English | 한국어
A secure and fast solution to manage proxy hosts, SSL certificates,
and security rules through an intuitive web UI
Website • Features • Quick Start • Tech Stack • API
Robust Security, Easy Management - Reduced Nginx complexity, maximized security
Let's Encrypt integration with automatic renewal. Supports wildcard certificates via DNS-01 challenge. Multiple DNS providers supported: Cloudflare, DuckDNS, Dynu.
Block 80+ malicious bots and 50+ AI crawlers automatically. Search engine allowlist ensures legitimate traffic. CAPTCHA challenge mode for suspicious requests.
Real-time traffic monitoring, security block logs, certificate status, and server health at a glance.
Block or allow traffic by country with interactive world map visualization. MaxMind GeoIP2 integration with auto-update.
Analyze Nginx access/error logs with powerful filtering and exclusion patterns. TimescaleDB time-series optimization with automatic compression.
ModSecurity v3 with OWASP Core Rule Set v4.21. Paranoia Level 1-4, per-host rule exceptions, exploit blocking rules.
Protect against DDoS and brute-force attacks with configurable rate limits per IP, URI, or IP+URI combination.
Multiple backend servers with round-robin, least connections, IP hash, or weighted distribution. Health checks included.
HSTS, X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy, and Content-Security-Policy.
IP-based access control lists for whitelisting or blacklisting. Support for CIDR notation.
Full configuration backup including certificates, settings, and database. Scheduled auto-backup support.
Create API tokens with granular permissions, IP restrictions, and expiration. Perfect for CI/CD integration.
HTTP to HTTPS redirects, domain redirects, and custom redirect rules.
Track all configuration changes with user attribution and timestamps.
Optional 2FA for admin accounts using TOTP (Google Authenticator, Authy, etc.).
Modern protocol support for faster, more reliable connections over UDP.
Solid Tech Stack - Designed with modern technologies, a microservices architecture
| Technology | Purpose |
|---|---|
| Nginx 1.28 | High-performance reverse proxy core with HTTP/3 & QUIC support |
| TimescaleDB | PostgreSQL with time-series optimization for log compression |
| Valkey 8 | Redis-compatible high-speed caching and session management |
| Go 1.23 | Backend API with efficient resource management and concurrency |
| React 18 & TypeScript | Type-safe, component-based modern UI |
| ModSecurity 3 | Web Application Firewall with OWASP Core Rule Set v4.21 |
| MaxMind GeoIP2 | Geographic IP database for country-level access control |
Get Started in 1 Minute - Run Nginx Proxy Guard using Docker Compose
- Docker 24.0+ and Docker Compose v2
- (Optional) MaxMind License Key for GeoIP
# 1. Create directory
mkdir -p ~/nginx-proxy-guard && cd ~/nginx-proxy-guard
# 2. Download files
wget https://raw.githubusercontent.com/svrforum/nginxproxyguard/main/docker-compose.yml
wget -O .env https://raw.githubusercontent.com/svrforum/nginxproxyguard/main/env.example
# 3. Auto-generate secure secrets
sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -base64 24)/" .env
sed -i "s/JWT_SECRET=.*/JWT_SECRET=$(openssl rand -hex 32)/" .env
# 4. Start services
docker compose up -d| Service | URL |
|---|---|
| Admin Panel | https://localhost:81 |
| HTTP Proxy | http://localhost:80 |
| HTTPS Proxy | https://localhost:443 |
Default Login: admin / admin (Change immediately after first login!)
docker compose pull
docker compose up -dNginx Proxy Guard provides a comprehensive REST API for automation and integration.
All API endpoints require authentication via:
- JWT Token:
Authorization: Bearer <jwt_token>(from login) - API Token:
Authorization: Bearer ng_<api_token>(for automation)
| Endpoint | Description |
|---|---|
POST /api/v1/auth/login |
Authenticate and get JWT token |
GET /api/v1/proxy-hosts |
List all proxy hosts |
POST /api/v1/proxy-hosts |
Create new proxy host |
GET /api/v1/certificates |
List SSL certificates |
POST /api/v1/certificates |
Request new certificate |
GET /api/v1/waf/rules |
List WAF rules |
POST /api/v1/backups |
Create backup |
GET /api/v1/dashboard |
Get dashboard stats |
Access the interactive API documentation at:
https://localhost:81/api/v1/swagger
| Variable | Description | Default |
|---|---|---|
DB_PASSWORD |
PostgreSQL password | (required) |
JWT_SECRET |
Secret for JWT tokens | (required) |
TZ |
Timezone | UTC |
DB_USER |
PostgreSQL user | postgres |
DB_NAME |
Database name | nginx_proxy_guard |
DOCKER_API_VERSION |
Docker API version (for Synology) | auto-detect |
- Website: nginxproxyguard.com
- Documentation: nginxproxyguard.com/docs
This project is licensed under the MIT License - see the LICENSE file for details.
- GitHub Issues - Bug reports and feature requests
- Discussions - Questions and community