Files
silverlinux-infra/nginx-proxy-manager/README.md
T
2026-06-22 15:55:41 +03:30

209 lines
3.1 KiB
Markdown

# Nginx Proxy Manager
## Overview
Nginx Proxy Manager (NPM) is the public entry point for all internet-facing services hosted on SilverLinux.
It provides:
* Reverse proxy routing
* SSL certificate management
* HTTPS termination
* Domain forwarding
* Centralized access to services
All public services should be exposed through Nginx Proxy Manager instead of directly exposing application ports.
---
## Service Information
Container Name:
```text
nginx-proxy-manager
```
Image:
```text
jc21/nginx-proxy-manager:latest
```
Docker Network:
```text
proxy
```
---
## Ports
| Port | Purpose |
| ---- | ---------------------------------- |
| 80 | HTTP |
| 81 | Nginx Proxy Manager Administration |
| 443 | HTTPS |
---
## Data Storage
### Application Data
```text
/srv/docker/nginx-proxy-manager/data
```
Contains:
* Proxy host configuration
* Access lists
* Users
* Application settings
* SSL metadata
---
### SSL Certificates
```text
/srv/docker/nginx-proxy-manager/letsencrypt
```
Contains:
* Let's Encrypt certificates
* Private keys
* Renewal information
This folder is critical for disaster recovery.
---
## Responsibilities
Nginx Proxy Manager is responsible for:
### Reverse Proxy
Routing incoming requests to Docker containers.
Examples:
| Domain | Target Service |
| --------------------------- | -------------- |
| git.silveressence.net | Gitea |
| team.silveressence.net | OpenProject |
| meet.silveressence.net | Jitsi |
| portainer.silveressence.net | Portainer |
| nuget.silveressence.net | BaGet |
| dbgate.silveressence.net | DbGate |
---
### SSL Certificates
Provides:
* HTTPS encryption
* Certificate renewal
* Certificate management
All public services should use HTTPS.
---
### Domain Management
Centralized management for:
* Domains
* Subdomains
* SSL certificates
* Proxy routing
---
## Docker Configuration
Volumes:
```text
/srv/docker/nginx-proxy-manager/data:/data
/srv/docker/nginx-proxy-manager/letsencrypt:/etc/letsencrypt
```
Network:
```text
proxy
```
Applications exposed through NPM must be connected to the proxy network.
---
## Administration
Web Interface:
```text
https://portainer.silveressence.net
```
Nginx Proxy Manager Admin:
```text
http://SERVER-IP:81
```
or through the configured domain if one exists.
---
## Backup Requirements
The following directories must be backed up:
```text
/srv/docker/nginx-proxy-manager/data
/srv/docker/nginx-proxy-manager/letsencrypt
```
Without these directories:
* SSL certificates are lost
* Proxy configurations are lost
* Domain mappings must be recreated
---
## Security Notes
* Only ports 80 and 443 should be exposed publicly.
* Administrative access should be restricted.
* SSL certificates should be renewed automatically.
* Services should never be exposed directly to the internet when NPM can proxy them.
---
## Related Services
* Gitea
* OpenProject
* Jitsi Meet
* Portainer
* BaGet
* DbGate
---
## Related Documentation
* docs/server.md
* docs/security.md
* docs/domains.md
* docs/backups.md