Setup a Reverse Proxy & a Load Balancer on ports 80 and 443 with Nginx

Viewed 75

I want to use Nginx to act as a reverse proxy to serve multiple services on fixed URL and IP while managing their SSL certificates AND as a load balancer to send other requests to a Traefik container hosted on a orchestrator. When acting as a load balancer, I don't need Nginx to handle SSL certificates

The issue is that both the reverse proxy and the load balancer have to listen on ports 80 and 443 in order to give access to everything but I can't figure out how to configure Nginx to do that. I can only make either one of those works at a time but not both at the same time.

The global infrastructure is available at https://i.stack.imgur.com/BxGnP.png

I have a Nomad (orchestrator) & Consul (service mesh) Cluster with 3 servers (S0, S1 & S2) and 3 clients (C0, C1 & C2). On the servers, there are Nomad and Consul web UIs. On the clients there is the Traefik Docker container serving various services as a reverse proxy and handling SSL certificates. In front of all of that, I have the Nginx on Debian 10.

Here are the configuration files I'm currently. The reverse proxy part is working but the load balancer part isn't. (I'm using Ansible to deploy everything so these files are jinja templates)

nomad.j2:

upstream nomad_panel{
  {% for server_addr in agents["server-neteau_ip_v4"]["value"] %}
    server  {{ agents["server-neteau_ip_v4"]["value"][server_addr] }}:4646;
  {% endfor %}
}


server {
        listen 80;
        server_name nomad_URL;
        
        location ^~/.well-known/ {
          root /var/lib/certbot;
        }
        location  /{
          return 301 https://$host$request_uri;
        }
}

server {
        listen 443 ssl;
        server_name nomad_URL;

        ssl_certificate /etc/letsencrypt/live/nomad_URL/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/nomad_URL/privkey.pem; 
        ssl_trusted_certificate /etc/letsencrypt/live/nomad_URL/chain.pem;
        
        location /{
          proxy_pass http://nomad_panel;
          proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
          proxy_read_timeout 310s;
          proxy_buffering off;

          # The Upgrade and Connection headers are used to establish
          # a WebSockets connection.
          proxy_set_header Upgrade $http_upgrade;
          proxy_set_header Connection "upgrade";

          # The default Origin header will be the proxy address, which
          # will be rejected by Nomad. It must be rewritten to be the
          # host address instead.
          proxy_set_header Origin "${scheme}://${proxy_host}";
        }


}

consul.j2:

upstream consul_panel{
  {% for server_addr in agents["server-neteau_ip_v4"]["value"] %}
    server  {{ agents["server-neteau_ip_v4"]["value"][server_addr] }}:8500;
  {% endfor %}
}


server {
        listen 80;
        server_name consul_URL;
        
        location ^~/.well-known/ {
          root /var/lib/certbot;
        }
        location /{
        return 301 https://$host$request_uri;
        }

 
}

server {
        listen 443 ssl;
        server_name consul_URL;

        ssl_certificate /etc/letsencrypt/live/consul_URL/fullchain.pem;
        ssl_certificate_key /etc/letsencrypt/live/consul_URL/privkey.pem; 
        ssl_trusted_certificate /etc/letsencrypt/live/consul_URL/chain.pem;
        

        location /{
          #resolver 8.8.8.8 valid=30s;
          proxy_pass http://consul_panel;

        }

}

traefik.j2:

upstream web{
  {% for client_addr in agents["client-neteau_ip_v4"]["value"] %}
    server  {{ agents["client-neteau_ip_v4"]["value"][client_addr] }}:8080;
  {% endfor %}
}
upstream secure_web{
  {% for client_addr in agents["client-neteau_ip_v4"]["value"] %}
    server  {{ agents["client-neteau_ip_v4"]["value"][client_addr] }}:8443;
  {% endfor %}
}


server {
        listen 80 default_server;
        server_name _;
        location /{
          #resolver 8.8.8.8 valid=30s;
          proxy_pass http://web;
          proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
          proxy_read_timeout 310s;
          proxy_buffering off;

          # The Upgrade and Connection headers are used to establish
          # a WebSockets connection.
          proxy_set_header Upgrade $http_upgrade;
          proxy_set_header Connection "upgrade";
          # Mandatory to preserve URL in host (and to survive upstream's redirections)
          proxy_set_header Host $host;
          # The default Origin header will be the proxy address, which
          # will be rejected by Nomad. It must be rewritten to be the
          # host address instead.
          proxy_set_header Origin "${scheme}://${proxy_host}";
        }
}

server {
        listen 443;
        server_name _;

        location /{
          #resolver 8.8.8.8 valid=30s;
          proxy_pass http://secure_web;
          proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
          proxy_read_timeout 310s;
          proxy_buffering off;
          # Mandatory to preserve URL in host (and to survive upstream's redirections)
          proxy_set_header Host $host;
          # The Upgrade and Connection headers are used to establish
          # a WebSockets connection.
          proxy_set_header Upgrade $http_upgrade;
          proxy_set_header Connection "upgrade";

          # The default Origin header will be the proxy address, which
          # will be rejected by Nomad. It must be rewritten to be the
          # host address instead.
          proxy_set_header Origin "${scheme}://${proxy_host}";
        }
}
0 Answers
Related