← Back to Blog

How to Set Up Nginx Proxy Manager on a VPS (2026)

Published October 7, 2026  ·  5 min read  ·  Galaxy Cloud Solutions

Say you run a couple of apps on your server, one on port 3000 and one on port 8080. Sending people to http://203.0.113.10:3000 works, but it looks rough, it isn't encrypted, and nobody remembers it. What you want is app.yourdomain.com with a padlock in the address bar.

That's the job of a reverse proxy. It sits on ports 80 and 443, looks at which domain each visitor asked for, and passes them to the right app behind it. Nginx is very good at this, but setting it up means config files and certificate commands. Nginx Proxy Manager puts the same thing behind a web page. Its docs describe it as a way to forward to your sites, "including free SSL, without having to know too much about Nginx or Letsencrypt."

It's in our one-click installer, and we tested it on our current Ubuntu 24.04 and Rocky Linux 9 images this week.

⚡ Run Nginx Proxy Manager from $5/mo, use code LAUNCH2026 for 50% off

Where it fits, and where it doesn't

Nginx Proxy Manager is light. Our installer allows it on any plan, and Nebula 1 ($5/mo, 1 vCPU, 1 GB RAM, 20 GB storage) is plenty if it's only directing traffic. If the apps behind it run on the same server, size the plan for those apps, not for the proxy.

The catch is that it needs ports 80 and 443 to itself. Only one program on a server can listen on each port, so it won't sit alongside another app that wants them. On our installer list that includes WordPress, the LAMP and LEMP stacks, Appwrite and Discourse. If you already run one of those, put Nginx Proxy Manager on its own small server.

It works well in front of apps that run on other ports, like Gitea, Vaultwarden, Uptime Kuma or anything you've written yourself. It can also send traffic to apps on a different server.

Setting it up

  1. Order a VPS. Ubuntu 24.04 is the default operating system and it's what I'd use. Rocky Linux 9 also passed our tests.
  2. In the client portal, open your VPS, expand the One-Click App Installer and choose Nginx Proxy Mgr under Networking & VPN. In our tests the install took about three and a half minutes on Ubuntu 24.04 and about five on Rocky Linux 9, and you'll get an email when it's done.
  3. On the same page, under Firewall Rules, add two rules: port 80 TCP and port 443 TCP, both from any source. Your server starts with everything closed except SSH, and visitors need both ports. Let's Encrypt also needs port 80 to issue your certificates.
  4. Leave port 81, the admin page, closed for now. The next section explains how to reach it safely.

Getting into the admin page

The admin page runs on port 81 over plain HTTP. Rather than opening that to the whole internet, reach it through SSH, which is already open. On your own computer, run:

ssh -L 8181:localhost:81 YOUR-USER@YOUR-IP

Use the login from your welcome email. Leave that window open, then go to http://localhost:8181 in your browser. You're looking at the admin page through the SSH connection, and nobody else can see it.

What you see next depends on the version. If it asks you to create an admin account, do it now, with your real email and a long password. If it shows a login page instead, the starting details are [email protected] and changeme, and it will ask you to change both as soon as you log in.

If you'd rather not use SSH, you can open port 81 in Firewall Rules with your own IP address in the Source IP box. Then only your connection can reach it.

Your first site, start to finish

Let's say you want git.yourdomain.com to reach a Gitea install on port 3000 on the same server.

  1. DNS first. At your domain registrar or DNS provider, create an A record for git pointing at your server's IP. Give it a few minutes to take effect.
  2. Add a Proxy Host. In the admin page, add a new Proxy Host. Enter git.yourdomain.com as the domain. For the forward address, use your server's IP and port 3000.
  3. Get the certificate. On the SSL tab, request a free Let's Encrypt certificate, set it to force SSL, and save.
  4. Test it. Open https://git.yourdomain.com. You should see Gitea with a padlock.

Once the app is reached through the proxy, you don't need its own port open in Firewall Rules any more. If you opened 3000 earlier, you can delete that rule.

If the certificate request fails, it's almost always one of two things: the A record doesn't point at this server yet, or port 80 isn't open in Firewall Rules.

Looking after it

Everything Nginx Proxy Manager knows lives in two folders: your hosts and settings in /opt/npm/data, and your certificates in /opt/npm/letsencrypt. Keep a copy of both somewhere else. If you ever rebuild the server, putting those two folders back gets every site and certificate back. Our guide on how to back up a VPS covers the basics.

Let's Encrypt certificates are short-lived and need renewing, and renewal needs port 80 just like the first request did. Don't remove that rule later while tidying up.

If you'd rather do all this by hand, our guide on setting up an Nginx reverse proxy shows the config-file way. If you'd rather click, Nebula 1 and the one-click installer will have you running in a few minutes.

One-click Nginx Proxy Manager installer included

Nebula 1: 1 vCPU, 1 GB RAM, 20 GB storage, 500 GB transfer, a dedicated IP and full root access, with Nginx Proxy Manager one click away in the control panel. Use code LAUNCH2026 for 50% off your first month on monthly billing.

Try Galaxy Cloud Solutions