API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) · Урок

Пересылка заголовков и IP-адрес клиента

Узнайте, как Nginx изменяет заголовки запросов при проксировании и как сохранять исходную информацию о клиенте для вышестоящих приложений.

Урок 4 из 413 шагов

«Пересылка заголовков и IP-адрес клиента» — бесплатный урок API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) на CoddyKit. Это урок 4 из 4. Ты можешь прочитать весь урок бесплатно ниже — а потом практиковать его прямо в браузере с встроенным редактором кода и ИИ-репетитором 24/7. Это часть пути обучения API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), и твой прогресс синхронизируется между веб-версией и приложением CoddyKit. Курс API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) содержит 4 уроков всего.

Части этого урока еще не переведены и отображаются на английском.

Why Headers Matter

When Nginx acts as a reverse proxy, the upstream server only sees a connection coming from Nginx, not the real client. Without extra configuration, the backend loses the visitor's original IP, host, and protocol.

To keep this information, Nginx must forward headers describing the original request.

The Default Host Header

By default Nginx may pass the upstream server's address as the Host header. Many apps rely on the original host for routing or building absolute URLs.

Set it explicitly so the backend sees what the client requested:

location / {
    proxy_pass http://backend;
    proxy_set_header Host $host;
}

Preserving the Real Client IP

The X-Real-IP header carries the original client's address so the backend can log or rate-limit by real visitor.

  • $remote_addr holds the connecting client's IP
proxy_set_header X-Real-IP $remote_addr;

X-Forwarded-For Chain

X-Forwarded-For is a comma-separated chain of every proxy a request passed through. The variable $proxy_add_x_forwarded_for appends the current client to any existing value.

proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;

Forwarding the Protocol

If TLS terminates at Nginx, the backend speaks plain HTTP and cannot tell the original scheme. Send X-Forwarded-Proto so it can build correct https URLs and set secure cookies.

proxy_set_header X-Forwarded-Proto $scheme;

Putting It Together

A standard reverse-proxy block bundles all four headers. This is the baseline you will reuse across nearly every project.

location / {
    proxy_pass http://backend;
    proxy_set_header Host $host;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
}

Reusing Header Config

Repeating the same headers in every location is error prone. Put them in an include file and pull it in wherever needed.

# /etc/nginx/proxy_headers.conf
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;

# in a server/location block:
include /etc/nginx/proxy_headers.conf;

Trusting Forwarded Headers Safely

Clients can spoof X-Forwarded-For. Only trust it from known proxies. Use the real_ip module to set the true client IP from trusted upstreams.

set_real_ip_from 10.0.0.0/8;
real_ip_header X-Forwarded-For;
real_ip_recursive on;

Removing or Clearing Headers

You can strip a header by setting it to an empty string. This is useful to hide internal headers from upstream or to prevent leaking server identity.

proxy_set_header X-Powered-By "";
proxy_hide_header X-Powered-By;

Passing Custom Headers

You can inject your own headers to give the backend extra context, such as a tag identifying which gateway handled the request.

proxy_set_header X-Gateway-Node "edge-1";
proxy_set_header X-Request-Start $msec;

Verifying the Result

Test from a backend that echoes headers (or use an inspector endpoint). You should see X-Real-IP matching your machine and X-Forwarded-Proto matching the scheme you used.

curl -H "Host: example.com" http://localhost/headers

Quick Check

Which Nginx variable appends the current client to an existing forwarding chain?

Recap

You learned how Nginx rewrites requests and how to keep client context intact:

  • Host preserves the requested domain
  • X-Real-IP and X-Forwarded-For carry the client IP
  • X-Forwarded-Proto reports the original scheme
  • Use real_ip and trusted ranges to avoid spoofing

These headers are the foundation of a transparent, secure reverse proxy.

Можно начать бесплатно

Изучай API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) с ИИ-репетитором — бесплатно

Пиши и запускай код прямо в браузере, получай мгновенную помощь от ИИ-репетитора 24/7 и продолжи учиться на сайте или в приложении.

Курсы
12
Уроки
48

Часто задаваемые вопросы

Урок «Пересылка заголовков и IP-адрес клиента» бесплатный?

Да — полный текст урока «Пересылка заголовков и IP-адрес клиента» бесплатно доступен здесь в веб-версии. Чтобы практиковать его интерактивно (встроенный редактор кода и ИИ-репетитор 24/7) и разблокировать остальной курс API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), подпишись на CoddyKit PRO. Курс API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) содержит 4 уроков всего.

Чему я научусь в уроке «Пересылка заголовков и IP-адрес клиента»?

Узнайте, как Nginx изменяет заголовки запросов при проксировании и как сохранять исходную информацию о клиенте для вышестоящих приложений. Ты практикуешь API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) с помощью реального кода, который запускаешь прямо в браузере, и ИИ-репетитор 24/7 отвечает на твои вопросы во время урока.

Нужен ли мне опыт, чтобы начать API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)?

Предыдущий опыт не требуется. API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) на CoddyKit структурирован для всех уровней — от новичков до продвинутых, поэтому ты можешь начать отсюда или с самого начала и учиться в своем темпе. Это урок 4 из 4.

Сколько времени занимает урок «Пересылка заголовков и IP-адрес клиента»?

Большинство уроков CoddyKit занимают около 5–10 минут. Каждый из них компактный и интерактивный, поэтому ты постоянно делаешь прогресс и продолжаешь с того же места в веб-версии и приложении.

Можно ли писать и запускать код в этом уроке API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)?

Да. Каждый урок API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) включает встроенный редактор кода, поэтому ты пишешь и запускаешь реальный код прямо в браузере и получаешь моментальную обратную связь от AI — локальная установка не требуется.

Все уроки этого курса

  1. Настройка простого обратного прокси
  2. Серверы upstream и балансировка нагрузки
  3. Буферизация и кэширование прокси
  4. Пересылка заголовков и IP-адрес клиента
← Назад к API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway)