- Task
- Create
Run Liquibase Secure server behind a reverse proxy
Last updated: September 29, 2026
The Liquibase Secure server bundle includes its own reverse proxy, which terminates TLS and routes traffic to the API and the web app. A standard deployment does not need anything in front of it. Use this guide when your organization requires an existing entry point, such as a corporate nginx tier, a load balancer, or another proxy that all internal applications sit behind.
Procedure
Forward traffic to the server's HTTPS port
Your proxy forwards all requests for the deployment's hostname to the server host on its HTTPS port, which defaults to 443 and is set by LIQUIBASE_PLATFORM_HTTPS_PORT. The bundled proxy then routes requests internally. Paths under /api/ go to the server API, and everything else goes to the web app, so your external proxy needs no path-based routing rules.
Configure forwarded headers, WebSockets, and timeouts
Forwarded headers: The API trusts
X-Forwarded-ForandX-Forwarded-Protofor logging and authentication redirect URLs. Always set them, along withHostandX-Real-IP.WebSocket support: The web app uses WebSocket connections for live updates. The proxy must use HTTP/1.1 and forward the
UpgradeandConnectionheaders. If it does not, clients silently fall back to HTTP long-polling, which is slower and more resource-intensive.Timeouts: WebSocket connections are long-lived. Raise the proxy's read and send timeouts well above the common 60 second default.
Update the application URLs
Set the URL variables in .env to the public hostname your proxy serves, then restart the stack. If the proxy runs on a different origin than the web app URL, also set LIQUIBASE_PLATFORM_CORS_ORIGINS.
Be sure to:
Replace
liquibase.example.comwith the hostname your proxy serves
LIQUIBASE_PLATFORM_WEB_URL=https://liquibase.example.com
LIQUIBASE_PLATFORM_API_URL=https://liquibase.example.com/api
NEXT_PUBLIC_API_URL=https://liquibase.example.comConfigure your proxy
Be sure to:
Replace
liquibase.example.comwith the hostname your proxy servesReplace
your_server_hostwith the host where the Liquibase Secure server bundle runs
Note: In nginx, use the literal string "upgrade" for the Connection header as shown. Using a variable for the value breaks the WebSocket upgrade.
Other proxies work the same way. Traefik forwards WebSocket upgrades automatically on its HTTPS entrypoint, and Caddy handles them by default with reverse_proxy. Apply the same forwarded headers and timeout guidance in each.