FerryDocs
ArchitectureSecurity model

Proxy headers

The proxy removes the X-Forwarded headers that a client sends and sets its own. Your app can trust them.

Edit on GitHub
X-Forwarded-ForX-Forwarded-ForClientfalse addressProxyYour app

A client sends its own X-Forwarded-For header, with a false address.

1 / 4

The headers that the proxy sets

Value
X-Forwarded-For, X-Real-IPThe address of the peer of the connection, and nothing else
X-Forwarded-Protohttp or https
X-Forwarded-HostThe Host that the client used
X-Forwarded-PortThe port of that Host (else 80 or 443), not the port of the listener. Thus apps build correct URLs behind port forwarding.
ForwardedThe same facts in RFC 7239 form
X-Request-IdKept if the client sent one. If not, a random id.

When your app can trust them

Trust these headers for requests that come through the . The proxy is the only way in from outside the server, because the containers listen on 127.0.0.1.

Calls from the private network

Other containers on the can call your app directly. These calls do not go through the proxy.

On this page