Reverse Proxies
Already running a reverse proxy? Skip ahead to Requirements.
A reverse proxy is a server that sits in front of your apps and passes each request to the right one. When you open https://profilarr.example.com, the request doesn’t go to Profilarr. It goes to the proxy, which reads the name you typed, finds the app that name belongs to, and forwards the request to Profilarr over plain HTTP inside your network. The proxy handles the HTTPS side, so Profilarr never sees it.
That gets you:
- An address you can remember, like
profilarr.example.cominstead of192.168.1.10:6868. - HTTPS for every app, set up once in the proxy instead of in each app.
- One place to put a login like Authelia or Authentik in front of all your apps.
If you only need to reach Profilarr yourself, you might not need a reverse proxy at all. A VPN like WireGuard or Tailscale gets you to Profilarr from anywhere without exposing it to the internet. See Authentication.
Requirements
Behind a proxy, Profilarr never sees your browser’s request. It only sees the proxy’s copy, so it can’t tell whether you used HTTPS or where you’re connecting from. Whichever proxy you use, Profilarr needs a few things to work around that.
| Requirement | Why | Without it |
|---|---|---|
Set ORIGIN to the address you open Profilarr at | Profilarr only accepts forms submitted from its own address. The proxy talks to Profilarr over plain HTTP, so without ORIGIN, Profilarr thinks its address starts with http:// and rejects your browser's https:// forms. | Pages load, but every form fails with "Request blocked: origin mismatch". |
| Use one address | ORIGIN holds one address, and Profilarr only accepts forms submitted from that address. | Pages load at other addresses, like http://192.168.1.10:6868, but every form fails there. See #927. |
| Use a subdomain | Every link and request Profilarr makes points at the root of its address. | Pages break in a folder like example.com/profilarr. See #245. |
Don't buffer /jobs/events, and allow more than 30 seconds between messages | Profilarr streams job progress from /jobs/events and sends a message every 30 seconds to keep the stream open. | Job progress doesn't update while a job runs. |
| Accept uploads up to 1 GB, and give them time to finish | You can upload backups of up to 1 GB. | Backup uploads fail with "Failed to upload backup". |
ORIGIN to the address you open Profilarr at/jobs/events, and allow more than 30 seconds between messages/jobs/events and sends a message every 30 seconds to keep the stream open.Why check forms at all? Another website can make your browser submit a form to Profilarr without you knowing. This is called cross-site request forgery (CSRF). For example:
- You open a malicious website on a computer that can reach Profilarr.
- The website has a hidden form that deletes one of your Arr instances.
- Your browser submits that form to Profilarr.
Profilarr checks which website each form came from and rejects forms from any other website. To run that check, Profilarr needs to know its own address.
Guides
| Proxy | Description | Status |
|---|---|---|
| Traefik | Configures itself from labels on your Docker containers. Recommended if you run Profilarr with Docker. | Available |
| Caddy | Gets and renews HTTPS certificates automatically, with a short config file. | Not written |
| nginx | A general-purpose web server. This guide also covers SWAG and Nginx Proxy Manager, which run nginx underneath. | Not written |
If you’d like to help write the Caddy or nginx (including SWAG and Nginx Proxy Manager) guide, please feel free to contribute here.