Configure Apache HTTP Server as a Reverse Proxy for Bloomreach Experience Manager
Overview
This guide explains how to configure Apache HTTP Server (httpd) as a reverse proxy for Bloomreach Experience Manager (brXM) CMS and delivery tier web applications.
When to Use
Use Apache HTTP Server as a reverse proxy to:
- Expose CMS and site applications on clean, production-ready URLs.
- Remove port numbers and context paths from public URLs.
- Enable SSL offloading and protocol forwarding.
- Support virtual host routing for multiple web applications.
Prerequisites
- Apache HTTP Server is installed and running.
- brXM CMS and site web applications are deployed in an application container (such as Tomcat).
- You have access to the Apache configuration files and SSL certificates (if using HTTPS).
- You know the internal host, port, and context paths for your CMS and site applications.
Configuration Requirements
1. Map Host Name to Application
Define a VirtualHost for each web application using the ServerName directive. This maps a domain name to the application.
<VirtualHost *:80> ServerName HOSTNAME # Add further configuration as described below </VirtualHost>
Replace HOSTNAME with the desired domain (for example, cms.example.com or www.example.com).
2. Remove Port and Context Path from URLs
Configure the reverse proxy to map the public root path / to the internal application URL using ProxyPass. This hides the internal port and context path.
ProxyPass / http://HOST:PORT/CONTEXTPATH/ ProxyPassReverse / http://HOST:PORT/CONTEXTPATH/ ProxyPassReverseCookiePath /CONTEXTPATH /
Where:
HOST: Internal host running the application container (commonly127.0.0.1).PORT: Application container port (commonly8080).CONTEXTPATH: Context path for the web application (cmsorsite).
3. Preserve Host Name for Site Requests
The brXM delivery framework uses virtual host matching. To ensure correct routing, set ProxyPreserveHost On for the site application's virtual host. This forwards the original host header to the application.
ProxyPreserveHost On
For the CMS application, set:
ProxyPreserveHost Off
4. Enable Site Preview in Experience Manager
To support site previews in the Experience manager, add a ProxyPass rule in the CMS virtual host. This allows requests to the site context path through the CMS host.
ProxyPass /CONTEXTPATH/ http://HOST:PORT/CONTEXTPATH/
Where:
HOST: Internal host (e.g.,127.0.0.1).PORT: Application container port (e.g.,8080).CONTEXTPATH: Site application context path (commonlysite).
5. Forward HTTPS Protocol
When SSL offloading is handled by Apache HTTP Server, set the X-Forwarded-Proto header to inform the application of the original protocol.
RequestHeader set X-Forwarded-Proto https
If another proxy (such as HAProxy) handles SSL offloading, configure that proxy to set the X-Forwarded-Proto header.
Example Configuration
The following example demonstrates a typical deployment where the CMS and a single site application run in the same container. The CMS is accessed via https://cms.example.com, and the site is accessed via http://*.example.com and https://*.example.com. Apache HTTP Server handles SSL offloading.
Assumptions:
- The site application is deployed as
site.war. - The CMS application is deployed as
cms.war. - The application container listens on port
8080on the same host as Apache. - SSL certificates are available at
/etc/apache2/ssl/server.crtand/etc/apache2/ssl/server.key.
<VirtualHost *:443> ServerName cms.example.com # Enable SSL SSLEngine on SSLCertificateFile /etc/apache2/ssl/server.crt SSLCertificateKeyFile /etc/apache2/ssl/server.key SSLHonorCipherOrder On SSLCipherSuite ECDHE-RSA-AES128-SHA256:AES128-GCM-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH BrowserMatch "MSIE [6-9]" ssl-unclean-shutdown <Location /> Order deny,allow Allow from all </Location> RequestHeader set X-Forwarded-Proto https ProxyPreserveHost Off # Allow Experience manager preview of the site ProxyPass /site/ http://127.0.0.1:8080/site/ ProxyPass / http://127.0.0.1:8080/cms/ ProxyPassReverse / http://127.0.0.1:8080/cms/ ProxyPassReverseCookiePath /cms / </VirtualHost> <VirtualHost *:80> ServerName www.example.com ServerAlias *.example.com ProxyPreserveHost On ProxyPass / http://127.0.0.1:8080/site/ ProxyPassReverse / http://127.0.0.1:8080/site/ ProxyPassReverseCookiePath /site / </VirtualHost> <VirtualHost *:443> ServerName www.example.com ServerAlias *.example.com # Enable SSL SSLEngine on SSLCertificateFile /etc/apache2/ssl/server.crt SSLCertificateKeyFile /etc/apache2/ssl/server.key SSLHonorCipherOrder On SSLCipherSuite ECDHE-RSA-AES128-SHA256:AES128-GCM-SHA256:RC4:HIGH:!MD5:!aNULL:!EDH BrowserMatch "MSIE [6-9]" ssl-unclean-shutdown <Location /> Order deny,allow Allow from all </Location> RequestHeader set X-Forwarded-Proto https ProxyPreserveHost On ProxyPass / http://127.0.0.1:8080/site/ ProxyPassReverse / http://127.0.0.1:8080/site/ ProxyPassReverseCookiePath /site / </VirtualHost>
Supporting Multiple Site Applications
To support additional site web applications, duplicate the <VirtualHost *:80> and <VirtualHost *:443> blocks for each site. Update the ServerName, ServerAlias, and context path values as needed for each domain and application.
Verification
After applying the configuration:
- Restart Apache HTTP Server to apply the changes.
- Access the CMS and site applications through their configured domains.
- Confirm that URLs do not expose internal ports or context paths.
- Verify HTTPS connections and that the
X-Forwarded-Protoheader is set. - Use the Experience manager to preview the site and confirm correct routing.