Reverse Proxy for Discourse | Real IP Masking
vifyirusti wants to set up a reverse proxy to mask the real IP address of their Discourse server. They’re looking for a step-by-step guide, as they’re not familiar with the process.
Lilly provided some links to relevant topics on Meta Discourse, but vifyirusti found them unclear.
RGJ suggested using a guide for running other websites on the same machine as Discourse and modifying the proxy_pass line to the IP address of the real Discourse installation. riking added that correct set_real_ip_from directives are also necessary.
However, vifyirusti pointed out that using Cloudflare alone is not enough to hide the IP address, as tools like iplogger.org can still expose it. They’re looking for a way to prevent this and have proposed a setup involving a VPS, external CDN, external SMTP, and a reverse proxy (HAProxy) behind Cloudflare.
RGJ suggested that the issue might be due to a configuration mistake, but vifyirusti explained that the problem is with outgoing requests from the server, which can expose the IP address.
pfaffman suggested allowing only connections from Cloudflare servers in the firewall, but vifyirusti found this insufficient.
Finally, vifyirusti asked how to route outgoing traffic from the VPS through CloudFlare, and pfaffman recommended using a proxy server, such as Squid, to achieve this.