker yet, take a look at our Docker Basics.

If you prefer to use Cloudflare’s infrastructure, we also have an article on Cloudflare Tunnel. NPM is the right choice if you want to use your own domain with your own TLS certificates.

Key Terms

TermDefinition
Reverse ProxyA service that forwards external requests to internal services.
NginxA versatile web server and reverse proxy that also serves as a load balancer.
Let’s EncryptA free certificate authority that issues TLS certificates.
SSL/TLSEncryption for HTTPS connections.
Proxy HostAn entry in NPM that connects a domain and internal destination.
Access ListA rule that determines who can access a proxy host.
DockerA platform for isolating applications in containers.
ComposeA way to start multiple Docker containers via a YAML file.

Prerequisites for Installation

You need a Linux system with Docker and Docker Compose installed. Many beginners use Ubuntu, Debian, or a NAS with container support. Make sure your user belongs to the Docker group or you run commands with sudo. Your server should be reachable from the internet, meaning it needs public ports 80 and 443 open. You’ll need port forwarding configured in your router for this.

You also need your own domain with DNS pointing to your public IP address. This can be with Cloudflare, Hetzner, INWX, or any other registrar. You should set up at least one subdomain like ollama.example.de that points to your public IP address. If you have a dynamic IP, use a DynDNS service.

If you’re still uncertain about networking, you’ll find the basics in the Network article. For security topics, we recommend Network Security.

Installation via Docker Compose

The cleanest way to install Nginx Proxy Manager is through Docker. Create a folder on your server and inside it a file named docker-compose.yml with the following content:

version: "3.8"
services:
  npm:
    image: jc21/nginx-proxy-manager:latest
    container_name: npm
    restart: unless-stopped
    ports:
      - "80:80"
      - "81:81"
      - "443:443"
    volumes:
      - ./data:/data
      - ./letsencrypt:/etc/letsencrypt
    environment:
      - DB_SQLITE_FILE=/data/database.sqlite

Save the file and start the container:

cd /opt/npm
docker compose up -d

The first startup may take a few seconds. After that, the web interface is accessible at http://YOUR_SERVER_IP:81. The default credentials are admin@example.com and changeme. You’ll be prompted to set a new password on your first login.

Creating Your First Proxy Host

Log in to Nginx Proxy Manager. Click on Hosts and then Proxy Hosts. Select Add Proxy Host. In the form, enter the following values:

  • Domain Names: ollama.example.de
  • Forward Hostname / IP: The IP or name of your Ollama container, for example ollama or localhost
  • Forward Port: 11434
  • Block Common Exploits: turn on
  • Websockets Support: turn on if needed

Save the entry. Your internal service is now accessible under your domain, but without HTTPS yet.

Enabling HTTPS with Let’s Encrypt

Edit the proxy host you just created and go to the SSL tab. Select Request a new SSL Certificate. Make sure your domain actually points to your public IP, because Let’s Encrypt needs to verify ownership. Accept the terms of service and save.

After a few seconds, you should receive a valid certificate. Additionally, enable Force SSL so all unencrypted requests are automatically redirected to HTTPS. Optionally, you can enable HTTP/2 Support and HSTS.

From now on, Ollama is accessible at https://ollama.example.de. Your data is transmitted encrypted and your browser shows the lock icon.

Setting Up Access Control

Not every service should be exposed publicly. NPM lets you create access lists to restrict who can reach your services. You can control access by IP address, username and password, or a combination of both. HTTP Basic Auth is particularly recommended, since it prompts users in the browser for credentials.

For every public AI service that isn’t meant for the whole world, set up at least a password. Keep in mind that IP whitelisting alone becomes awkward with mobile or dynamic IPs. Username and password offer much more flexibility.

Common Pitfalls

  1. Default credentials unchanged: Nginx Proxy Manager ships with admin@example.com and changeme. Change these immediately, or you’ve essentially opened your system to anyone.

  2. Port 81 not open: The web dashboard requires port 81. If you’ve only exposed 80 and 443, you won’t reach the dashboard.

  3. Domain not pointing to your IP yet: Let’s Encrypt only works once DNS is correctly configured and propagated. Verify your DNS and be patient.

  4. Internal service unreachable: If localhost:11434 doesn’t work, Ollama might be on a different Docker network. Use the container name with the correct bridge instead.

  5. Let’s Encrypt rate limits: If certificate requests fail repeatedly, Let’s Encrypt temporarily blocks your domain. Test DNS and connectivity before retrying.

  6. Cloudflare proxy interferes with Let’s Encrypt: If your domain runs through Cloudflare with proxying enabled, Let’s Encrypt can’t validate the IP. Temporarily switch to DNS only mode.

  7. Firewall blocks ports: Make sure your server firewall allows inbound traffic on 80, 443, and 81. Otherwise HTTPS and the web UI will fail.

  8. Docker volume permissions: NPM stores certificates and data in volumes. Wrong permissions can prevent certificates from being written.

  9. HTTPS shows red in browser: A red warning usually means the certificate has expired, HSTS is misconfigured, or the domain doesn’t match.

  10. Cache prevents changes: After configuration updates, restarting the container or clearing your browser cache often helps.

Hardware, Cost, and Security

Nginx Proxy Manager is extremely lightweight. It runs smoothly on a Raspberry Pi 4, a small VPS, or a NAS. You only need significantly more power if you’re handling many concurrent requests or running numerous additional containers. For a typical home network, a Pi or budget server is plenty.

Costs come from your domain, possibly DynDNS, and electricity. Let’s Encrypt certificates are free. If you host with Cloudflare or another provider, you may have domain costs to factor in. Security-wise, NPM is solid once you enable HTTPS, access lists, and block common exploits.

Don’t forget to configure your local firewall and only open ports you actually need. Regularly updating the container is just as important as using strong passwords.

Further Reading

FAQ

  1. Does Nginx Proxy Manager cost anything?
    No, it’s an open-source project and free to use. Costs are limited to your domain or hosting provider.

  2. Do I need port forwarding?
    Yes, if you want to use external domains directly. Alternatively, Cloudflare Tunnel is a good option.

  3. Does NPM work with Ollama?
    Yes. Just forward port 11434 to a nice domain.

  4. How often does Let’s Encrypt renew certificates?
    NPM checks automatically at regular intervals and renews certificates before they expire.

  5. Is NPM suitable for beginners?
    Yes, the web interface makes getting started much easier.

  6. Can I use multiple domains?
    Yes, you can create as many proxy hosts as you need, each with different domains and targets.

  7. What if my IP is dynamic?
    Use DynDNS. NPM doesn’t handle DNS updates on its own.

  8. Is my data encrypted then?
    With SSL enabled, yes, at least between your browser and Nginx Proxy Manager. Internal traffic runs over the Docker network.

  9. Can I block external users?
    Yes, via access lists with passwords or IP whitelisting.

  10. What’s the difference between this and Nginx itself?
    NPM is Nginx with a web interface and additional management features.

  11. Do I have to write Nginx configurations?
    No, NPM handles that automatically behind the scenes. Advanced users can add custom snippets if needed.

  12. How do I restart NPM without losing data?
    Run docker compose restart in the project folder. Data in volumes is preserved.

Sources

  • Nginx Proxy Manager Documentation: nginxproxymanager.com
  • Nginx Official Documentation: nginx.org
  • Let’s Encrypt Documentation: letsencrypt.org
  • Docker Compose Reference: docker.com
  • Ollama Official Documentation: ollama.com
  • Cloudflare Community Guides on DNS Configuration
Back to Blog
Share:

Nächster Artikel in Self-Hosting

Weiterlesen
WireGuard: Private VPN for AI Services

Related Posts