https://postqueen.example.com.
What a reverse proxy is
A reverse proxy is a small program that sits in front of your app. It takes requests from the internet on the standard web ports, handles the HTTPS certificate, and passes each request along to the app running quietly on a local port. You need one because PostQueen does not manage certificates herself, and because you do not want her port open to the world. The proxy is also where the certificate lives, which is why the tools below can obtain and renew one for you automatically. You never handle certificate files by hand.Why HTTPS is not optional here
This is not a general recommendation. Two things genuinely stop working without it. Sign-in. PostQueen marks her login cookies as secure, which is a browser rule meaning the cookie is only sent over an encrypted connection. Over plain HTTP the browser refuses to store it, so signing in appears to succeed and then immediately does not. Connecting channels. Several networks, including Slack, TikTok, Threads and Instagram, reject a plain HTTP return address outright when you connect an account. She works around it in development by routing those redirects through a public helper service, and that workaround disappears the moment your address is HTTPS, which is where you want to be anyway.Which proxy should you use
Caddy
Pick this if you have no preference. Three lines of configuration, and it gets and
renews your certificate on its own with nothing to schedule.
Nginx
The one most people have heard of. More configuration, and certificates are a separate
tool. Sensible if you already run it.
Traefik
Configured with labels on the container rather than a file. Natural if you already run it
in front of your other containers.
Something else
Cloudflare Tunnel, a load balancer, a split deployment. What any proxy has to get right.
Which port to send traffic to
This trips people up, so it is worth being exact.
Inside the container she always listens on 5000. The Compose file publishes that as
4007 on the host, which is why the number your proxy needs depends on how you started her.
Traefik is the exception because it talks to the container directly rather than through the
host, so it uses 5000 even under Compose.
Tell her about her own address
Setting up the proxy is only half of it. She also has to know what address people use, because she builds sign-in origins and every social network’s return address from it. Indocker-compose.yaml:
- No trailing slashes. She flags them at startup and they break comparisons.
NEXT_PUBLIC_BACKEND_URLkeeps the/apisuffix. Everything arrives on one address, and that path is how the internal proxy knows to send a request to the backend.BACKEND_INTERNAL_URLstayshttp://localhost:3000. It is not a public address. It is how the web interface reaches the backend inside the same container, and changing it to your domain sends that traffic on a pointless round trip through the internet, if it works at all.
docker compose down and then docker compose up -d. A plain restart
keeps the old values.
Check that it worked
From your own machine, not the server:HTTP/2 200 means the proxy, the certificate and PostQueen are all doing their jobs. Then open
the address in a browser and sign in. If the page loads but sign-in does not stick, the
certificate is fine and the URL settings above are what to check.
Your install is live on your own domain, over HTTPS. The padlock is real, the certificate
renews itself, and sign-in holds between page loads.