# Loadbalancing and Proxying MENDER-API-GATEWAY-DOCKER behind an NGINX worker that is running on Host

**URL:** <https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210>\
**Category:** General Discussions\
**Tags:** nginx, api-gateway\
**Created:** [November 3, 2019, 7:50am UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210 "2019-11-03T07:50:46Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![uttaravadina](https://avatars.discourse-cdn.com/v4/letter/u/e99b99/32.png) [@uttaravadina](https://hub.mender.io/u/uttaravadina)\
**Post date:** [November 3, 2019, 7:50am UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/1 "2019-11-03T07:50:46Z")

</div>

First of all, thank you Mender team for creating this efficient and kickass OTA service and open-sourcing it.  
I have been using it for a small period of time for experimenting mostly and so far everything has been pretty good so far.

Since I am experimenting, I am trying out different combinations by which the self-hosted version can be hosted. Here is one such combination I am having trouble configuring.

I would like to proxy and also load balance the Api-Gateway-Docker behind an Nginx worker alongside other services (say, service A, B and C) apart from the Mender suite.

How should I go about the nginx configuration that can forward the requests to the Mender-Api-Gateway-Docker?

Here is a [diagram](https://yadi.sk/i/XoEm5LHWp2YgWw) for reference.

---

<div class="post-metadata">

**Author:** ![uttaravadina](https://avatars.discourse-cdn.com/v4/letter/u/e99b99/32.png) [@uttaravadina](https://hub.mender.io/u/uttaravadina)\
**Post date:** [November 15, 2019, 1:53pm UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/2 "2019-11-15T13:53:39Z")

</div>

Can someone provide a sample config file for referencing? It will be really helpful if someone can guide me.

---

<div class="post-metadata">

**Author:** ![peter](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@peter](https://hub.mender.io/u/peter)\
**Post date:** [November 15, 2019, 5:34pm UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/3 "2019-11-15T17:34:45Z")

</div>

Hello!

thanks a lot for using Mender.  
I am not sure what you are trying exactly to achieve, but please note that the api gateway (docker pull mendersoftware/api-gateway:2.0.0) is based on openresty which is nginx-based. you can take a look at /usr/local/openresty and do any configuration modifications you want. At least that is what I would do.  
What is the reason for the extra nginx? Do you want just a loadbalancer? In any case it can be something very simple, since the api-gateway is, well, the main gateway.  
Let me know if you need some more details or assistance. And sorry for not giving a straight answer, perhaps I am missing the exact use case here.

peter

---

<div class="post-metadata">

**Author:** ![uttaravadina](https://avatars.discourse-cdn.com/v4/letter/u/e99b99/32.png) [@uttaravadina](https://hub.mender.io/u/uttaravadina)\
**Post date:** [November 16, 2019, 10:25am UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/4 "2019-11-16T10:25:42Z")

</div>

The idea is to run Mender in parallel with other services which run independently and may not run in a docker environment. As you will see in the link to the diagram I have provided above @peter

---

<div class="post-metadata">

**Author:** ![peter](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@peter](https://hub.mender.io/u/peter)\
**Post date:** [November 16, 2019, 2:32pm UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/5 "2019-11-16T14:32:09Z")

</div>

I see, thank you for explanation. Then maybe it is better to change the topology of your diagram and incorporate the configuration of api-gateway into your nginx config or, alternatively, slightly modify the configuration and use api-gateway for all services.  
We do not have the standalone ready nginx working configuration, but I would do one of the above; if you take a look at the api-gateway openresty config you will see that it is not that complicated.

peter

---

<div class="post-metadata">

**Author:** ![uttaravadina](https://avatars.discourse-cdn.com/v4/letter/u/e99b99/32.png) [@uttaravadina](https://hub.mender.io/u/uttaravadina)\
**Post date:** [November 17, 2019, 12:00pm UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/6 "2019-11-17T12:00:32Z")

</div>

Yes, I am looking at the api-gateway configuration and it actually is not complicated at all, provided some basic understanding of Load-balancing and proxying exists.

For my current use case, it will be best if I do the 1st approach, i.e., to incorporate config of api-gateway into the Nginx config, as I have a cronjob that periodically updates the SSL certificates.  
If I am successfull I will definitely share the Nginx ready-to-go configuration for self-hosted Mender.

Thanks a lot for the help @peter. It was really helpful!

---

<div class="post-metadata">

**Author:** ![peter](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@peter](https://hub.mender.io/u/peter)\
**Post date:** [November 17, 2019, 3:49pm UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/7 "2019-11-17T15:49:57Z")

</div>

Thank you!  
Let me know how it goes! good luck @uttaravadina!

peter

---

<div class="post-metadata">

**Author:** ![uttaravadina](https://avatars.discourse-cdn.com/v4/letter/u/e99b99/32.png) [@uttaravadina](https://hub.mender.io/u/uttaravadina)\
**Post date:** [November 19, 2019, 7:48am UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/8 "2019-11-19T07:48:37Z")

</div>

So I was able to solve the reverse-proxying without using any of the 2 methods that @peter you mentioned.

**Solution:**  
The simple and most effective way to solve this can be to expose the **mender-api-gateway** to a different host port rather than the default set 443 port in **prod.yml** and then using the proxy\_pass to forward the requests to the exposed host port for mender-api-gateway.

**Confusion:**  
Although one interesting thing that I notice is when I do a curl request on the machine locally to the exposed port of the mender-api-gateway **(curl [http://localhost](http://localhost):$PORT/)**, it throws an error saying that the certificates appears to be self-signed and therefore cannot create connection, which makes sense. But the host nginx is able to proxy forward the requests to the mender-apigateway without any such errors, which is confusing to me. I haven’t even provided an proxy\_ssl\_\* parameters in the host nginx config file.

What can be the possible explanation to this @peter?

---

<div class="post-metadata">

**Author:** ![peter](https://avatars.discourse-cdn.com/v4/letter/p/278dde/32.png) [@peter](https://hub.mender.io/u/peter)\
**Post date:** [November 22, 2019, 11:44pm UTC](https://hub.mender.io/t/loadbalancing-and-proxying-mender-api-gateway-docker-behind-an-nginx-worker-that-is-running-on-host/1210/9 "2019-11-22T23:44:29Z")

</div>

so you have a proxy at address0:443 that points to address1:port1 and address1:port1 is a port exposed by mender-api-gateway, right? and when you do curl [https://address0](https://address0) you get no error, while with curl [https://address1](https://address1):port1 you get certificate error?  
could you share the logs form the proxy?

peter
