Skip to main content
Mini PC Lab logo
Mini PC LabMini PCs for Homelabs
tutorials

How to Set Up Nginx Proxy Manager on Mini PC

By Max · May 2, 2026 · Updated May 5, 2026

This article contains affiliate links. If you purchase through our links, we may earn a commission at no extra cost to you. We only recommend products we’ve thoroughly researched and verified.

How to set up Nginx Proxy Manager on a mini PC hero image

Every service on your mini PC runs on a different port: Home Assistant on 8123, Jellyfin on 8096, Nextcloud on 8080, Portainer on 9443. Nginx Proxy Manager replaces http://192.168.1.100:8096 with https://jellyfin.yourdomain.com — cleaner URLs, automatic HTTPS certificates, and all external traffic entering through a single HTTPS reverse proxy. This guide sets up NPM, configures DNS, and walks through adding proxy hosts for common services.

What you need:

  • A mini PC running Ubuntu Server 24.04 LTS with Docker installed
  • A domain name with DNS managed by a provider NPM supports Cloudflare, Route53, or any registrar
  • Port 80 and 443 forwarded from your router to the mini PC for Let’s Encrypt certificates

How Nginx Proxy Manager Works

Without NPM:

Internet → Router → Port 8096 → Mini PC → Jellyfin
          Each service needs its own port forwarding rule

With NPM:

Internet → Router → Port 443 (HTTPS) → Mini PC → NPM → jellyfin.yourdomain.com → Jellyfin
                                                 NPM → ha.yourdomain.com → Home Assistant
                                                 NPM → cloud.yourdomain.com → Nextcloud

NPM receives all HTTPS traffic on port 443 and routes it to the correct internal service based on the domain name. One port forwarding rule handles all external access.


Step 1: Deploy Nginx Proxy Manager

mkdir -p ~/npm/{data,letsencrypt}
nano ~/npm/docker-compose.yml
services:
  npm:
    image: jc21/nginx-proxy-manager:latest
    container_name: nginx-proxy-manager
    ports:
      - "80:80"     # HTTP (required for Let's Encrypt HTTP-01 challenge)
      - "443:443"   # HTTPS
      - "81:81"     # NPM admin UI
    volumes:
      - ./data:/data
      - ./letsencrypt:/etc/letsencrypt
    restart: unless-stopped
cd ~/npm
docker compose up -d
docker compose logs -f  # Watch startup — ready in 30 seconds

Access the NPM admin UI at http://192.168.1.100:81

Default credentials:

  • Email: admin@example.com
  • Password: changeme

Change these immediately after first login.


Step 2: Configure Your Domain’s DNS

NPM needs to obtain SSL certificates from Let’s Encrypt. For the HTTP-01 challenge, Let’s Encrypt verifies your domain by placing a file at http://yourdomain.com/.well-known/acme-challenge/....

Prerequisites:

  1. A domain name example: yourhomelab.com
  2. DNS pointing to your home router’s public IP:
    • A record: @ → [your public IP]
  • A record: *.yourhomelab.com → [your public IP] wildcard — covers all subdomains
  1. Router port forwarding: TCP 80 and 443 → 192.168.1.100

Find your public IP:

curl ifconfig.me

Dynamic DNS if your ISP changes your IP:

If your home IP changes regularly, use a Dynamic DNS service. DuckDNS is free:

# Install ddclient for automatic IP updates
sudo apt install -y ddclient

# Or use the DuckDNS update script:
mkdir -p ~/duckdns
cat > ~/duckdns/duck.sh << 'EOF'
#!/bin/bash
echo url="https://www.duckdns.org/update?domains=yourdomain&token=YOUR-TOKEN&ip=" | curl -k -o ~/duckdns/duck.log -K -
EOF
chmod +x ~/duckdns/duck.sh

# Schedule every 5 minutes
crontab -e
# Add: */5 * * * * ~/duckdns/duck.sh >/dev/null 2>&1

Step 3: Add Your First Proxy Host

In NPM admin UI → Proxy Hosts → Add Proxy Host:

Jellyfin

SettingValue
Domain Namesjellyfin.yourhomelab.com
Schemehttp
Forward Hostname/IP192.168.1.100
Forward Port8096
Websockets Support✓ required for Jellyfin
Block Common Exploits✓

SSL tab:

  • SSL Certificate → Request a New SSL Certificate
  • Let’s Encrypt
  • Email address: your email
  • Force SSL ✓
  • HTTP/2 Support ✓
  • Click Save

NPM requests the certificate from Let’s Encrypt automatically. The first request takes 20-30 seconds. Jellyfin is now accessible at https://jellyfin.yourhomelab.com.


Common Service Proxy Configurations

Home Assistant

SettingValue
Forward Hostname192.168.1.100
Forward Port8123
Websockets Support✓

Home Assistant additional configuration — add to configuration.yaml:

http:
  use_x_forwarded_for: true
  trusted_proxies:
    - 172.0.0.0/8
    - 127.0.0.1

Nextcloud

SettingValue
Forward Hostname192.168.1.100
Forward Port8080

Custom Nginx configuration Advanced tab:

client_max_body_size 10G;
proxy_buffering off;
proxy_request_buffering off;

Add to Nextcloud config.php:

'overwrite.cli.url' => 'https://cloud.yourhomelab.com',
'overwritehost' => 'cloud.yourhomelab.com',
'overwriteprotocol' => 'https',
'trusted_proxies' => ['172.0.0.0/8'],

Portainer

SettingValue
Schemehttps
Forward Hostname192.168.1.100
Forward Port9443
SSL verificationOFF Portainer uses self-signed cert

Vaultwarden

SettingValue
Forward Hostname192.168.1.100
Forward Port80
Websockets Support✓

Grafana

SettingValue
Forward Hostname192.168.1.100
Forward Port3000

n8n

SettingValue
Forward Hostname192.168.1.100
Forward Port5678
Websockets Support✓

Step 4: Set Up Wildcard Certificate Optional

Instead of one certificate per subdomain, a wildcard certificate covers *.yourhomelab.com — all subdomains with one certificate. This requires DNS challenge instead of HTTP challenge works behind CGNAT.

Cloudflare DNS challenge recommended:

  1. In Cloudflare → Profile → API Tokens → Create Token → Edit Zone DNS
  2. In NPM → SSL Certificates → Add SSL Certificate → Let’s Encrypt
  3. Domain Names: *.yourhomelab.com and yourhomelab.com
  4. Use a DNS Challenge ✓
  5. DNS Provider: Cloudflare
  6. Credentials: paste your Cloudflare API token

NPM obtains and renews the wildcard certificate automatically.

Now assign it to new proxy hosts: in the SSL tab, select your wildcard cert instead of requesting a new one.


Restrict Access by IP Access Lists

NPM’s Access Lists restrict who can reach a proxy host. Useful for admin interfaces Portainer, NPM itself that should only be accessible from your home network:

In NPM → Access Lists → Add Access List:

  • Name: “Local Only”
  • Allow: 192.168.1.0/24
  • Satisfy Any: no

Apply to a proxy host: Edit proxy host → Access List tab → select “Local Only”.

Now accessing https://portainer.yourhomelab.com from outside your home network returns 403.


Automatic Certificate Renewal

NPM renews Let’s Encrypt certificates automatically 30 days before expiry. Certificates valid for 90 days are renewed at 60 days by default — you never need to manually renew.

Monitor certificates: SSL Certificates tab → shows each cert’s expiry date and renewal status.


Troubleshooting

Let’s Encrypt Certificate Request Failed

Verify that port 80 on your router is forwarded to the mini PC. Let’s Encrypt’s HTTP challenge requires an inbound connection on port 80 from the internet. Check with: curl http://yourhomelab.com from a network outside your home.

502 Bad Gateway

The forward hostname/port doesn’t match a running service. Verify the service is running: docker ps. Verify the port is correct — use ss -tulpn | grep LISTEN to see what ports are actually open.

Websocket Connection Fails

Some services Home Assistant, Jellyfin, n8n require WebSocket support. Enable “Websockets Support” on the proxy host. If still failing, add this to the Advanced tab:

proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";

“Host Header” Error in Nextcloud

Nextcloud rejects requests from unrecognized hostnames. Add your domain to config.php:

'trusted_domains' => [
  'localhost',
  '192.168.1.100',
  'cloud.yourhomelab.com',
],

Who Should Skip This Comparison

Frequently Asked Questions

What is Nginx Proxy Manager and why do I need it?

Nginx Proxy Manager is a Docker container that provides a web GUI for managing Nginx reverse proxies. It handles HTTPS certificates from Let’s Encrypt automatically, routes traffic from a single IP to multiple services Home Assistant on 8123, Jellyfin on 8096, Nextcloud on 8080, and renews certificates automatically. It replaces manually editing Nginx config files.

Do I need a domain name to use Nginx Proxy Manager?

Yes, for Let’s Encrypt HTTPS certificates. You need a domain name with DNS pointing to your home IP for NPM to obtain certificates. If you only need HTTPS internally without a domain, NPM can generate self-signed certificates. For proper HTTPS with trusted certificates: use a domain and configure DNS to point to your router’s public IP.

Is Nginx Proxy Manager better than Traefik or Caddy?

NPM has the most approachable GUI — it’s the easiest entry point for beginners. Traefik and Caddy offer more automation automatic service discovery via Docker labels but require more initial configuration. For a mini PC home server where you’re manually deploying 5-10 services: NPM’s GUI is simpler. For larger or frequently-changing environments: Traefik’s auto-discovery is more efficient.

Can Nginx Proxy Manager handle all home server traffic on a single mini PC?

Yes. NPM handles hundreds of requests per second on a mini PC — residential traffic for 5-10 services is negligible. NPM uses roughly 50-100MB of RAM. On the MINI S12 or EQ14, NPM runs alongside Home Assistant, Jellyfin, Nextcloud, and Pi-hole without any resource impact.