• Task
  • Create

Run Liquibase Secure server behind a reverse proxy

Last updated: September 29, 2026

The Liquibase Secure server bundle includes its own reverse proxy, which terminates TLS and routes traffic to the API and the web app. A standard deployment does not need anything in front of it. Use this guide when your organization requires an existing entry point, such as a corporate nginx tier, a load balancer, or another proxy that all internal applications sit behind.

Procedure

1

Forward traffic to the server's HTTPS port

Your proxy forwards all requests for the deployment's hostname to the server host on its HTTPS port, which defaults to 443 and is set by LIQUIBASE_PLATFORM_HTTPS_PORT. The bundled proxy then routes requests internally. Paths under /api/ go to the server API, and everything else goes to the web app, so your external proxy needs no path-based routing rules.

2

Configure forwarded headers, WebSockets, and timeouts

  • Forwarded headers: The API trusts X-Forwarded-For and X-Forwarded-Proto for logging and authentication redirect URLs. Always set them, along with Host and X-Real-IP.

  • WebSocket support: The web app uses WebSocket connections for live updates. The proxy must use HTTP/1.1 and forward the Upgrade and Connection headers. If it does not, clients silently fall back to HTTP long-polling, which is slower and more resource-intensive.

  • Timeouts: WebSocket connections are long-lived. Raise the proxy's read and send timeouts well above the common 60 second default.

3

Update the application URLs

Set the URL variables in .env to the public hostname your proxy serves, then restart the stack. If the proxy runs on a different origin than the web app URL, also set LIQUIBASE_PLATFORM_CORS_ORIGINS.

Be sure to:

  • Replace liquibase.example.com with the hostname your proxy serves

LIQUIBASE_PLATFORM_WEB_URL=https://liquibase.example.com
LIQUIBASE_PLATFORM_API_URL=https://liquibase.example.com/api
NEXT_PUBLIC_API_URL=https://liquibase.example.com
4

Configure your proxy

Be sure to:

  • Replace liquibase.example.com with the hostname your proxy serves

  • Replace your_server_host with the host where the Liquibase Secure server bundle runs

loading

Note: In nginx, use the literal string "upgrade" for the Connection header as shown. Using a variable for the value breaks the WebSocket upgrade.

Other proxies work the same way. Traefik forwards WebSocket upgrades automatically on its HTTPS entrypoint, and Caddy handles them by default with reverse_proxy. Apply the same forwarded headers and timeout guidance in each.