# Edge reverse proxy

Source: https://docs.quake.ai/resources/iac-templates/edge-reverse-proxy
Markdown: https://docs.quake.ai/resources/iac-templates/edge-reverse-proxy.md

---

# Edge reverse proxy

This pattern composes Compute, Network, and Block Storage into a self-hosted reverse proxy with automatic TLS on infrastructure you control.

## What this template does

Provisions a single instance running [Caddy](https://caddyserver.com), an open-source reverse proxy, that terminates TLS on a floating IP and forwards traffic to a private backend:

- Compute instance that runs Caddy in Docker, sized for TLS termination and routing (2 vCPU and 2 GiB RAM)
- Private network, subnet, router, port, and security group; a floating IP on the proxy only
- A block volume mounted at `/data`, so Caddy certificate state lives on a volume you can grow rather than on the boot disk
- cloud-init installs Docker, writes a Caddyfile for your backend, and starts Caddy on first boot

The backend stays on the private subnet with no floating IP of its own. You set `upstream_host` and `upstream_port` to the private address of the backend, then lock the backend security group to accept traffic only from the proxy.

No credential ships with this template. Caddy obtains a Let's Encrypt certificate automatically when you set `domain` and point its DNS A record at the floating IP.

## Honest scope

This proxy runs in one region on a VM you operate. It is a regional reverse proxy, not a global edge network: Quake AI has no anycast, no global PoPs, and no first-party CDN. For geographic distribution and volumetric DDoS absorption at the network edge, [front the origin with a third-party CDN](/docs/network/how-to/front-with-cdn).

## Alternate engines

This template leads with Caddy (automatic HTTPS, single binary, minimal config). [Traefik 3](https://traefik.io) fits when the proxy fronts many containers with label-based discovery. [Nginx Proxy Manager](https://nginxproxymanager.com) fits when you want a web UI instead of editing config files. Both are MIT-licensed; swap the container and config in cloud-init if you prefer one of them.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (Caddy runs on 2 vCPU / 2 GiB) | `s1a.small` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `edge-reverse-proxy` |
| `caddy_version` | Caddy container image tag | `2-alpine` |
| `domain` | Public domain for automatic HTTPS; empty serves HTTP on the floating IP | `""` |
| `upstream_host` | Private IP of the backend instance | `10.42.0.10` |
| `upstream_port` | TCP port the backend listens on | `8080` |
| `volume_size` | Block volume size in GiB, mounted at `/data` | `10` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.42.0.0/24` |

## Ports and access

| Port | Purpose |
| --- | --- |
| 22 | Host SSH for administration |
| 80 | HTTP (ACME challenges when `domain` is set; the public entry when it is not) |
| 443 | HTTPS when `domain` is set and Caddy has obtained a certificate |

## When to use this pattern

Run your own reverse proxy and TLS front door on a VM you operate, so a private app backend reaches the internet through one controlled entry point instead of exposing the origin directly. This is the foundation template for the edge and gateway family; the WAF, API gateway, and tunnel templates build on the same shape.

For DNS and certificate join points, see [point a domain to Quake AI](/docs/network/how-to/point-domain-to-quake-ai) and [Let's Encrypt certificates](/docs/network/how-to/lets-encrypt-certificate). For the WAF concept this template omits, see [front with a WAF](/docs/network/how-to/front-with-waf).

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "edge-reverse-proxy", required: true },
  ]}
/>

## Template source

This is a [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked).

<TemplateSource slug="edge-reverse-proxy" />

<TemplateResourceMap template="edge-reverse-proxy" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy an edge reverse proxy with the edge-reverse-proxy template](/resources/deployments/deploy-edge-reverse-proxy-template)
- [API gateway template](/resources/iac-templates/api-gateway)
- [Private network + VPN template](/resources/iac-templates/private-network-vpn)
- [Front with a CDN](/docs/network/how-to/front-with-cdn)
