Back to BlogApplication Deployment

Nginx Reverse Proxy for WebSocket Applications

Upgrade headers, timeouts, and load balancing for realtime features behind Nginx on Linux.

How WebSocket differs from HTTP

WebSocket connections start as HTTP requests then upgrade to a persistent channel. Nginx must pass Upgrade and Connection headers correctly or clients fall back to polling with poor performance.

Vcom Web Tech validates websocket paths separately from static assets because caching rules differ.

Sticky sessions may be required when multiple upstream Node processes maintain in-memory connection state.

Configuration essentials

Use proxy_http_version 1.1 and map Connection headers appropriately. Increase proxy_read_timeout because websocket connections stay open far longer than typical HTTP requests.

Disable buffering for streaming endpoints when latency matters.

Test with browser devtools and wscat from the server to isolate Nginx versus application faults.

TLS termination

Browsers require wss when pages load over https. Terminate TLS at Nginx and proxy plain HTTP to localhost upstreams on trusted hosts.

Certificate renewals should not drop active websocket connections without warning; schedule reloads during low usage when possible.

HTTP/2 and websocket interactions depend on Nginx version capabilities; verify docs for your release.

Scaling

Separate websocket upstream pools from stateless HTTP pools when tuning timeouts differently.

Consider dedicated realtime services when connection counts exceed single-host limits.

Monitor open file descriptors on Nginx and Node under high connection churn.

Additional operational notes

Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.

When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.

Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.

Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.

Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.

Additional operational notes

Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.

When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.

Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.

Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.

Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.