---
title: "How to install Nginx Proxy Manager on a VPS with Docker | StreetHosting"
description: "Install Nginx Proxy Manager on your VPS with Docker Compose, add proxy hosts, get free SSL and run several domains without exposing the admin panel."
url: "https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps"
type: "page"
language: "en-US"
---

VPS · 9 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# Nginx Proxy Manager on a VPS: reverse proxy with a web interface

Nginx Proxy Manager puts a reverse proxy and Let's Encrypt certificates behind a web interface. Learn how to install it with Docker Compose, connect applications running in containers or on the host, and keep the admin panel off the public internet.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking) [Certificates and HTTPS](https://streethosting.com.br/en/guides/topics/ssl) [Containers and Docker](https://streethosting.com.br/en/guides/topics/docker)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20install%20Nginx%20Proxy%20Manager%20on%20a%20VPS%20with%20Docker&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps "Share on LinkedIn") [](https://wa.me/?text=How%20to%20install%20Nginx%20Proxy%20Manager%20on%20a%20VPS%20with%20Docker%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Finstall-nginx-proxy-manager-on-vps "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps.md)

In this guide 8 sections

* [When it is worth it](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#quando-usar)
* [Installing with Docker Compose](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#instalacao)
* [Secure first access](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#primeiro-acesso)
* [Create the first proxy host](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#proxy-host)
* [Automatic SSL](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#ssl)
* [Multiple domains and extra features](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#varios-dominios)
* [Backup, updates and errors](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#manutencao-erros)
* [Which VPS to choose](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#onde-rodar)

Quick answer

To **install Nginx Proxy Manager** on a VPS, start the `jc21/nginx-proxy-manager` image with Docker Compose publishing ports 80 and 443, keep the admin panel's port 81 bound to localhost and reach it through an SSH tunnel to change the administrator credentials on the first login. After that, each domain becomes a proxy host with a Let's Encrypt certificate issued and renewed by the interface itself.

## When Nginx Proxy Manager is worth it[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#quando-usar)

Nginx Proxy Manager, usually shortened to NPM, is a web interface on top of Nginx. Instead of writing a server block for each domain, you fill in a form with the name, the destination and the port, and it generates the configuration, requests the certificate and reloads Nginx. It shines in one specific scenario: several containerized services on the same VPS, each with its own subdomain, managed by someone who does not want to edit configuration files every week.

| Approach                      | Strengths                                                      | When to choose it                                                          |
| ----------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------------------- |
| Nginx installed on the system | Full control, fewer layers, no Docker                          | One or a few applications and someone comfortable with configuration files |
| Nginx Proxy Manager           | Web interface, SSL in two clicks, access lists                 | Several containers and subdomains, a team that prefers a panel             |
| Coolify                       | Proxy, build, automatic deploy and databases in the same panel | You want a complete deployment platform, not just the proxy                |

If your case is a single application, the [Nginx as a reverse proxy](https://streethosting.com.br/en/guides/vps/nginx-reverse-proxy-vps) route has fewer moving parts. If you want the panel itself to build and deploy on every push, look at [Coolify on a VPS](https://streethosting.com.br/en/guides/vps/install-coolify-on-vps), which already ships with the proxy built in. The two do not coexist on the same ports 80 and 443.

Know the limit before adopting it. NPM generates and overwrites the Nginx configuration files inside the `data`folder, so any manual edit to those files is lost on the next change made through the panel. Fine-tuning goes through each host's Advanced tab, which accepts Nginx directives. Very elaborate setups, with proxy caching, per-route rate limit rules or load balancing across several backends, are easier to maintain in a hand-written Nginx.

## Installing with Docker Compose[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#instalacao)

The requirement is having Docker Engine and the Compose plugin installed from the official repository. If you do not have them yet, follow the guide on [installing Docker on Ubuntu](https://streethosting.com.br/en/guides/vps/install-docker-ubuntu-vps) and come back here. Also check that no service is occupying the web ports:

`sudo ss -tlnp | grep -E ':(80|443) ' # if nginx or apache2 shows up, stop the service: sudo systemctl disable --now nginx`

Create a folder for the project and the `compose.yaml` file:

`mkdir -p ~/npm && cd ~/npm nano compose.yaml`

`services: npm: image: jc21/nginx-proxy-manager:latest container_name: npm restart: unless-stopped ports: - "80:80" - "443:443" - "127.0.0.1:81:81" volumes: - ./data:/data - ./letsencrypt:/etc/letsencrypt extra_hosts: - "host.docker.internal:host-gateway" networks: - proxy networks: proxy: name: proxy`

Start the container and follow the first boot. If your user is not in the docker group, put sudo in front of the commands:

`docker compose up -d docker compose logs -f npm`

Three decisions in that file deserve an explanation:

* **Port 81 on localhost only:** Docker publishes ports by going around the UFW rules. With `"81:81"`, the panel would be open to the internet even with the firewall saying otherwise. With the `127.0.0.1` prefix, only someone on the VPS itself can reach it.
* **Network with a fixed name:** the `proxy` network will be shared with the other containers, which NPM then finds by name.
* **host.docker.internal:** creates a name that points to the VPS itself, useful when the application runs outside Docker, under PM2 or systemd.

The `latest` tag makes the first test easier. In production, pin the current version published by the project and update on purpose, reading the release notes, instead of receiving changes without knowing.

## Secure first access to the admin panel[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#primeiro-acesso)

Since port 81 only exists on localhost, open an SSH tunnel from your computer. It carries port 8181 on your machine to port 81 on the VPS:

`ssh -L 8181:127.0.0.1:81 usuario@IP_DA_VPS # with the session open, browse to: # http://localhost:8181`

On the first boot, NPM generates its internal keys, creates the SQLite database in the `data` folder and prepares an administrator user. Log in with the initial credentials listed in the official documentation for the installed version and change the email and password immediately, before creating any host.

Do not publish port 81 to the internet, not even for a few minutes. Bots sweep entire IP ranges looking for panels with default credentials, and every public IP gets that kind of visit all the time.

## Create the first proxy host[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#proxy-host)

First of all, point the domain at the VPS with an A record, as shown in the guide on [DNS for a VPS](https://streethosting.com.br/en/guides/vps/point-domain-to-vps). Then, in the panel, open Hosts, Proxy Hosts and click Add Proxy Host. The form asks for four main pieces of information: the domain name, the scheme (http in most cases, because TLS terminates at NPM), the destination host and the destination port.

### Application in another container[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#app-em-container)

This is the ideal scenario. Put the application's container on the `proxy` network and publish no ports at all: NPM talks to it over the internal network, and nothing is exposed to the outside.

`services: app: image: ghcr.io/sua-conta/sua-app:1.4.0 container_name: minha-app restart: unless-stopped networks: - proxy networks: proxy: external: true`

In the proxy host, use `minha-app`as the Forward Hostname and the application's internal port (3000, for example) as the Forward Port. Check Block Common Exploits and, if the application uses WebSocket, Websockets Support.

### Application running outside Docker[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#app-no-host)

If the application runs directly on the system, under PM2 or systemd, use `host.docker.internal`as the destination. Two adjustments are mandatory: the application must listen on an interface the container can reach (0.0.0.0, not 127.0.0.1) and UFW must allow the traffic coming from the Docker network. Find the range and open only the application's port:

`docker network inspect proxy --format '{{(index .IPAM.Config 0).Subnet}}' # example output: 172.18.0.0/16 sudo ufw allow from 172.18.0.0/16 to any port 3000 proto tcp`

Here UFW really does protect, because port 3000 belongs to a system process and not to a container. It stays closed to the internet; only the Docker network reaches it.

### The application needs to see the real IP[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#ip-real)

With the proxy in front, every request reaches the application coming from NPM's IP. The real visitor travels in the `X-Forwarded-For` and `X-Real-IP` headers, and the original protocol in `X-Forwarded-Proto`. Configure the application to trust those headers only when they come from the proxy, or rate limiting, logs and HTTPS link generation will be based on the wrong address. In Express that is the `trust proxy` setting; in other frameworks, look for proxy headers or forwarded headers in the documentation.

## Automatic SSL with Let's Encrypt[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#ssl)

On the SSL tab of the same proxy host, choose Request a new SSL Certificate, enter an email for expiration notices and accept the Let's Encrypt terms. NPM validates the domain over port 80, so DNS must already point to the VPS and port 80 must be reachable from the internet.

* **Force SSL:** redirects every HTTP access to HTTPS. Always turn it on.
* **HTTP/2 Support:** improves loading for pages with many files. Safe to turn on.
* **HSTS Enabled:** tells the browser to remember that the site only works over HTTPS for a long period. Turn it on only after confirming everything works, because undoing it is not immediate for anyone who has already visited.

Renewal happens inside the container, with no cron job on the VPS. For a wildcard certificate, such as `*.seu-dominio.com.br`, use the DNS challenge option: you pick the DNS provider, paste an API token with permission to edit the zone and NPM creates the validation record on its own.

## Multiple domains and extra features[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#varios-dominios)

Each application gets its own proxy host, and a single host accepts several names (with and without www, for example). Beyond the plain proxy, the panel brings features that solve common situations without opening a configuration file:

| Feature           | What it does                             | Example                                                |
| ----------------- | ---------------------------------------- | ------------------------------------------------------ |
| Redirection Hosts | Redirect an entire domain to another one | Old domain to the new one, with a 301 code             |
| Custom Locations  | Send a path to a different destination   | /api to the API container, everything else to the site |
| Access Lists      | Basic auth and IP allowlisting           | Protect internal panels and admin tools                |
| Streams           | Forward TCP or UDP without HTTP          | Pass a game port through to another container          |
| 404 Hosts         | Answer domains you do not want to serve  | Old names that still point to the IP                   |
| Advanced          | Extra Nginx directives per host          | client\_max\_body\_size 50m for large uploads          |

A smart use is publishing the panel itself under a domain and retiring the tunnel. Create a proxy host `npm.seu-dominio.com.br` pointing to `127.0.0.1` on port 81 (inside the container, that address is NPM itself), issue the certificate and attach an Access List that only allows your IP or requires a password. Port 81 stays closed to the outside.

The Advanced tab accepts configuration snippets that apply only to that host. A common example for an API that receives uploads and slow responses:

`client_max_body_size 50m; proxy_read_timeout 120s; proxy_send_timeout 120s;`

If you prefer to understand what the panel generates under the hood, you will find the file-based equivalent in the guide on [several sites on the same VPS with Nginx](https://streethosting.com.br/en/guides/vps/multiple-websites-on-one-vps).

## Backup, updates and common errors[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#manutencao-erros)

Everything that matters lives in the `data` and `letsencrypt` folders. A simple backup is compressing the project folder and moving it off the VPS. Updating means pulling the new image and recreating the container:

`cd ~/npm sudo tar czf ~/npm-backup-$(date +%F).tar.gz data letsencrypt compose.yaml docker compose pull docker compose up -d`

| Symptom                                        | Likely cause                                                            | How to fix it                                                                                 |
| ---------------------------------------------- | ----------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- |
| 502 Bad Gateway                                | Wrong destination or port, or container outside the proxy network       | Check the container name, the internal port and the network with docker network inspect proxy |
| 502 with the application on the host           | Application listens only on 127.0.0.1 or UFW blocks the Docker network  | Listen on 0.0.0.0 and allow the Docker network range on the port                              |
| Internal Error when requesting the certificate | DNS does not point to the VPS or port 80 is in use                      | Confirm with dig and check whether another service is using port 80                           |
| Redirect loop                                  | Force SSL combined with an external proxy that talks HTTP to the origin | On the external proxy, use the mode that connects to the origin over HTTPS                    |
| 413 Request Entity Too Large                   | Nginx default upload limit                                              | In Advanced, add client\_max\_body\_size with the size you need                               |
| Panel does not open on port 81                 | Port bound to localhost, as planned                                     | Use the SSH tunnel or the proxy host for the panel itself                                     |

For the ports that live outside Docker, like SSH, keep the [UFW firewall](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) active. Remember that it does not filter ports published by containers: their protection comes from publishing nothing beyond 80 and 443.

## Which VPS to choose for Nginx Proxy Manager[](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#onde-rodar)

NPM itself is lightweight. What sizes the VPS is the set of applications behind it: every container, every database and every build consumes memory and disk. That is why the choice starts with what you are going to host, and the proxy comes in as a small line item. NVMe storage makes a difference when there are databases and Docker images being pulled and extracted.

| Scenario                                          | Suggested plan                      | Monthly price |
| ------------------------------------------------- | ----------------------------------- | ------------- |
| Proxy and two or three light sites                | Xeon 2 vCPU, 2 GB DDR4, 20 GB NVMe  | R$ 26.00      |
| Proxy, Node or Python applications and a database | Ryzen 2 vCPU, 4 GB DDR5, 40 GB NVMe | R$ 66.00      |
| Several containers and databases with headroom    | Xeon 6 vCPU, 8 GB DDR4, 80 GB NVMe  | R$ 77.00      |
| Applications that depend on high clock speed      | Ryzen 4 vCPU, 8 GB DDR5, 80 GB NVMe | R$ 118.00     |

Both lines are listed under [VPS plans](https://streethosting.com.br/en/vps), with root access, NVMe, Anti-DDoS included and a datacenter in São Paulo, which keeps latency low for anyone accessing from Brazil. For applications that render pages on the server or do heavy processing per request, the [Ryzen 9 9950X VPS](https://streethosting.com.br/en/vps/ryzen) delivers more speed per core. Activation happens within 60 seconds.

* Ports 80 and 443 free before starting the container
* Port 81 published only on 127.0.0.1
* Administrator credentials changed on the first login
* Applications on the proxy network, with no published ports
* Force SSL enabled on every host
* data and letsencrypt folders copied off the VPS

In this guide

* [When it is worth it](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#quando-usar)
* [Installing with Docker Compose](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#instalacao)
* [Secure first access](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#primeiro-acesso)
* [Create the first proxy host](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#proxy-host)
* [Automatic SSL](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#ssl)
* [Multiple domains and extra features](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#varios-dominios)
* [Backup, updates and errors](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#manutencao-erros)
* [Which VPS to choose](https://streethosting.com.br/en/guides/vps/install-nginx-proxy-manager-on-vps#onde-rodar)

## Frequently asked questions

Is Nginx Proxy Manager the same thing as Nginx?

Not exactly. It runs Nginx inside a container and generates the configuration for you from a web interface. You gain convenience for creating proxies and certificates, but give up part of the fine-grained control you have when editing the Nginx files directly.

Can I run Nginx Proxy Manager alongside an Nginx installed on the system?

Not on the same ports. Both need 80 and 443, so pick one of them as the entry point. If Nginx is already installed on the system, stop and disable the service before starting the container, or migrate the sites to proxy hosts.

Which port does the Nginx Proxy Manager admin panel use?

The admin panel uses port 81. Keep that port off the internet: publish it only on localhost and reach it through an SSH tunnel, or create a proxy host with HTTPS and an access list for the panel itself.

How do I get a wildcard certificate in Nginx Proxy Manager?

A wildcard certificate requires DNS validation. On the SSL tab, enable the DNS challenge option, choose your DNS provider and enter its API token. The wildcard certificate covers every subdomain and renews on its own from then on.

How do I back up Nginx Proxy Manager?

Copy the whole project folder, including the data and letsencrypt folders, somewhere outside the VPS. They hold the SQLite database with every host, the generated configuration and the certificates. Restoring means copying the folders back and starting the same compose file.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[VPS Intermediate How to install Docker on Ubuntu 22.04 or 24.04 on a VPS (straight to the point) A stable Docker install on an Ubuntu VPS depends on the right package source and step by step validation. In this guide you set up the official repository, install Engine and Compose, test the daemon and apply basic security measures before deploying applications. 3 min Read guide](https://streethosting.com.br/en/guides/vps/install-docker-ubuntu-vps) [VPS Intermediate How to set up Nginx as a reverse proxy on a VPS Your app runs on an internal port and you want to serve it on a domain with HTTPS. Nginx as a reverse proxy solves that and also brings several apps together in one place. 3 min Read guide](https://streethosting.com.br/en/guides/vps/nginx-reverse-proxy-vps) [VPS Intermediate How to install Coolify on a VPS and deploy with HTTPS Coolify turns an empty VPS into a deploy platform with builds, a proxy, certificates and rollback. Here is the install, the firewall details Docker forces on you and the path from repository to a domain with HTTPS. 9 min Read guide](https://streethosting.com.br/en/guides/vps/install-coolify-on-vps)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
